Writing LDAP search filter

LDAP search filter is useful in Apache LDAP authentication and Ironport.

Under Ironport, I use the below filter to search for valid user with his aliase :


I use the below to search if an user/alias is in a specific posix group :


Under OpenLDAP, to search a user :

ldapsearch -x -b ‘dc=xxx,dc=yyy,dc=edu,dc=hk’ ‘(&(objectClass=*)(uid=test))’

A bit of search filter syntax :

match more than one attribute?


How do I match 3 attributes?


Notice how we weave one query into another. For 4 attributes, this would be:


Leave a Reply

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>