Thanks again
----- Cary Shultz [A.D. MVP] wrote: -----
Well,
I am thinking that if I gave you one piece of the puzzle I might as well
give it all to you. Sorry for the multiple posts. Anyway, you can do this
for the computer accounts as well as the user accounts. This should give
you three .ldf files and if might be a bit easier for you. Here is the
syntax:
ldifde -f computers.ldf -s servername -t 389 -d "DC=yourdomain,DC=com" -p
subtree - r "(&(objectCategory=computer)(objectClass=user))
This will give you an .ldf file named 'computers.ldf' from which you can see
what computer accounts are in your domain.
ldifde -f users.ldf -s servername -t 389 -d "DC=yourdomain,DC=com" -p
subtree - r "(&(objectCategory=person)(objectClass=user))"
This will give you a third file named 'users.ldf' from which you can see
what user accounts are in your domain.
Just a hint: if you need only specific attributes to be listed in the
output files ( groups.ldf, computers.ldf and users.ldf ) then you can add
the -l switch ( that is the lower case letter 'L' ) at the end of each line
with the specific attributes that you want / need. Here are some examples:
================
ldifde -f groups.ldf -s yourservername -t 389 -d "DC=yourdomain,DC=com" -p
subtree -r "(objectClass=group)" -l "DN,mail,groupType,members"
This will give you the Distinguished Name, the e-mail address associated
with the group ( if applicable ), the type of group ( security /
distribution and local, global, universal ) and the members of that group.
================
ldifde -f computers.ldf -s servername -t 389 -d "DC=yourdomain,DC=com" -p
subtree - r "(&(objectCategory=computer)(objectClass=user)) -l
"DN,sAMAccountName,operatingSystem,operatingSystemVersion,operatingSystemSer
vicePack"
This will give you the Distinguished Name, the 'old stlye name', the
Operating System, the Operating System Version and the Operating System
Service Pack level.
These two examples are what I typically use. You may need / want other
attributes to be included in the output files.
HTH,
Cary
"DC=yourdomain,DC=com" -p
subtree -r "(objectClass=group)" happens
when