ldapsearch
ldapsearchは LDAP サーバーに接続し、検索条件に一致するエントリを LDIF 形式で表示するコマンド。
ldapsearch \ -x \ -H ldap://ldap.example.com/ \ -ZZ \ -b "dc=example,dc=com" \ "(uid=ldapuser)"この例では、 ldap.example.com に StartTLS で接続し、 dc=example,dc=com 配下から uid=ldapuser のエントリを検索する。
何を確認できるか
Section titled “何を確認できるか”ldapsearch は LDAP サーバーへ直接問い合わせる。
ldapsearch -> LDAP protocol -> slapdそのため、次の確認に向いている。
- LDAP サーバーへ接続できるか
- Base DN が正しいか
- 検索フィルターに一致するエントリがあるか
- LDAP 側の属性値がどう保存されているか
- Bind DN とパスワードが正しいか
- TLS 設定が正しいか
Linux がユーザーとして認識しているかは、 ldapsearch ではなく getent passwd や id で確認する。
よく使うオプション
Section titled “よく使うオプション”| オプション | 意味 |
|---|---|
-x |
Simple Bind を使う |
-H URI |
LDAP サーバーの URI を指定する |
-b DN |
検索を開始する Base DN を指定する |
-D DN |
Bind DN を指定する |
-W |
Bind パスワードを対話入力する |
-ZZ |
StartTLS を必須にする |
-LLL |
LDIF 出力から余分な情報を減らす |
-s base |
Base DN そのものだけ検索する |
-s one |
Base DN 直下だけ検索する |
-s sub |
Base DN 配下を再帰的に検索する |
-z N |
最大 N 件まで取得する |
-W はパスワードを対話入力する。 -w password でコマンドラインに直接書くこともできるが、履歴やプロセス一覧に残る可能性があるため避ける。
検索結果に表示する属性は、検索フィルターの後ろに並べる。
ldapsearch \ -x \ -H ldap://ldap.example.com/ \ -ZZ \ -b "ou=people,dc=example,dc=com" \ "(uid=ldapuser)" \ uid uidNumber gidNumber homeDirectory loginShell* は通常属性、 + は operational attribute を表す。
ldapsearch \ -x \ -H ldap://ldap.example.com/ \ -ZZ \ -b "dc=example,dc=com" \ "(uid=ldapuser)" \ "*" "+"検索スコープ
Section titled “検索スコープ”-s で検索範囲を指定できる。
| 値 | 意味 |
|---|---|
base |
Base DN のエントリだけ |
one |
Base DN の 1 階層下だけ |
sub |
Base DN 配下すべて |
Base DN そのものが存在するかを見るときは base が便利である。
ldapsearch \ -x \ -H ldap://ldap.example.com/ \ -ZZ \ -b "dc=example,dc=com" \ -s base \ "(objectClass=*)"エントリが見つかると、次のように dn: から始まる LDIF が表示される。
dn: uid=ldapuser,ou=people,dc=example,dc=comuid: ldapuseruidNumber: 10000gidNumber: 10000homeDirectory: /home/ldapuserloginShell: /bin/bash検索自体は成功していても、条件に一致するエントリがなければ結果は空になる。接続失敗、認証失敗、TLS 失敗、Base DN 不正などはエラーメッセージと非ゼロ終了ステータスになる。
Debian manpages
Section titled “Debian manpages”- ldapsearch(1) LDAP 検索コマンド。検索ベース、検索スコープ、Bind、StartTLS、出力形式など。