Are there any command line options available to know the (user)account type?

Hemanth Thummala hemanth.thummala at nutanix.com
Fri Feb 16 22:37:18 UTC 2018


Thanks Ralph! This definitely helps. 

On 16/02/18, 2:09 PM, "Ralph Böhme" <slow at samba.org> wrote:

    On Fri, Feb 16, 2018 at 08:01:09PM +0000, Hemanth Thummala via samba-technical wrote:
    > Correct. Looks like that’s the only authoritative way to identify a machine
    > account. We are able to get this information using ldapsearch query using
    > anonymous bind.  But, we would like to know if this ldapsearch anonymous bind
    > works all the time to query for “SamAccountType” attribute for any user
    > account. Is there a possibility that this anonymous check can be blocked by
    > placing any restrictions on the Active Directory objects?
    
    duno, but on a member server why not bind with machine trust account credentials
    and use net ads search:
    
    # net ads search -P cn=NAME sAMAccountType
    
    ?
    
    -slow
    
    -- 
    Ralph Boehme, Samba Team       https://urldefense.proofpoint.com/v2/url?u=https-3A__samba.org_&d=DwIDaQ&c=s883GpUCOChKOHiocYtGcg&r=upHhZKvLG1wGJVQsvdamubutehC8co9bx_lsVXPKCKw&m=zS8gfu4MKmO13GCzft_RT2wdL2mBk_kz2KIYTP1dN84&s=NotKLEfTPAXqwlV9F3B12KlqO67b8TSkdjGNENI7fcU&e=
    Samba Developer, SerNet GmbH   https://urldefense.proofpoint.com/v2/url?u=https-3A__sernet.de_en_samba_&d=DwIDaQ&c=s883GpUCOChKOHiocYtGcg&r=upHhZKvLG1wGJVQsvdamubutehC8co9bx_lsVXPKCKw&m=zS8gfu4MKmO13GCzft_RT2wdL2mBk_kz2KIYTP1dN84&s=ybkFqrYa9_6VUolOvrFxa9JQFg144HDQ3KFLFWdkdrE&e=
    GPG Key Fingerprint: FAE2 C608 8A24 2520 51C5  59E4 AA1E 9B71 2639 9E46
    



More information about the samba-technical mailing list