ldapsearch[1] 는 OpenLDAP 클라이언트 도구로, LDAP 서버에 접속해 항목을 검색하고 LDIF 로 출력한다. 서버가 살아 있는지, 인증 정보가 맞는지, 어떤 항목이 어떤 속성으로 들어 있는지 확인하는 첫 번째 도구다. OpenLDAP 서버뿐 아니라 Active Directory · FreeIPA 에도 그대로 쓴다.
패키지는 RHEL 계열 openldap-clients, Debian 계열 ldap-utils 다.
dnf install -y openldap-clients
apt install -y ldap-utils
ldapsearch [옵션] 필터 [속성...]
| 옵션 | 뜻 |
|---|---|
-H ldap://host:389 |
서버 URI. ldaps:// 는 TLS, ldapi:/// 는 로컬 소켓 |
-x |
simple 인증. 이 옵션이 없으면 SASL 을 시도한다 |
-D "cn=admin,dc=example,dc=com" |
bind DN. 익명이면 생략 |
-W / -w 비밀번호 / -y 파일 |
비밀번호를 물어보기 / 인라인 / 파일에서. 인라인은 히스토리에 남으므로 -W 나 -y 를 쓴다 |
-b "dc=example,dc=com" |
검색 시작점(base DN) |
-s base\|one\|sub |
범위 — 그 항목만 / 바로 아래 / 하위 전체(기본) |
-Y GSSAPI |
SASL 메커니즘. Kerberos 티켓으로 인증할 때 |
-Z / -ZZ |
StartTLS. -ZZ 는 실패하면 중단 |
-LLL |
LDIF 주석 · 버전 줄을 빼고 항목만 |
-o ldif-wrap=no |
긴 줄을 접지 않는다 |
-z 100 |
최대 항목 수 |
필터는 RFC 4515[2] 형식이다. 생략하면 (objectClass=*) 다. 속성 목록을 주면 그 속성만 출력한다.
| 필터 | 뜻 |
|---|---|
(uid=haedong) |
정확히 일치 |
(cn=hae*) |
앞부분 일치 |
(&(objectClass=inetOrgPerson)(mail=*)) |
AND — 사람이고 메일이 있는 항목 |
(\|(uid=a)(uid=b)) |
OR |
(!(uid=guest)) |
NOT |
(memberOf=cn=admins,ou=groups,dc=example,dc=com) |
그룹 소속(AD · memberOf overlay) |
인증 없이 서버가 어떤 suffix 를 서비스하는지 본다. 서버가 살아 있는지 확인하는 가장 가벼운 방법이다.
ldapsearch -x -H ldap://ldap.example.com -b "" -s base "(objectClass=*)" namingContexts supportedLDAPVersion
ldapsearch -x -H ldap://ldap.example.com -D "cn=root,dc=example,dc=com" -W -b "dc=example,dc=com" -LLL
ldapsearch -x -H ldaps://ldap.example.com -D "cn=root,dc=example,dc=com" -W \
-b "ou=users,dc=example,dc=com" "(uid=haedong)" cn mail memberOf
사용자 DN 으로 bind 해 본다. 성공하면 비밀번호가 맞는 것이다. ldapwhoami 가 더 짧다.
ldapwhoami -x -H ldap://ldap.example.com -D "uid=haedong,ou=users,dc=example,dc=com" -W
# dn:uid=haedong,ou=users,dc=example,dc=com
AD 는 bind DN 으로 user@domain 형식(UPN)도 받는다.
ldapsearch -H ldaps://ad.haedongg.net:3269 -x -D "haedong_adm@haedongg.net" -W \
-b "dc=haedongg,dc=net" "(sAMAccountName=haedong)" displayName mail memberOf
kinit haedong@EXAMPLE.COM
ldapsearch -Y GSSAPI -H ldap://ipa.example.com -b "cn=accounts,dc=example,dc=com" "(uid=haedong)"
ldaps:// 나 -ZZ 로 접속할 때 서버 인증서가 사설 CA 이면 CA 를 지정해야 한다. /etc/openldap/ldap.conf(Debian 은 /etc/ldap/ldap.conf)에 TLS_CACERT /etc/pki/tls/certs/ca.crt 를 적거나 환경변수 LDAPTLS_CACERT 로 준다.LDAPTLS_REQCERT=never ldapsearch .... 운영에서는 쓰지 않는다.LDAPTLS_CACERT=/etc/pki/tls/certs/ca.crt ldapsearch -x -H ldaps://ldap.example.com -b "" -s base namingContexts
| 메시지 | 원인 |
|---|---|
ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1) |
호스트 · 포트 · 방화벽, 또는 TLS 인증서 검증 실패 |
ldap_bind: Invalid credentials (49) |
bind DN 이나 비밀번호가 틀림. AD 는 data 52e 가 같은 뜻 |
ldap_bind: Confidentiality required (13) |
서버가 평문 bind 를 막음. ldaps:// 또는 -ZZ |
No such object (32) |
-b 의 base DN 이 없음 |
Size limit exceeded (4) |
서버 제한. -z 나 필터를 좁힌다. AD 는 1000 건 기본 |
ldapsearch(1) — OpenLDAP man page. 2026-09-20 확인. https://www.openldap.org/software/man.cgi?query=ldapsearch&sektion=1 ↩︎
RFC 4515 — LDAP: String Representation of Search Filters. 2026-09-20 확인. https://www.rfc-editor.org/rfc/rfc4515.html ↩︎