<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>http://wiki.define-technology.com/mediawiki-1.35.0/index.php?action=history&amp;feed=atom&amp;title=Linux%3A_using_ldapsearch_to_debug_Active_Directory</id>
	<title>Linux: using ldapsearch to debug Active Directory - Revision history</title>
	<link rel="self" type="application/atom+xml" href="http://wiki.define-technology.com/mediawiki-1.35.0/index.php?action=history&amp;feed=atom&amp;title=Linux%3A_using_ldapsearch_to_debug_Active_Directory"/>
	<link rel="alternate" type="text/html" href="http://wiki.define-technology.com/mediawiki-1.35.0/index.php?title=Linux:_using_ldapsearch_to_debug_Active_Directory&amp;action=history"/>
	<updated>2026-05-04T22:47:02Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.0</generator>
	<entry>
		<id>http://wiki.define-technology.com/mediawiki-1.35.0/index.php?title=Linux:_using_ldapsearch_to_debug_Active_Directory&amp;diff=29424&amp;oldid=prev</id>
		<title>Antony c: first post</title>
		<link rel="alternate" type="text/html" href="http://wiki.define-technology.com/mediawiki-1.35.0/index.php?title=Linux:_using_ldapsearch_to_debug_Active_Directory&amp;diff=29424&amp;oldid=prev"/>
		<updated>2019-11-12T16:31:55Z</updated>

		<summary type="html">&lt;p&gt;first post&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;When using SSSD to authenticate against AD with &amp;quot;ldap_id_mapping = False&amp;quot; a user must have ALL posix attributes to be able to login&lt;br /&gt;
&lt;br /&gt;
when customers tell you that it is done for all users and another user works and one doesn&amp;#039;t and you need the smoking gun . . . here is how you find it:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ldapsearch -x -W -D &amp;#039;zSvcJoinDomainLinux@INT.CORP.GEL.AC&amp;#039; -b &amp;#039;dc=corp,dc=gel,dc=ac&amp;#039; -H ldap://10.105.15.20 -s sub &amp;quot;(CN=Donald Trumper)&amp;quot;&lt;br /&gt;
&lt;br /&gt;
this is an example from GEL (with name changed so as not to violate GDPR):&lt;br /&gt;
&lt;br /&gt;
* -D is the user to bind to LDAP as in this case the user they gave us to join nodes to this domain&lt;br /&gt;
* -b is the bind dn for the domain in this case we know the user should be in the CORP.GEL.AC domain&lt;br /&gt;
* -H ldap://10.105.15.20 is one of the AD servers we are joined to&lt;br /&gt;
* -s sub &amp;quot;(CN=Donald Trumper)&amp;quot; is the specific user we are looking for and when we look we see that he doesn&amp;#039;t have a gidNumber so won&amp;#039;t be allowed in&lt;br /&gt;
&lt;br /&gt;
  [root@p2postlog0002 ~]# ldapsearch -x -W -D &amp;#039;zSvcJoinDomainLinux@INT.CORP.GEL.AC&amp;#039; -b &amp;#039;dc=corp,dc=gel,dc=ac&amp;#039; -H ldap://10.105.15.20 -s sub &amp;quot;(CN=Donald Trumper)&amp;quot;&lt;br /&gt;
  Enter LDAP Password: &lt;br /&gt;
  # extended LDIF&lt;br /&gt;
  #&lt;br /&gt;
  # LDAPv3&lt;br /&gt;
  # base &amp;lt;dc=corp,dc=gel,dc=ac&amp;gt; with scope subtree&lt;br /&gt;
  # filter: (CN=Donald Trumper)&lt;br /&gt;
  # requesting: ALL&lt;br /&gt;
  #&lt;br /&gt;
  &lt;br /&gt;
  # Donald Trumper, GEL, Users, GEL, corp.gel.ac&lt;br /&gt;
  dn: CN=Donald Trumper,OU=GEL,OU=Users,OU=GEL,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  objectClass: top&lt;br /&gt;
  objectClass: person&lt;br /&gt;
  objectClass: organizationalPerson&lt;br /&gt;
  objectClass: user&lt;br /&gt;
  cn: Donald Trumper&lt;br /&gt;
  sn: Trumper&lt;br /&gt;
  title: Commercial Proposition and Product Manager&lt;br /&gt;
  description: Permanent&lt;br /&gt;
  physicalDeliveryOfficeName: Dawson Hall&lt;br /&gt;
  givenName: Donald&lt;br /&gt;
  distinguishedName: CN=Donald Trumper,OU=GEL,OU=Users,OU=GEL,DC=corp,DC=gel,DC&lt;br /&gt;
   =ac&lt;br /&gt;
  instanceType: 4&lt;br /&gt;
  whenCreated: 20190716101933.0Z&lt;br /&gt;
  whenChanged: 20191112083729.0Z&lt;br /&gt;
  displayName: Donald Trumper&lt;br /&gt;
  uSNCreated: 139477&lt;br /&gt;
  memberOf: CN=O365-SelfService-PasswordReset,OU=Applications,OU=Groups,OU=GEL,D&lt;br /&gt;
   C=corp,DC=gel,DC=ac&lt;br /&gt;
  uSNChanged: 829130&lt;br /&gt;
  department: Commercial&lt;br /&gt;
  proxyAddresses: SMTP:Donald.Trumper@genomicsengland.co.uk&lt;br /&gt;
  proxyAddresses: smtp:Donald.Trumper@genomicsenglandltd.mail.onmicrosoft.com&lt;br /&gt;
  proxyAddresses: x500:/o=ExchangeLabs/ou=Exchange Administrative Group (FYDIBOH&lt;br /&gt;
   F23SPDLT)/cn=Recipients/cn=c8aab061b3894a979b1f3f1959697821-Donald Nanki&lt;br /&gt;
  name: Donald Trumper&lt;br /&gt;
  objectGUID:: FWMDEkpkwk6jL6h4s1itQw==&lt;br /&gt;
  userAccountControl: 66048&lt;br /&gt;
  badPwdCount: 0&lt;br /&gt;
  codePage: 0&lt;br /&gt;
  countryCode: 0&lt;br /&gt;
  pwdLastSet: 132180206048436784&lt;br /&gt;
  primaryGroupID: 513&lt;br /&gt;
  objectSid:: AQUAAAAAAAUVAAAAz0olKw83ALo6csJV3AQAAA==&lt;br /&gt;
  accountExpires: 9223372036854775807&lt;br /&gt;
  sAMAccountName: Donald.Trumper&lt;br /&gt;
  sAMAccountType: 805306368&lt;br /&gt;
  showInAddressBook: CN=All Recipients(VLV),CN=All System Address Lists,CN=Addre&lt;br /&gt;
   ss Lists Container,CN=Genomics,CN=Microsoft Exchange,CN=Services,CN=Configura&lt;br /&gt;
   tion,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  showInAddressBook: CN=Default Global Address List,CN=All Global Address Lists,&lt;br /&gt;
   CN=Address Lists Container,CN=Genomics,CN=Microsoft Exchange,CN=Services,CN=C&lt;br /&gt;
   onfiguration,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  showInAddressBook: CN=All Users,CN=All Address Lists,CN=Address Lists Containe&lt;br /&gt;
   r,CN=Genomics,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=corp,DC=g&lt;br /&gt;
   el,DC=ac&lt;br /&gt;
  legacyExchangeDN: /o=Genomics/ou=Exchange Administrative Group (FYDIBOHF23SPDL&lt;br /&gt;
   T)/cn=Recipients/cn=68ff8beeb37d4296a3bc8fc6cb40bb2c-Donald Trumper&lt;br /&gt;
  userPrincipalName: Donald.Trumper@genomicsengland.co.uk&lt;br /&gt;
  lockoutTime: 0&lt;br /&gt;
  objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  dSCorePropagationData: 20190903120415.0Z&lt;br /&gt;
  dSCorePropagationData: 16010101000001.0Z&lt;br /&gt;
  mS-DS-ConsistencyGuid:: FWMDEkpkwk6jL6h4s1itQw==&lt;br /&gt;
  msDS-SupportedEncryptionTypes: 0&lt;br /&gt;
  msDS-ExternalDirectoryObjectId: User_a15bc18c-a3cd-4c3e-8118-7ffeefb42225&lt;br /&gt;
  mail: Donald.Trumper@genomicsengland.co.uk&lt;br /&gt;
  manager: CN=Carl Smith,OU=GEL,OU=Users,OU=GEL,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  uidNumber: 32613&lt;br /&gt;
  msExchVersion: 88218628259840&lt;br /&gt;
  msExchPoliciesIncluded: 316e658b-7875-40fb-a467-5a28d79efd21&lt;br /&gt;
  msExchPoliciesIncluded: {26491cfc-9e50-4857-861b-0cb8df22b5d7}&lt;br /&gt;
  targetAddress: SMTP:Donald.Trumper@genomicsenglandltd.mail.onmicrosoft.com&lt;br /&gt;
  msExchUMDtmfMap: emailAddress:37265626548355&lt;br /&gt;
  msExchUMDtmfMap: lastNameFirstName:62654835537265&lt;br /&gt;
  msExchUMDtmfMap: firstNameLastName:37265626548355&lt;br /&gt;
  msExchRecipientDisplayType: -2147483642&lt;br /&gt;
  mailNickname: Donald.Trumper&lt;br /&gt;
  msExchMailboxGuid:: KwBgAAPE2UabehM5pv31gg==&lt;br /&gt;
  msExchBlockedSendersHash:: JCe8iw==&lt;br /&gt;
  msExchRemoteRecipientType: 1&lt;br /&gt;
  msExchRecipientTypeDetails: 2147483648&lt;br /&gt;
  &lt;br /&gt;
  # search reference&lt;br /&gt;
  ref: ldap://int.corp.gel.ac/DC=int,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  &lt;br /&gt;
  # search reference&lt;br /&gt;
  ref: ldap://DomainDnsZones.corp.gel.ac/DC=DomainDnsZones,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  &lt;br /&gt;
  # search reference&lt;br /&gt;
  ref: ldap://ForestDnsZones.corp.gel.ac/DC=ForestDnsZones,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  &lt;br /&gt;
  # search reference&lt;br /&gt;
  ref: ldap://corp.gel.ac/CN=Configuration,DC=corp,DC=gel,DC=ac&lt;br /&gt;
  &lt;br /&gt;
  # search result&lt;br /&gt;
  search: 2&lt;br /&gt;
  result: 0 Success&lt;br /&gt;
  &lt;br /&gt;
  # numResponses: 6&lt;br /&gt;
  # numEntries: 1&lt;br /&gt;
  # numReferences: 4&lt;br /&gt;
  [root@p2postlog0002 ~]#&lt;/div&gt;</summary>
		<author><name>Antony c</name></author>
	</entry>
</feed>