关于ldapsearch验证特定用户是否属于指定组的查询问题咨询
Hey there! Let's work through this LDAP group membership check issue together—totally get the frustration when IT doesn't reply quickly, so let's break this down step by step.
First, let's spot a likely typo in your original filter that's probably causing problems. Look at the memberOf value in your query:memberOf=cn=groupname,ou=User Groups,ou=Groupsdc=something,dc=something
Notice the part ou=Groupsdc=something? You're missing a comma between ou=Groups and dc=something! That invalid DN would definitely make the filter fail, even if everything else is right. Let's fix that first—your corrected filter should look like this:
ldapsearch -x -H "ldap://ldap.server.edu:389" -P 3 -LLL -b "dc=something,dc=something" "(&(|(objectclass=inetOrgPerson)(objectclass=person)(objectclass=umichPerson))(uid=theuid)(memberOf=cn=groupname,ou=User Groups,ou=Groups,dc=something,dc=something))"
If fixing the DN doesn't work, the next thing to consider is that some LDAP servers (like OpenLDAP) don't enable the memberOf reverse attribute by default. memberOf is a computed attribute that links users back to their groups, but if your server isn't set up to maintain it, the attribute won't exist on user objects.
In that case, you can flip the query around to check the group's member attribute instead. Here's how:
- First, get the full DN of the user you're checking (since the
memberattribute stores full user DNs):ldapsearch -x -H "ldap://ldap.server.edu:389" -P 3 -LLL -b "dc=something,dc=something" "(uid=theuid)" dn - Then, query the group directly to see if that user DN is in its
memberlist:ldapsearch -x -H "ldap://ldap.server.edu:389" -P 3 -LLL -b "cn=groupname,ou=User Groups,ou=Groups,dc=something,dc=something" "(member=uid=theuid,dc=something,dc=something)"
If this returns the group entry, the user is definitely a member.
Another option if you need to check nested group memberships (e.g., the user is in a subgroup that's part of your target group) is to use the LDAP matching rule 1.2.840.113556.1.4.1941 (aka LDAP_MATCHING_RULE_IN_CHAIN). This lets you recursively check membership through nested groups. Your filter would look like this:
ldapsearch -x -H "ldap://ldap.server.edu:389" -P 3 -LLL -b "dc=something,dc=something" "(&(|(objectclass=inetOrgPerson)(objectclass=person)(objectclass=umichPerson))(uid=theuid)(memberOf:1.2.840.113556.1.4.1941:=cn=groupname,ou=User Groups,ou=Groups,dc=something,dc=something))"
Note that this rule is supported by Active Directory out of the box, but for OpenLDAP you might need to install and configure the memberof overlay first.
Start with fixing that DN typo—it's the most common quick fix here. If that doesn't resolve it, try the reverse group query. Let me know if you hit any snags!
备注:内容来源于stack exchange,提问作者John Sly

