ActiveDirectoryMembershipProvider.ValidateUser(String, String) 方法
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
驗證指定的使用者名稱與密碼是否存在於 Active Directory 資料儲存庫中。
public:
override bool ValidateUser(System::String ^ username, System::String ^ password);
public override bool ValidateUser(string username, string password);
override this.ValidateUser : string * string -> bool
Public Overrides Function ValidateUser (username As String, password As String) As Boolean
參數
- username
- String
使用者的名字來驗證。
- password
- String
指定使用者的密碼。
傳回
true若指定username且password有效;否則,。 false 若使用者指定的資料不存在於 Active Directory 資料儲存庫中,該 ValidateUser(String, String) 方法會回傳 false。
例外狀況
備註
此方法由類別呼叫 Membership ,以驗證使用者憑證與 Active Directory 資料儲存庫的關聯。
若屬性 EnablePasswordReset 成立 true 且提供的憑證有效,使用者的錯誤密碼追蹤計數器會被重置。
ValidateUser當提供正確憑證後,方法可能會回傳false,且在以下情況下:
由於登入失敗次數太多,該使用者帳號被目錄伺服器鎖定。 使用者必須等到目錄的鎖定時間結束才能登入。
如果屬性 EnablePasswordReset 是
true,且使用者多次提供錯誤密碼答案,該帳號將會被鎖定。 用戶帳號會在物業指定 PasswordAnswerAttemptLockoutDuration 時間過後解鎖。使用者必須存在於連接字串指定的容器中。 有效的憑證會被提供給位於不同容器或不同網域的使用者帳號。 使用者必須存在於連接字串指定的容器中。
在驗證使用者時,提供者會透過指定的使用者名稱與密碼連接 Active Directory 資料儲存來驗證憑證,而非應用程式設定檔中設定的憑證。
然而, ActiveDirectoryMembershipProvider 實例會根據設定的憑證連接到該目錄,原因如下。
以確認使用者是否存在於根據實例連接字串所判定 ActiveDirectoryMembershipProvider 的搜尋範圍內。 提供者會從連接字串指定的搜尋點開始,進行子樹搜尋來判斷使用者是否存在。 使用者必須存在於指定的容器中。 在連接字串指定容器外有效的憑證將不會被驗證。 有關連接字串的更多資訊,請參見 ActiveDirectoryMembershipProvider 課程主題。
如果屬性 EnablePasswordReset 為
true,實 ActiveDirectoryMembershipProvider 例會利用設定的憑證載入使用者實例,以檢查使用者是否因更改密碼答案失敗而被鎖定。
Important
啟用「訪客」帳號連接 Active Directory 網域控制器可能構成安全威脅。 所有在啟用「訪客」帳號的 Active Directory 網域控制器上進行的驗證嘗試都會成功。 為了提升使用 Active Directory 網域控制器的安全性,你應該在網域控制器上停用「訪客」帳號。
當符合以下任一條件時,實 ActiveDirectoryMembershipProvider 例將嘗試對 Active Directory 進行並行綁定:
CurrentConnectionProtection 屬性會設定為 None。
CurrentConnectionProtection屬性設定為 ,SignAndSeal實例選擇 ActiveDirectoryMembershipProvider SSL 來保護連線。
此外,若要建立並行綁定,必須符合以下條件:
目錄伺服器必須運行在 Windows Server 2003 上。
執行該 ActiveDirectoryMembershipProvider 實例的網頁伺服器作業系統必須支援並行綁定(例如 Windows Server 2003)。
當使用並行綁定時,使用者的最後登入日期不會在目錄中更新;因此, LastLoginDate 該財產不可依賴。
前置與後置空間從參數中被裁掉 username 。