如果要禁用Windows Active Directory中的帐户,
您可以尝试这个(在我的Win2k环境中有效)
(foo.bar应该替换为"$ldapBase"中的正确
域名,例如,如果您的域名是phpfreackx.com,则为"DC=phpfreackx,DC=com")
domctrl = 域控制器
domadlogin = 域管理员登录名
domadpw = 域管理员密码
username = 用户帐户的登录名(例如,“john.doe”)
enable =1(如果要启用它,则为0,如果要禁用它)
<?php
function userchange($username,$enable=1,$domadlogin,$domadpw,$domctrl)
{
$ldapServer = $domctrl;
$ldapBase = 'DC=foo,DC=bar';
$ds = ldap_connect($ldapServer);
if (!$ds) {die('无法连接到LDAP服务器');}
$ldapBind = ldap_bind($ds,$domadlogin,$domadpw);
if (!$ldapBind) {die('无法绑定到LDAP服务器');}
ldap_set_option($ds, LDAP_OPT_PROTOCOL_VERSION, 3);
$sr = ldap_search($ds, $ldapBase, "(samaccountname=$username)");
$ent= ldap_get_entries($ds,$sr);
$dn=$ent[0]["dn"];
$ac = $ent[0]["useraccountcontrol"][0];
$disable=($ac | 2); $enable =($ac & ~2); $userdata=array();
if ($enable==1) $new=$enable; else $new=$disable; $userdata["useraccountcontrol"][0]=$new;
ldap_modify($ds, $dn, $userdata); $sr = ldap_search($ds, $ldapBase, "(samaccountname=$username)");
$ent= ldap_get_entries($ds,$sr);
$ac = $ent[0]["useraccountcontrol"][0];
if (($ac & 2)==2) $status=0; else $status=1;
ldap_close($ds);
return $status; }
?>