Anyone know how to dump/output Active Directory Policies from Unix?

Jason Haar Jason.Haar at
Thu Apr 6 02:53:12 GMT 2006

Jason Haar wrote:
> Says it all really. I'd like to start "diff"'ing AD policies on a
> routine basis as a way of tracking/Change Control.
> (i.e. to be able to track additions/deletions/changes made to policies)
> Is there a way to do that from Unix? (actually, I can't think of a way
> of doing it from Windows either ;-)
Too quick with the email - I've figured it out

ldapsearch -x  -b cn=policies,cn=system,dc=xxx,dc=domain,dc=com
displayName whencreated whenchanged

will do the trick


Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1

More information about the samba-technical mailing list