![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 519](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675519.webp)
Using ldapsearch
Appendix
B
Finding Directory Entries
519
Searching the Schema Entry
Directory Server stores all directory server schema in the special
cn=schema
entry.
This entry contains information on every object class and attribute defined for your
directory server.
You can examine the contents of this entry as follows:
ldapsearch -h mozilla -b "cn=schema" -s base "objectclass=*"
Using LDAP_BASEDN
To make searching easier, you can set your search base using the
LDAP_BASEDN
environment variable. Doing this allows you to skip specifying the search base
with the
-b
option (for information on how to set environment variables, see the
documentation for your operating system).
Typically, you set
LDAP_BASEDN
to your directory’s suffix value. Since your
directory suffix is equal to the root, or topmost, entry in your directory, this causes
all searches to begin from your directory’s root entry.
For example, suppose you have set
LDAP_BASEDN
to
dc=example,dc=com
. Then to
search for
cn=babs jensen
in your directory use the following command-line call:
ldapsearch -h mozilla "cn=babs jensen"
In this example, the default scope of
sub
is used because the
-s
option was not
used to specify the scope.
Displaying Subsets of Attributes
The
ldapsearch
command returns all search results in LDIF format. By default,
ldapsearch
returns the entry’s distinguished name and all of the attributes that
you are allowed to read (you can set up the directory access control such that you
are allowed to read only a subset of the attributes on any given directory entry).
Only operational attributes are not returned. If you want operational attributes
returned as a result of a search operation, you must explicitly specify them in the
search command.
Suppose you do not want to see all of the attributes returned in the search results.
You can limit the returned attributes to just a few specific attributes by specifying
the ones you want on the command line immediately after the search filter. For
example, to show the
cn
and
sn
attributes for every entry in the directory, use the
following command-line call:
ldapsearch -h mozilla "objectclass=*" sn cn
This example assumes you set your search base with
LDAP_BASEDN
.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...