Win32 API 日本語リファレンス
ホームNetworking.Ldap › ldap_bind_s

ldap_bind_s

関数
指定方式でLDAPサーバーに同期バインドする。
DLLWLDAP32.dll文字セットANSI (-A)呼出規約cdecl対応OSWindows Vista 以降

シグネチャ

// WLDAP32.dll  (ANSI / -A)
#include <windows.h>

DWORD ldap_bind_s(
    LDAP* ld,
    LPCSTR dn,   // optional
    LPCSTR cred,   // optional
    DWORD method
);

パラメーター

名前方向説明
ldLDAP*inoutセッションハンドル。
dnLPCSTRinoptionalバインドに使用するエントリの識別名を格納する、null で終わる文字列へのポインター。DN、UPN、WinNT 形式のユーザー名、またはディレクトリサーバーが識別子として受け入れるその他の名前を指定できます。
credLPCSTRinoptional認証に使用する資格情報を格納する、null で終わる文字列へのポインター。このパラメーターを使用して任意の資格情報を渡すことができます。資格情報の形式と内容は、method パラメーターの設定によって異なります。詳細については「解説」を参照してください。
methodDWORDin使用する認証方法を示します。詳細および有効な非同期認証方法の一覧については、「解説」セクションを参照してください。詳細および有効な非同期認証方法の説明については、 ldap_bind を参照してください。

戻り値の型: DWORD

公式ドキュメント

ldap_bind_s 関数 (winldap.h) は、クライアントを LDAP サーバーに対して同期的に認証します。

戻り値

関数が成功した場合、戻り値は LDAP_SUCCESS です。

関数が失敗した場合は、エラーコードを返します。詳細については、 Return Values を参照してください。

解説(Remarks)

Windows Server 2008 および Windows Vista で導入されたユーザーアカウント制御 (UAC) は、LDAP での変更や追加に関して非常に重要な影響を及ぼします。制限された UAC 管理者トークンでユーザーが DC にログオンし、NULL の資格情報を使用している場合、ディレクトリに対する変更や追加、およびスキーマ変更操作はすべて失敗します。これには、DirSync 検索や、SecurityDescriptorFlags を使用してオブジェクトの ntSecurityDescriptor 属性から SACL を取得する操作など、多くの操作が含まれます。

これらはすべて、アクセス権が不足しているというエラーで失敗します。

管理者が DC にログオンする際にユーザーアカウント制御が有効になっていると、管理者はログオンセッションで制限されたトークンを取得します。その状態で NULL の資格情報を指定して ldap_bind_s を使用すると、変更や追加を行う操作は失敗します。

ldap_bind_s の実装は、次の表に示す認証方法をサポートします。LDAP_AUTH_SIMPLE オプションを指定して ldap_bind_s を呼び出すことは、ldap_simple_bind_s を呼び出すことと同等です。

認証方法 説明 資格情報
LDAP_AUTH_SIMPLE 平文パスワードによる認証。 ユーザーのパスワードを格納する文字列。
LDAP_AUTH_DIGEST ダイジェスト認証パッケージ。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには、適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_DPA 分散パスワード認証。Microsoft Membership System で使用されます。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには、適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_MSN Microsoft Network 認証サービス。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには、適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_NEGOTIATE 汎用セキュリティサービス (GSS) (Snego)。認証自体は行わず、利用可能なサービスの一覧から最も適切な認証方法を選択し、すべての認証データをそのサービスに渡します。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには、適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体または SEC_WINNT_AUTH_IDENTITY_EX 構造体へのポインターを設定します。
LDAP_AUTH_NTLM NT LAN Manager 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには、適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体または SEC_WINNT_AUTH_IDENTITY_EX 構造体へのポインターを設定します。
LDAP_AUTH_SICILY MSN サーバーに対するパッケージネゴシエーションに対応します。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには、適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_SSPI 古い定数です。下位互換性のために含まれています。この定数を使用すると、GSS (Snego) ネゴシエーションサービスが選択されます。 LDAP_AUTH_NEGOTIATE と同じです。

非同期のバインド認証を行うには、ldap_bindLDAP_AUTH_SIMPLE を使用します。

バインド操作は、識別名とパスワードなどの何らかの認証資格情報を提供することで、クライアントをディレクトリサーバーに対して識別します。実際に必要な資格情報は、使用する認証方法によって異なります。ldap_bind_s() で資格情報に NULL を渡した場合 (simple 以外)、現在のユーザーまたはサービスの資格情報が使用されます。simple バインド方法 ( ldap_simple_bind_s と同様のもの) を指定した場合は、NULL の平文パスワードを指定したことと同等になります。詳細については、 ldap_bind を参照してください。

LDAP 2 サーバーでは、認証を必要とする他の操作を試みる前に、アプリケーションがバインドを行う必要があることに注意してください。

マルチスレッド: バインドの呼び出しは接続全体に適用されるため、安全ではありません。複数のスレッドで接続を共有し、バインド操作を他の操作とスレッド化しようとする場合は注意してください。

注意 Microsoft LDAP クライアントは、バインドと応答の往復ごとに既定のタイムアウト値として 120 秒 (2 分) を使用します。このタイムアウト値は、LDAP_OPT_TIMELIMIT セッションオプションを使用して変更できます。他の操作には、 ldap_set_option で指定しない限りタイムアウトはありません。
セッションハンドルに対するすべての操作が完了したら、LDAP セッションハンドルを ldap_unbind 関数に渡してセッションを終了する必要があります。また、ldap_bind_s の呼び出しが失敗した場合も、エラー回復のために不要になった時点で ldap_unbind を呼び出してセッションハンドルを解放してください。
出典・ライセンス: 上記「公式ドキュメント」の内容は Microsoft の Win32 API ドキュメント(MicrosoftDocs/sdk-api)を日本語に翻訳・改変したものです。© Microsoft Corporation. CC BY 4.0 で提供。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)

各言語での呼び出し定義

// WLDAP32.dll  (ANSI / -A)
#include <windows.h>

DWORD ldap_bind_s(
    LDAP* ld,
    LPCSTR dn,   // optional
    LPCSTR cred,   // optional
    DWORD method
);
[DllImport("WLDAP32.dll", CharSet = CharSet.Ansi, ExactSpelling = true, CallingConvention = CallingConvention.Cdecl)]
static extern uint ldap_bind_s(
    IntPtr ld,   // LDAP* in/out
    [MarshalAs(UnmanagedType.LPStr)] string dn,   // LPCSTR optional
    [MarshalAs(UnmanagedType.LPStr)] string cred,   // LPCSTR optional
    uint method   // DWORD
);
<DllImport("WLDAP32.dll", CharSet:=CharSet.Ansi, ExactSpelling:=True, CallingConvention:=CallingConvention.Cdecl)>
Public Shared Function ldap_bind_s(
    ld As IntPtr,   ' LDAP* in/out
    <MarshalAs(UnmanagedType.LPStr)> dn As String,   ' LPCSTR optional
    <MarshalAs(UnmanagedType.LPStr)> cred As String,   ' LPCSTR optional
    method As UInteger   ' DWORD
) As UInteger
End Function
' ld : LDAP* in/out
' dn : LPCSTR optional
' cred : LPCSTR optional
' method : DWORD
Declare PtrSafe Function ldap_bind_s Lib "wldap32" ( _
    ByVal ld As LongPtr, _
    ByVal dn As String, _
    ByVal cred As String, _
    ByVal method As Long) As Long
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

ldap_bind_s = ctypes.cdll.wldap32.ldap_bind_s
ldap_bind_s.restype = wintypes.DWORD
ldap_bind_s.argtypes = [
    ctypes.c_void_p,  # ld : LDAP* in/out
    wintypes.LPCSTR,  # dn : LPCSTR optional
    wintypes.LPCSTR,  # cred : LPCSTR optional
    wintypes.DWORD,  # method : DWORD
]
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('WLDAP32.dll')
ldap_bind_s = Fiddle::Function.new(
  lib['ldap_bind_s'],
  [
    Fiddle::TYPE_VOIDP,  # ld : LDAP* in/out
    Fiddle::TYPE_VOIDP,  # dn : LPCSTR optional
    Fiddle::TYPE_VOIDP,  # cred : LPCSTR optional
    -Fiddle::TYPE_INT,  # method : DWORD
  ],
  -Fiddle::TYPE_INT, Fiddle::Function::CDECL)
#[link(name = "wldap32")]
extern "C" {
    fn ldap_bind_s(
        ld: *mut LDAP,  // LDAP* in/out
        dn: *const u8,  // LPCSTR optional
        cred: *const u8,  // LPCSTR optional
        method: u32  // DWORD
    ) -> u32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[DllImport("WLDAP32.dll", CharSet = CharSet.Ansi, CallingConvention = CallingConvention.Cdecl)]
public static extern uint ldap_bind_s(IntPtr ld, [MarshalAs(UnmanagedType.LPStr)] string dn, [MarshalAs(UnmanagedType.LPStr)] string cred, uint method);
"@
$api = Add-Type -MemberDefinition $sig -Name 'WLDAP32_ldap_bind_s' -Namespace Win32 -PassThru
# $api::ldap_bind_s(ld, dn, cred, method)
#uselib "WLDAP32.dll"
#func global ldap_bind_s "ldap_bind_s" sptr, sptr, sptr, sptr
; ldap_bind_s varptr(ld), dn, cred, method   ; 戻り値は stat
; ld : LDAP* in/out -> "sptr"
; dn : LPCSTR optional -> "sptr"
; cred : LPCSTR optional -> "sptr"
; method : DWORD -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "WLDAP32.dll"
#cfunc global ldap_bind_s "ldap_bind_s" var, str, str, int
; res = ldap_bind_s(ld, dn, cred, method)
; ld : LDAP* in/out -> "var"
; dn : LPCSTR optional -> "str"
; cred : LPCSTR optional -> "str"
; method : DWORD -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; DWORD ldap_bind_s(LDAP* ld, LPCSTR dn, LPCSTR cred, DWORD method)
#uselib "WLDAP32.dll"
#cfunc global ldap_bind_s "ldap_bind_s" var, str, str, int
; res = ldap_bind_s(ld, dn, cred, method)
; ld : LDAP* in/out -> "var"
; dn : LPCSTR optional -> "str"
; cred : LPCSTR optional -> "str"
; method : DWORD -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	wldap32 = windows.NewLazySystemDLL("WLDAP32.dll")
	procldap_bind_s = wldap32.NewProc("ldap_bind_s")
)

// ld (LDAP* in/out), dn (LPCSTR optional), cred (LPCSTR optional), method (DWORD)
r1, _, err := procldap_bind_s.Call(
	uintptr(ld),
	uintptr(unsafe.Pointer(windows.BytePtrFromString(dn))),
	uintptr(unsafe.Pointer(windows.BytePtrFromString(cred))),
	uintptr(method),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // DWORD
function ldap_bind_s(
  ld: Pointer;   // LDAP* in/out
  dn: PAnsiChar;   // LPCSTR optional
  cred: PAnsiChar;   // LPCSTR optional
  method: DWORD   // DWORD
): DWORD; cdecl;
  external 'WLDAP32.dll' name 'ldap_bind_s';
result := DllCall("WLDAP32\ldap_bind_s"
    , "Ptr", ld   ; LDAP* in/out
    , "AStr", dn   ; LPCSTR optional
    , "AStr", cred   ; LPCSTR optional
    , "UInt", method   ; DWORD
    , "Cdecl UInt")   ; return: DWORD
●ldap_bind_s(ld, dn, cred, method) = DLL("WLDAP32.dll", "dword ldap_bind_s(void*, char*, char*, dword)")
# 呼び出し: ldap_bind_s(ld, dn, cred, method)
# ld : LDAP* in/out -> "void*"
# dn : LPCSTR optional -> "char*"
# cred : LPCSTR optional -> "char*"
# method : DWORD -> "dword"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。
# ※cdecl関数。DLL()宣言はstdcall前提。cdeclは EXEC_PTR(`cdecl`,…) を使用。
const std = @import("std");

extern "wldap32" fn ldap_bind_s(
    ld: [*c]LDAP, // LDAP* in/out
    dn: [*c]const u8, // LPCSTR optional
    cred: [*c]const u8, // LPCSTR optional
    method: u32 // DWORD
) callconv(.c) u32;
proc ldap_bind_s(
    ld: ptr LDAP,  # LDAP* in/out
    dn: cstring,  # LPCSTR optional
    cred: cstring,  # LPCSTR optional
    `method`: uint32  # DWORD
): uint32 {.importc: "ldap_bind_s", cdecl, dynlib: "WLDAP32.dll".}
pragma(lib, "wldap32");
extern(C)
uint ldap_bind_s(
    LDAP* ld,   // LDAP* in/out
    const(char)* dn,   // LPCSTR optional
    const(char)* cred,   // LPCSTR optional
    uint method   // DWORD
);
ccall((:ldap_bind_s, "WLDAP32.dll"), UInt32,
      (Ptr{LDAP}, Cstring, Cstring, UInt32),
      ld, dn, cred, method)
# ld : LDAP* in/out -> Ptr{LDAP}
# dn : LPCSTR optional -> Cstring
# cred : LPCSTR optional -> Cstring
# method : DWORD -> UInt32
local ffi = require("ffi")
ffi.cdef[[
uint32_t ldap_bind_s(
    void* ld,
    const char* dn,
    const char* cred,
    uint32_t method);
]]
local wldap32 = ffi.load("wldap32")
-- wldap32.ldap_bind_s(ld, dn, cred, method)
-- ld : LDAP* in/out
-- dn : LPCSTR optional
-- cred : LPCSTR optional
-- method : DWORD
-- 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
const koffi = require('koffi');
const lib = koffi.load('WLDAP32.dll');
const ldap_bind_s = lib.func('__cdecl', 'ldap_bind_s', 'uint32_t', ['void *', 'str', 'str', 'uint32_t']);
// ldap_bind_s(ld, dn, cred, method)
// ld : LDAP* in/out -> 'void *'
// dn : LPCSTR optional -> 'str'
// cred : LPCSTR optional -> 'str'
// method : DWORD -> 'uint32_t'
// 出力ポインタは koffi.out(...) で包む。構造体は koffi.struct で定義。
const lib = Deno.dlopen("WLDAP32.dll", {
  ldap_bind_s: { parameters: ["pointer", "buffer", "buffer", "u32"], result: "u32" },
});
// lib.symbols.ldap_bind_s(ld, dn, cred, method)
// ld : LDAP* in/out -> "pointer"
// dn : LPCSTR optional -> "buffer"
// cred : LPCSTR optional -> "buffer"
// method : DWORD -> "u32"
// 文字列は "buffer"。ANSI(-A) は new TextEncoder() で UTF-8/ANSI バイト列(末尾に \x00)を渡す。
// 値渡し構造体は { struct: [ ...field types... ] } を使用。
<?php
$ffi = FFI::cdef(<<<C
uint32_t ldap_bind_s(
    void* ld,
    const char* dn,
    const char* cred,
    uint32_t method);
C, "WLDAP32.dll");
// $ffi->ldap_bind_s(ld, dn, cred, method);
// ld : LDAP* in/out
// dn : LPCSTR optional
// cred : LPCSTR optional
// method : DWORD
// 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
import com.sun.jna.*;
import com.sun.jna.ptr.*;
import com.sun.jna.win32.StdCallLibrary;
import com.sun.jna.win32.W32APIOptions;

public interface Wldap32 extends Library {
    Wldap32 INSTANCE = Native.load("wldap32", Wldap32.class, W32APIOptions.ASCII_OPTIONS);
    int ldap_bind_s(
        Pointer ld,   // LDAP* in/out
        String dn,   // LPCSTR optional
        String cred,   // LPCSTR optional
        int method   // DWORD
    );
}
@[Link("wldap32")]
lib LibWLDAP32
  fun ldap_bind_s = ldap_bind_s(
    ld : LDAP*,   # LDAP* in/out
    dn : UInt8*,   # LPCSTR optional
    cred : UInt8*,   # LPCSTR optional
    method : UInt32   # DWORD
  ) : UInt32
end
# 構造体/GUID/enum は lib 内に対応する型定義が必要。
import 'dart:ffi';
import 'package:ffi/ffi.dart';

typedef ldap_bind_sNative = Uint32 Function(Pointer<Void>, Pointer<Utf8>, Pointer<Utf8>, Uint32);
typedef ldap_bind_sDart = int Function(Pointer<Void>, Pointer<Utf8>, Pointer<Utf8>, int);
final ldap_bind_s = DynamicLibrary.open('WLDAP32.dll')
    .lookupFunction<ldap_bind_sNative, ldap_bind_sDart>('ldap_bind_s');
// ld : LDAP* in/out -> Pointer<Void>
// dn : LPCSTR optional -> Pointer<Utf8>
// cred : LPCSTR optional -> Pointer<Utf8>
// method : DWORD -> Uint32
// 文字列は package:ffi の "...".toNativeUtf16()/toNativeUtf8() で変換。
{$mode objfpc}{$H+}
function ldap_bind_s(
  ld: Pointer;   // LDAP* in/out
  dn: PAnsiChar;   // LPCSTR optional
  cred: PAnsiChar;   // LPCSTR optional
  method: DWORD   // DWORD
): DWORD; cdecl;
  external 'WLDAP32.dll' name 'ldap_bind_s';
import Foreign
import Foreign.C.Types
import Foreign.C.String

foreign import ccall safe "ldap_bind_s"
  c_ldap_bind_s :: Ptr () -> CString -> CString -> Word32 -> IO Word32
-- ld : LDAP* in/out -> Ptr ()
-- dn : LPCSTR optional -> CString
-- cred : LPCSTR optional -> CString
-- method : DWORD -> Word32
-- 要 GHC(Windows)。stdcall は x64 では ccall として扱われる。ブロックする API は safe 呼び出し推奨。
open Ctypes
open Foreign

let ldap_bind_s =
  foreign "ldap_bind_s"
    ((ptr void) @-> string @-> string @-> uint32_t @-> returning uint32_t)
(* ld : LDAP* in/out -> (ptr void) *)
(* dn : LPCSTR optional -> string *)
(* cred : LPCSTR optional -> string *)
(* method : DWORD -> uint32_t *)
(* foreign は cdecl 前提。x64 Windows では WINAPI と一致。構造体は ctypes structure を定義のこと。 *)
(cffi:define-foreign-library wldap32 (t "WLDAP32.dll"))
(cffi:use-foreign-library wldap32)

(cffi:defcfun ("ldap_bind_s" ldap-bind-s :convention :cdecl) :uint32
  (ld :pointer)   ; LDAP* in/out
  (dn :string)   ; LPCSTR optional
  (cred :string)   ; LPCSTR optional
  (method :uint32))   ; DWORD
; isize/usize(INT_PTR/SIZE_T)は x64 前提で :int64/:uint64。x86 では :int32/:uint32。
use Win32::API;
my $ldap_bind_s = Win32::API::More->new('WLDAP32',
    'DWORD ldap_bind_s(LPVOID ld, LPCSTR dn, LPCSTR cred, DWORD method)');
# my $ret = $ldap_bind_s->Call($ld, $dn, $cred, $method);
# ld : LDAP* in/out -> LPVOID
# dn : LPCSTR optional -> LPCSTR
# cred : LPCSTR optional -> LPCSTR
# method : DWORD -> DWORD
# 値渡し構造体は pack() した文字列、または Win32::API::Struct を使用。

関連項目

文字セット違い
公式の関連項目
使用する型