求助:Linux下用ldapsearch获取计算机详情失败,求排查命令问题
Let's break down why your ldapsearch command isn't returning the computer info you expect, and fix it step by step.
First: The Shell Escape Issue (Most Likely Culprit)
In bash and similar shells, the & character is a special symbol used to run commands in the background. When you wrap your LDAP filter in double quotes, the shell parses the & before passing it to ldapsearch, which mangles your filter syntax. That's probably why your command fails outright.
Fix the Filter Syntax
To avoid this, wrap your entire filter in single quotes (so the shell leaves special characters like & untouched):
ldapsearch -t -x -D "ashu@example.com" -W -H ldaps://ldap.example.com:3269 -b "DC=example,DC=com" '(& (objectcategory=computer)(description=INXXXXX.example.com))'
Alternatively, if you prefer double quotes, escape the & with a backslash:
ldapsearch -t -x -D "ashu@example.com" -W -H ldaps://ldap.example.com:3269 -b "DC=example,DC=com" "(\&(objectcategory=computer)(description=INXXXXX.example.com))"
Second: Verify You're Using the Right Field to Match the Computer
It's unusual to use the description field to look up a computer by name. In Active Directory:
- The computer's NetBIOS name is stored in
samaccountname(and it always ends with a$, e.g.,INXXXXX$) - The full DNS name is often in the
dNSHostNamefield - The common name is in
cn
Chances are, the description field for your computer isn't actually set to INXXXXX.example.com. To confirm, first list all computers and their key fields:
ldapsearch -t -x -D "ashu@example.com" -W -H ldaps://ldap.example.com:3269 -b "DC=example,DC=com" "(objectcategory=computer)" samaccountname cn dNSHostName description
This will show you exactly what values exist for each computer. Then adjust your filter to use the correct field. For example, to search by DNS hostname:
ldapsearch -t -x -D "ashu@example.com" -W -H ldaps://ldap.example.com:3269 -b "DC=example,DC=com" '(& (objectcategory=computer)(dNSHostName=INXXXXX.example.com))'
Or by samaccountname:
ldapsearch -t -x -D "ashu@example.com" -W -H ldaps://ldap.example.com:3269 -b "DC=example,DC=com" '(& (objectcategory=computer)(samaccountname=INXXXXX$))'
Third: Double-Check Your Base DN
If your computers are organized in a specific Organizational Unit (OU) instead of the root DC=example,DC=com, narrow your search base to that OU to improve performance and avoid missing entries. For example:
ldapsearch -t -x -D "ashu@example.com" -W -H ldaps://ldap.example.com:3269 -b "OU=Servers,DC=example,DC=com" '(& (objectcategory=computer)(dNSHostName=INXXXXX.example.com))'
Final Checks
- Ensure your account (
ashu@example.com) has permission to read computer objects in the target LDAP path. Since you could query user info earlier, this is probably fine, but it's worth confirming if all other fixes fail. - For strict accuracy, you can use the full LDAP path for
objectcategoryinstead of the shorthand:objectcategory=CN=Computer,CN=Schema,CN=Configuration,DC=example,DC=com— the shorthand usually works, but the full path eliminates ambiguity.
内容的提问来源于stack exchange,提问作者Ashutosh Kumar

