note 64294 added to function.ldap-modify

From: Date: Tue, 11 Apr 2006 20:44:52 +0000
Subject: note 64294 added to function.ldap-modify
Groups: php.notes 
Request: Send a blank email to php-notes+get-107804@lists.php.net to get a copy of this message
If you want to disable an account in an Active Directory of Windows, you may try this (it works for me in a Win2k environment): (foo.bar should be replaced in "$ldapBase" to the correct domain, e.g. "DC=phpfreackx,DC=com" if your domain is phpfreackx.com) domctrl = domain controller domadlogin = domain admin login domadpw = domain admin password username = loginname of useraccount (e.g. "john.doe") enable =1 (if you want to enable it, 0 if it should be disabled) <?php function userchange($username,$enable=1,$domadlogin,$domadpw,$domctrl) { $ldapServer = $domctrl; $ldapBase = 'DC=foo,DC=bar'; $ds = ldap_connect($ldapServer); if (!$ds) {die('Cannot Connect to LDAP server');} $ldapBind = ldap_bind($ds,$domadlogin,$domadpw); if (!$ldapBind) {die('Cannot Bind to LDAP server');} ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3); $sr = ldap_search($ds, $ldapBase, "(samaccountname=$username)"); $ent= ldap_get_entries($ds,$sr); $dn=$ent[0]["dn"]; // Deactivate $ac = $ent[0]["useraccountcontrol"][0]; $disable=($ac | 2); // set all bits plus bit 1 (=dec2) $enable =($ac & ~2); // set all bits minus bit 1 (=dec2) $userdata=array(); if ($enable==1) $new=$enable; else $new=$disable; //enable or disable? $userdata["useraccountcontrol"][0]=$new; ldap_modify($ds, $dn, $userdata); //change state $sr = ldap_search($ds, $ldapBase, "(samaccountname=$username)"); $ent= ldap_get_entries($ds,$sr); $ac = $ent[0]["useraccountcontrol"][0]; if (($ac & 2)==2) $status=0; else $status=1; ldap_close($ds); return $status; //return current status (1=enabled, 0=disabled) } // use this to disable an account: // userchange('john.doe@foo.bar',0,'admin@foo.bar', 'secret','domctrl.foo.bar'); // ..but this to enable it: // userchange('john.doe@foo.bar',1,'admin@foo.bar', 'secret','domctrl.foo.bar'); ?> ---- Server IP: 217.160.72.57 Probable Submitter: 62.180.131.131 (proxied: 172.16.125.5) ---- X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/function.ldap-modify.php Edit -- http://master.php.net/note/edit/64294 Del: integrated -- http://master.php.net/note/delete/64294/integrated Del: useless -- http://master.php.net/note/delete/64294/useless Del: bad code -- http://master.php.net/note/delete/64294/bad+code Del: spam -- http://master.php.net/note/delete/64294/spam Del: non-english -- http://master.php.net/note/delete/64294/non-english Del: in docs -- http://master.php.net/note/delete/64294/in+docs Del: other reasons-- http://master.php.net/note/delete/64294 Reject -- http://master.php.net/note/reject/64294 Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#107804) next »