Win32 API 日本語リファレンス
ホームNetworking.Ldap › ldap_bind_sW

ldap_bind_sW

関数
指定方式でLDAPサーバーに同期バインドする(Unicode版)。
DLLWLDAP32.dll文字セットUnicode (-W)呼出規約cdecl対応OSWindows Vista 以降

シグネチャ

// WLDAP32.dll  (Unicode / -W)
#include <windows.h>

DWORD ldap_bind_sW(
    LDAP* ld,
    LPWSTR dn,   // optional
    LPWSTR cred,   // optional
    DWORD method
);

パラメーター

名前方向説明
ldLDAP*inoutセッションハンドル。
dnLPWSTRinoptionalバインドに使用するエントリの識別名を格納する、null で終わる文字列へのポインター。DN、UPN、WinNT 形式のユーザー名、またはディレクトリサーバーが識別子として受け付けるその他の名前を指定できます。
credLPWSTRinoptional認証に使用する資格情報を格納する、null で終わる文字列へのポインター。このパラメーターを使用して任意の資格情報を渡すことができます。資格情報の形式と内容は、method パラメーターの設定によって異なります。詳細については「解説」を参照してください。
methodDWORDin使用する認証方法を示します。詳細および有効な非同期認証方法の一覧については、「解説」セクションを参照してください。詳細および有効な非同期認証方法の説明については、 ldap_bind を参照してください。

戻り値の型: DWORD

公式ドキュメント

ldap_bind_sW (Unicode) 関数 (winldap.h) は、クライアントを LDAP サーバーに対して同期的に認証します。

戻り値

関数が成功した場合、戻り値は LDAP_SUCCESS です。

関数が失敗した場合は、エラーコードを返します。詳細については、 Return Values を参照してください。

解説(Remarks)

Windows Server 2008 および Windows Vista でのユーザーアカウント制御 (User Account Control) の導入は、LDAP で変更や追加を行う際に非常に重要な影響を及ぼします。制限された UAC 管理者トークンでユーザーが DC にログオンし、NULL 資格情報を使用している場合、ディレクトリに対する変更や追加、およびスキーマ変更操作はすべて失敗します。これには、DirSync 検索、SecurityDescriptorFlags を使用してオブジェクトの ntSecurityDescriptor 属性から SACL を取得する操作、およびその他の多くの操作が含まれます。

これらはすべて、アクセス権の不足により失敗します。

管理者が DC にログオンするときにユーザーアカウント制御が有効になっている場合、管理者はログオンセッションで制限付きトークンを取得します。その状態で NULL 資格情報を指定して ldap_bind_s を使用すると、変更や追加を行う操作は失敗します。

ldap_bind_s の実装は、次の表に示す認証方法をサポートします。LDAP_AUTH_SIMPLE オプションを指定して ldap_bind_s を呼び出すことは、ldap_simple_bind_s を呼び出すことと同等です。

認証方法 説明 資格情報
LDAP_AUTH_SIMPLE プレーンテキストのパスワードによる認証。 ユーザーのパスワードを格納する文字列。
LDAP_AUTH_DIGEST ダイジェスト認証パッケージ。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_DPA 分散パスワード認証。Microsoft Membership System で使用されます。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_MSN Microsoft Network Authentication Service。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_NEGOTIATE 汎用セキュリティサービス (GSS) (Snego)。認証自体は提供せず、利用可能なサービスの一覧から最も適切な認証方法を選択し、すべての認証データをそのサービスに渡します。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY または SEC_WINNT_AUTH_IDENTITY_EX 構造体へのポインターを設定します。
LDAP_AUTH_NTLM NT LAN Manager 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY または SEC_WINNT_AUTH_IDENTITY_EX 構造体へのポインターを設定します。
LDAP_AUTH_SICILY MSN サーバーに対するパッケージのネゴシエーションに対応します。 現在のユーザーとしてログインするには、dn パラメーターと cred パラメーターを NULL に設定します。別のユーザーとしてログインするには、dn パラメーターを NULL に設定し、cred パラメーターには適切なユーザー名、ドメイン名、パスワードを設定した SEC_WINNT_AUTH_IDENTITY 構造体へのポインターを設定します。
LDAP_AUTH_SSPI 廃止されました。下位互換性のために含まれています。この定数を使用すると、GSS (Snego) ネゴシエーションサービスが選択されます。 LDAP_AUTH_NEGOTIATE と同じです。

非同期のバインド認証を行うには、ldap_bindLDAP_AUTH_SIMPLE を使用します。

バインド操作は、識別名とパスワードなどの何らかの認証資格情報を提供することで、クライアントをディレクトリサーバーに対して識別します。実際に必要な資格情報は、使用する認証方法によって異なります。ldap_bind_s() (simple 以外) で資格情報に NULL を渡すと、現在のユーザーまたはサービスの資格情報が使用されます。( ldap_simple_bind_s のように) simple バインド方法が指定されている場合は、NULL のプレーンテキストパスワードを指定したことと同等になります。詳細については、 ldap_bind を参照してください。

LDAP 2 サーバーでは、認証を必要とする他の操作を実行する前に、アプリケーションがバインドを行う必要があることに注意してください。

マルチスレッド: バインド呼び出しは接続全体に適用されるため、安全ではありません。スレッド間で接続を共有し、バインド操作を他の操作と並行してスレッド化しようとする場合は注意してください。

注意 Microsoft LDAP クライアントは、バインドと応答のラウンドトリップごとに既定のタイムアウト値として 120 秒 (2 分) を使用します。このタイムアウト値は、LDAP_OPT_TIMELIMIT セッションオプションを使用して変更できます。他の操作には、 ldap_set_option で指定しない限りタイムアウトはありません。
セッションハンドルに対するすべての操作が完了したら、LDAP セッションハンドルを ldap_unbind 関数に渡してセッションを終了する必要があります。また、ldap_bind_s の呼び出しが失敗した場合も、エラー回復のために不要になった時点で ldap_unbind を呼び出してセッションハンドルを解放してください。
メモ

winldap.h ヘッダーは、UNICODE プリプロセッサ定数の定義に基づいてこの関数の ANSI 版と Unicode 版を自動的に選択するエイリアスとして ldap_bind_s を定義しています。エンコーディング中立のエイリアスの使用と、エンコーディング中立でないコードを混在させると、不一致が生じ、コンパイルエラーや実行時エラーの原因となる可能性があります。詳細については、Conventions for Function Prototypes を参照してください。

出典・ライセンス: 上記「公式ドキュメント」の内容は Microsoft の Win32 API ドキュメント(MicrosoftDocs/sdk-api)を日本語に翻訳・改変したものです。© Microsoft Corporation. CC BY 4.0 で提供。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)

各言語での呼び出し定義

// WLDAP32.dll  (Unicode / -W)
#include <windows.h>

DWORD ldap_bind_sW(
    LDAP* ld,
    LPWSTR dn,   // optional
    LPWSTR cred,   // optional
    DWORD method
);
[DllImport("WLDAP32.dll", CharSet = CharSet.Unicode, ExactSpelling = true, CallingConvention = CallingConvention.Cdecl)]
static extern uint ldap_bind_sW(
    IntPtr ld,   // LDAP* in/out
    [MarshalAs(UnmanagedType.LPWStr)] string dn,   // LPWSTR optional
    [MarshalAs(UnmanagedType.LPWStr)] string cred,   // LPWSTR optional
    uint method   // DWORD
);
<DllImport("WLDAP32.dll", CharSet:=CharSet.Unicode, ExactSpelling:=True, CallingConvention:=CallingConvention.Cdecl)>
Public Shared Function ldap_bind_sW(
    ld As IntPtr,   ' LDAP* in/out
    <MarshalAs(UnmanagedType.LPWStr)> dn As String,   ' LPWSTR optional
    <MarshalAs(UnmanagedType.LPWStr)> cred As String,   ' LPWSTR optional
    method As UInteger   ' DWORD
) As UInteger
End Function
' ld : LDAP* in/out
' dn : LPWSTR optional
' cred : LPWSTR optional
' method : DWORD
Declare PtrSafe Function ldap_bind_sW Lib "wldap32" ( _
    ByVal ld As LongPtr, _
    ByVal dn As LongPtr, _
    ByVal cred As LongPtr, _
    ByVal method As Long) As Long
' Unicode(W): 文字列は ByVal As LongPtr とし StrPtr(unicodeStr) を渡す
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

ldap_bind_sW = ctypes.cdll.wldap32.ldap_bind_sW
ldap_bind_sW.restype = wintypes.DWORD
ldap_bind_sW.argtypes = [
    ctypes.c_void_p,  # ld : LDAP* in/out
    wintypes.LPCWSTR,  # dn : LPWSTR optional
    wintypes.LPCWSTR,  # cred : LPWSTR optional
    wintypes.DWORD,  # method : DWORD
]
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('WLDAP32.dll')
ldap_bind_sW = Fiddle::Function.new(
  lib['ldap_bind_sW'],
  [
    Fiddle::TYPE_VOIDP,  # ld : LDAP* in/out
    Fiddle::TYPE_VOIDP,  # dn : LPWSTR optional
    Fiddle::TYPE_VOIDP,  # cred : LPWSTR optional
    -Fiddle::TYPE_INT,  # method : DWORD
  ],
  -Fiddle::TYPE_INT, Fiddle::Function::CDECL)
# Wide strings: pass str.encode("UTF-16LE") + "\x00\x00"
#[link(name = "wldap32")]
extern "C" {
    fn ldap_bind_sW(
        ld: *mut LDAP,  // LDAP* in/out
        dn: *mut u16,  // LPWSTR optional
        cred: *mut u16,  // LPWSTR optional
        method: u32  // DWORD
    ) -> u32;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[DllImport("WLDAP32.dll", CharSet = CharSet.Unicode, CallingConvention = CallingConvention.Cdecl)]
public static extern uint ldap_bind_sW(IntPtr ld, [MarshalAs(UnmanagedType.LPWStr)] string dn, [MarshalAs(UnmanagedType.LPWStr)] string cred, uint method);
"@
$api = Add-Type -MemberDefinition $sig -Name 'WLDAP32_ldap_bind_sW' -Namespace Win32 -PassThru
# $api::ldap_bind_sW(ld, dn, cred, method)
#uselib "WLDAP32.dll"
#func global ldap_bind_sW "ldap_bind_sW" wptr, wptr, wptr, wptr
; ldap_bind_sW varptr(ld), dn, cred, method   ; 戻り値は stat
; ld : LDAP* in/out -> "wptr"
; dn : LPWSTR optional -> "wptr"
; cred : LPWSTR optional -> "wptr"
; method : DWORD -> "wptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "WLDAP32.dll"
#cfunc global ldap_bind_sW "ldap_bind_sW" var, wstr, wstr, int
; res = ldap_bind_sW(ld, dn, cred, method)
; ld : LDAP* in/out -> "var"
; dn : LPWSTR optional -> "wstr"
; cred : LPWSTR optional -> "wstr"
; method : DWORD -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; DWORD ldap_bind_sW(LDAP* ld, LPWSTR dn, LPWSTR cred, DWORD method)
#uselib "WLDAP32.dll"
#cfunc global ldap_bind_sW "ldap_bind_sW" var, wstr, wstr, int
; res = ldap_bind_sW(ld, dn, cred, method)
; ld : LDAP* in/out -> "var"
; dn : LPWSTR optional -> "wstr"
; cred : LPWSTR optional -> "wstr"
; method : DWORD -> "int"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	wldap32 = windows.NewLazySystemDLL("WLDAP32.dll")
	procldap_bind_sW = wldap32.NewProc("ldap_bind_sW")
)

// ld (LDAP* in/out), dn (LPWSTR optional), cred (LPWSTR optional), method (DWORD)
r1, _, err := procldap_bind_sW.Call(
	uintptr(ld),
	uintptr(unsafe.Pointer(windows.StringToUTF16Ptr(dn))),
	uintptr(unsafe.Pointer(windows.StringToUTF16Ptr(cred))),
	uintptr(method),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // DWORD
function ldap_bind_sW(
  ld: Pointer;   // LDAP* in/out
  dn: PWideChar;   // LPWSTR optional
  cred: PWideChar;   // LPWSTR optional
  method: DWORD   // DWORD
): DWORD; cdecl;
  external 'WLDAP32.dll' name 'ldap_bind_sW';
result := DllCall("WLDAP32\ldap_bind_sW"
    , "Ptr", ld   ; LDAP* in/out
    , "WStr", dn   ; LPWSTR optional
    , "WStr", cred   ; LPWSTR optional
    , "UInt", method   ; DWORD
    , "Cdecl UInt")   ; return: DWORD
●ldap_bind_sW(ld, dn, cred, method) = DLL("WLDAP32.dll", "dword ldap_bind_sW(void*, char*, char*, dword)")
# 呼び出し: ldap_bind_sW(ld, dn, cred, method)
# ld : LDAP* in/out -> "void*"
# dn : LPWSTR optional -> "char*"
# cred : LPWSTR optional -> "char*"
# method : DWORD -> "dword"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。
# ※-W(Unicode)関数。なでしこ1はANSIのため -A 版の利用を推奨。
# ※cdecl関数。DLL()宣言はstdcall前提。cdeclは EXEC_PTR(`cdecl`,…) を使用。
const std = @import("std");

extern "wldap32" fn ldap_bind_sW(
    ld: [*c]LDAP, // LDAP* in/out
    dn: [*c]const u16, // LPWSTR optional
    cred: [*c]const u16, // LPWSTR optional
    method: u32 // DWORD
) callconv(.c) u32;
// Unicode(-W): UTF-16LE のヌル終端バッファ([*c]const u16)を渡す。
proc ldap_bind_sW(
    ld: ptr LDAP,  # LDAP* in/out
    dn: WideCString,  # LPWSTR optional
    cred: WideCString,  # LPWSTR optional
    `method`: uint32  # DWORD
): uint32 {.importc: "ldap_bind_sW", cdecl, dynlib: "WLDAP32.dll".}
# Unicode(-W): WideCString は newWideCString("...") で生成。
pragma(lib, "wldap32");
extern(C)
uint ldap_bind_sW(
    LDAP* ld,   // LDAP* in/out
    const(wchar)* dn,   // LPWSTR optional
    const(wchar)* cred,   // LPWSTR optional
    uint method   // DWORD
);
ccall((:ldap_bind_sW, "WLDAP32.dll"), UInt32,
      (Ptr{LDAP}, Cwstring, Cwstring, UInt32),
      ld, dn, cred, method)
# ld : LDAP* in/out -> Ptr{LDAP}
# dn : LPWSTR optional -> Cwstring
# cred : LPWSTR optional -> Cwstring
# method : DWORD -> UInt32
# Unicode(-W): Cwstring には transcode(UInt16, "...") 等で UTF-16 を渡す。
local ffi = require("ffi")
ffi.cdef[[
uint32_t ldap_bind_sW(
    void* ld,
    const uint16_t* dn,
    const uint16_t* cred,
    uint32_t method);
]]
local wldap32 = ffi.load("wldap32")
-- wldap32.ldap_bind_sW(ld, dn, cred, method)
-- ld : LDAP* in/out
-- dn : LPWSTR optional
-- cred : LPWSTR optional
-- method : DWORD
-- 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
-- Unicode(-W): uint16_t* には UTF-16LE のバッファ(ffi.new("uint16_t[?]", ...))を渡す。
const koffi = require('koffi');
const lib = koffi.load('WLDAP32.dll');
const ldap_bind_sW = lib.func('__cdecl', 'ldap_bind_sW', 'uint32_t', ['void *', 'str16', 'str16', 'uint32_t']);
// ldap_bind_sW(ld, dn, cred, method)
// ld : LDAP* in/out -> 'void *'
// dn : LPWSTR optional -> 'str16'
// cred : LPWSTR optional -> 'str16'
// method : DWORD -> 'uint32_t'
// 出力ポインタは koffi.out(...) で包む。構造体は koffi.struct で定義。
const lib = Deno.dlopen("WLDAP32.dll", {
  ldap_bind_sW: { parameters: ["pointer", "buffer", "buffer", "u32"], result: "u32" },
});
// lib.symbols.ldap_bind_sW(ld, dn, cred, method)
// ld : LDAP* in/out -> "pointer"
// dn : LPWSTR optional -> "buffer"
// cred : LPWSTR optional -> "buffer"
// method : DWORD -> "u32"
// 文字列は "buffer"。Unicode(-W) は new TextEncoder() ではなく UTF-16LE のバイト列(末尾に \x00\x00)を Uint8Array で渡す。
// 値渡し構造体は { struct: [ ...field types... ] } を使用。
<?php
$ffi = FFI::cdef(<<<C
uint32_t ldap_bind_sW(
    void* ld,
    const uint16_t* dn,
    const uint16_t* cred,
    uint32_t method);
C, "WLDAP32.dll");
// $ffi->ldap_bind_sW(ld, dn, cred, method);
// ld : LDAP* in/out
// dn : LPWSTR optional
// cred : LPWSTR optional
// method : DWORD
// 構造体/GUIDへのポインタは cdef が通るよう void* で表記(実型は各引数コメント参照)。値渡し構造体・enum は対応する typedef を cdef に追加すること。
import com.sun.jna.*;
import com.sun.jna.ptr.*;
import com.sun.jna.win32.StdCallLibrary;
import com.sun.jna.win32.W32APIOptions;

public interface Wldap32 extends Library {
    Wldap32 INSTANCE = Native.load("wldap32", Wldap32.class, W32APIOptions.UNICODE_OPTIONS);
    int ldap_bind_sW(
        Pointer ld,   // LDAP* in/out
        WString dn,   // LPWSTR optional
        WString cred,   // LPWSTR optional
        int method   // DWORD
    );
}
// Unicode(-W): WString(入力)/char[](出力)で UTF-16 をマーシャリング。
@[Link("wldap32")]
lib LibWLDAP32
  fun ldap_bind_sW = ldap_bind_sW(
    ld : LDAP*,   # LDAP* in/out
    dn : UInt16*,   # LPWSTR optional
    cred : UInt16*,   # LPWSTR optional
    method : UInt32   # DWORD
  ) : UInt32
end
# 構造体/GUID/enum は lib 内に対応する型定義が必要。
import 'dart:ffi';
import 'package:ffi/ffi.dart';

typedef ldap_bind_sWNative = Uint32 Function(Pointer<Void>, Pointer<Utf16>, Pointer<Utf16>, Uint32);
typedef ldap_bind_sWDart = int Function(Pointer<Void>, Pointer<Utf16>, Pointer<Utf16>, int);
final ldap_bind_sW = DynamicLibrary.open('WLDAP32.dll')
    .lookupFunction<ldap_bind_sWNative, ldap_bind_sWDart>('ldap_bind_sW');
// ld : LDAP* in/out -> Pointer<Void>
// dn : LPWSTR optional -> Pointer<Utf16>
// cred : LPWSTR optional -> Pointer<Utf16>
// method : DWORD -> Uint32
// 文字列は package:ffi の "...".toNativeUtf16()/toNativeUtf8() で変換。
{$mode objfpc}{$H+}
function ldap_bind_sW(
  ld: Pointer;   // LDAP* in/out
  dn: PWideChar;   // LPWSTR optional
  cred: PWideChar;   // LPWSTR optional
  method: DWORD   // DWORD
): DWORD; cdecl;
  external 'WLDAP32.dll' name 'ldap_bind_sW';
import Foreign
import Foreign.C.Types
import Foreign.C.String

foreign import ccall safe "ldap_bind_sW"
  c_ldap_bind_sW :: Ptr () -> CWString -> CWString -> Word32 -> IO Word32
-- ld : LDAP* in/out -> Ptr ()
-- dn : LPWSTR optional -> CWString
-- cred : LPWSTR optional -> CWString
-- method : DWORD -> Word32
-- 要 GHC(Windows)。stdcall は x64 では ccall として扱われる。ブロックする API は safe 呼び出し推奨。
open Ctypes
open Foreign

let ldap_bind_sw =
  foreign "ldap_bind_sW"
    ((ptr void) @-> (ptr uint16_t) @-> (ptr uint16_t) @-> uint32_t @-> returning uint32_t)
(* ld : LDAP* in/out -> (ptr void) *)
(* dn : LPWSTR optional -> (ptr uint16_t) *)
(* cred : LPWSTR optional -> (ptr uint16_t) *)
(* method : DWORD -> uint32_t *)
(* foreign は cdecl 前提。x64 Windows では WINAPI と一致。構造体は ctypes structure を定義のこと。 *)
(cffi:define-foreign-library wldap32 (t "WLDAP32.dll"))
(cffi:use-foreign-library wldap32)

(cffi:defcfun ("ldap_bind_sW" ldap-bind-s-w :convention :cdecl) :uint32
  (ld :pointer)   ; LDAP* in/out
  (dn (:string :encoding :utf-16le))   ; LPWSTR optional
  (cred (:string :encoding :utf-16le))   ; LPWSTR optional
  (method :uint32))   ; DWORD
; isize/usize(INT_PTR/SIZE_T)は x64 前提で :int64/:uint64。x86 では :int32/:uint32。
use Win32::API;
my $ldap_bind_sW = Win32::API::More->new('WLDAP32',
    'DWORD ldap_bind_sW(LPVOID ld, LPCWSTR dn, LPCWSTR cred, DWORD method)');
# my $ret = $ldap_bind_sW->Call($ld, $dn, $cred, $method);
# ld : LDAP* in/out -> LPVOID
# dn : LPWSTR optional -> LPCWSTR
# cred : LPWSTR optional -> LPCWSTR
# method : DWORD -> DWORD
# 値渡し構造体は pack() した文字列、または Win32::API::Struct を使用。
# Unicode(-W): LPCWSTR/LPWSTR は Win32::API が UTF-16 変換を行う。

関連項目

文字セット違い
公式の関連項目
使用する型