Are there any command line options available to know the (user)account type?
Hemanth Thummala
hemanth.thummala at nutanix.com
Fri Feb 16 22:37:18 UTC 2018
Thanks Ralph! This definitely helps.
On 16/02/18, 2:09 PM, "Ralph Böhme" <slow at samba.org> wrote:
On Fri, Feb 16, 2018 at 08:01:09PM +0000, Hemanth Thummala via samba-technical wrote:
> Correct. Looks like that’s the only authoritative way to identify a machine
> account. We are able to get this information using ldapsearch query using
> anonymous bind. But, we would like to know if this ldapsearch anonymous bind
> works all the time to query for “SamAccountType” attribute for any user
> account. Is there a possibility that this anonymous check can be blocked by
> placing any restrictions on the Active Directory objects?
duno, but on a member server why not bind with machine trust account credentials
and use net ads search:
# net ads search -P cn=NAME sAMAccountType
?
-slow
--
Ralph Boehme, Samba Team https://urldefense.proofpoint.com/v2/url?u=https-3A__samba.org_&d=DwIDaQ&c=s883GpUCOChKOHiocYtGcg&r=upHhZKvLG1wGJVQsvdamubutehC8co9bx_lsVXPKCKw&m=zS8gfu4MKmO13GCzft_RT2wdL2mBk_kz2KIYTP1dN84&s=NotKLEfTPAXqwlV9F3B12KlqO67b8TSkdjGNENI7fcU&e=
Samba Developer, SerNet GmbH https://urldefense.proofpoint.com/v2/url?u=https-3A__sernet.de_en_samba_&d=DwIDaQ&c=s883GpUCOChKOHiocYtGcg&r=upHhZKvLG1wGJVQsvdamubutehC8co9bx_lsVXPKCKw&m=zS8gfu4MKmO13GCzft_RT2wdL2mBk_kz2KIYTP1dN84&s=ybkFqrYa9_6VUolOvrFxa9JQFg144HDQ3KFLFWdkdrE&e=
GPG Key Fingerprint: FAE2 C608 8A24 2520 51C5 59E4 AA1E 9B71 2639 9E46
More information about the samba-technical
mailing list