Accessing IPA LDAP Tree - dogtagpki/freeipa GitHub Wiki

Overview

This page describes how to access IPA LDAP tree.

Master Hosts

$ ldapsearch \
    -H ldap://$HOSTNAME \
    -x \
    -D "cn=Directory Manager" \
    -w Secret.123 \
    -b "cn=masters,cn=ipa,cn=etc,dc=example,dc=com" \
    -o ldif_wrap=no \
    -LLL
dn: cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: top
cn: masters

dn: cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: top
objectClass: nsContainer
objectClass: ipaReplTopoManagedServer
objectClass: ipaConfigObject
objectClass: ipaSupportedDomainLevelConfig
cn: ipa.example.com
ipaReplTopoManagedSuffix: dc=example,dc=com
ipaReplTopoManagedSuffix: o=ipaca
ipaMinDomainLevel: 1
ipaMaxDomainLevel: 1

dn: cn=KDC,cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: ipaConfigObject
objectClass: top
cn: KDC
ipaConfigString: startOrder 10
ipaConfigString: kdcProxyEnabled
ipaConfigString: pkinitEnabled
ipaConfigString: enabledService

dn: cn=KPASSWD,cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: ipaConfigObject
objectClass: top
cn: KPASSWD
ipaConfigString: startOrder 20
ipaConfigString: enabledService

dn: cn=KEYS,cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: ipaConfigObject
objectClass: top
cn: KEYS
ipaConfigString: startOrder 41
ipaConfigString: enabledService

dn: cn=CA,cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: ipaConfigObject
objectClass: top
cn: CA
ipaConfigString: startOrder 50
ipaConfigString: caRenewalMaster
ipaConfigString: enabledService

dn: cn=OTPD,cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: ipaConfigObject
objectClass: top
cn: OTPD
ipaConfigString: startOrder 80
ipaConfigString: enabledService

dn: cn=HTTP,cn=ipa.example.com,cn=masters,cn=ipa,cn=etc,dc=example,dc=com
objectClass: nsContainer
objectClass: ipaConfigObject
objectClass: top
cn: HTTP
ipaConfigString: startOrder 40
ipaConfigString: enabledService
⚠️ **GitHub.com Fallback** ⚠️