Cercare un utente

Trova un utente tramite sAMAccountName e mostra gli attributi principali (nome, e-mail, DN, gruppi).

Active Directory

Nome utente (sAMAccountName)
jdoe Modifica nel generatore →

PowerShell (Windows)

DirectorySearcher (.NET) Integrato

$s = New-Object DirectoryServices.DirectorySearcher
$s.SearchRoot = "LDAP://dc01.example.com/DC=example,DC=com"
$s.Filter = "(sAMAccountName=jdoe)"
"displayName", "mail", "distinguishedName", "memberOf" | ForEach-Object { [void]$s.PropertiesToLoad.Add($_) }
$r = $s.FindOne()
if ($r) { $r.Properties } else { "not found" }

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -b "DC=example,DC=com" "(sAMAccountName=jdoe)" displayName mail distinguishedName memberOf

Shell Unix (bash)

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -b "DC=example,DC=com" "(sAMAccountName=jdoe)" displayName mail distinguishedName memberOf

curl Strumento aggiuntivo

curl -s "ldap://dc01.example.com/DC=example,DC=com?displayName,mail?sub?(sAMAccountName=jdoe)"

Senza dati di bind, la ricerca viene eseguita con l'utente Windows connesso (autenticazione integrata). Linux non ha un client LDAP integrato: usate ldapsearch (openldap-clients / ldap-utils) o curl con supporto LDAP; per ldapsearch aggiungete se necessario -D <bind DN> -W.

Testare bind / accesso

Verifica se un account può effettuare il bind (autenticarsi) alla directory.

PowerShell (Windows)

DirectoryEntry (.NET) Integrato

$de = New-Object DirectoryServices.DirectoryEntry("LDAP://dc01.example.com", "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com", "P@ssw0rd")
try { $null = $de.NativeObject; "bind ok: $($de.distinguishedName)" }
catch { "bind failed: $($_.Exception.Message)" }

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -D "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com" -W -b "" -s base "(objectClass=*)" 1.1

Shell Unix (bash)

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -D "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com" -W -b "" -s base "(objectClass=*)" 1.1

curl Strumento aggiuntivo

curl -s -u "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com:P@ssw0rd" "ldap://dc01.example.com/"

Sostituite P@ssw0rd con la password reale. -W in ldapsearch chiede la password in modo interattivo.

Filtro personalizzato

Esegue una ricerca LDAP con un filtro libero ed elenca i DN trovati.

PowerShell (Windows)

DirectorySearcher (.NET) Integrato

$root = New-Object DirectoryServices.DirectoryEntry("LDAP://dc01.example.com/DC=example,DC=com", "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com", "P@ssw0rd")
$s = New-Object DirectoryServices.DirectorySearcher($root, "(&(objectClass=user)(sAMAccountName=jdoe))")
$s.PageSize = 200
$s.FindAll() | ForEach-Object { $_.Properties["distinguishedname"] }

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -D "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com" -W -b "DC=example,DC=com" "(&(objectClass=user)(sAMAccountName=jdoe))" dn

Shell Unix (bash)

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -D "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com" -W -b "DC=example,DC=com" "(&(objectClass=user)(sAMAccountName=jdoe))" dn

curl Strumento aggiuntivo

curl -s -u "CN=svc-ldap,OU=Service Accounts,DC=example,DC=com:P@ssw0rd" "ldap://dc01.example.com/DC=example,DC=com?dn?sub?(&(objectClass=user)(sAMAccountName=jdoe))"

Sostituite P@ssw0rd con la password reale. Per una ricerca anonima, eliminate la parte di bind.

Root DSE

Legge il Root DSE: naming context, nome host e versione LDAP supportata, senza autenticazione.

PowerShell (Windows)

[ADSI] RootDSE Integrato

$r = [ADSI]"LDAP://dc01.example.com/RootDSE"
$r.defaultNamingContext; $r.dnsHostName; $r.supportedLDAPVersion; $r.rootDomainNamingContext

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -s base -b "" "(objectClass=*)" +

Shell Unix (bash)

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldap://dc01.example.com -s base -b "" "(objectClass=*)" +

curl Strumento aggiuntivo

curl -s "ldap://dc01.example.com/?+?base?(objectClass=*)"

LDAPS (636)

Verifica la connessione LDAP cifrata e ne mostra il certificato.

LDAPS (636)

PowerShell (Windows)

SslStream (.NET) Integrato

$h = "dc01.example.com"; $p = 636
$c = New-Object Net.Sockets.TcpClient($h, $p)
$ssl = New-Object Net.Security.SslStream($c.GetStream(), $false, ({ $true }))
$ssl.AuthenticateAsClient($h)
([Security.Cryptography.X509Certificates.X509Certificate2]$ssl.RemoteCertificate) | Format-List Subject, Issuer, NotAfter
$ssl.Dispose(); $c.Close()

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldaps://dc01.example.com:636 -s base -b "" "(objectClass=*)" 1.1

Shell Unix (bash)

openssl Integrato

openssl s_client -connect dc01.example.com:636 </dev/null 2>/dev/null | openssl x509 -noout -subject -dates

ldapsearch Strumento aggiuntivo

LDAPTLS_REQCERT=allow ldapsearch -x -H ldaps://dc01.example.com:636 -s base -b "" "(objectClass=*)" 1.1

Globaler Katalog (3269)

PowerShell (Windows)

SslStream (.NET) Integrato

$h = "dc01.example.com"; $p = 3269
$c = New-Object Net.Sockets.TcpClient($h, $p)
$ssl = New-Object Net.Security.SslStream($c.GetStream(), $false, ({ $true }))
$ssl.AuthenticateAsClient($h)
([Security.Cryptography.X509Certificates.X509Certificate2]$ssl.RemoteCertificate) | Format-List Subject, Issuer, NotAfter
$ssl.Dispose(); $c.Close()

ldapsearch Strumento aggiuntivo

ldapsearch -x -H ldaps://dc01.example.com:3269 -s base -b "" "(objectClass=*)" 1.1

Shell Unix (bash)

openssl Integrato

openssl s_client -connect dc01.example.com:3269 </dev/null 2>/dev/null | openssl x509 -noout -subject -dates

ldapsearch Strumento aggiuntivo

LDAPTLS_REQCERT=allow ldapsearch -x -H ldaps://dc01.example.com:3269 -s base -b "" "(objectClass=*)" 1.1

LDAPTLS_REQCERT=allow accetta anche un certificato non attendibile, così la connessione di prova riesce.

Altre aree