dotws86260 2018-04-25 18:48
浏览 118
已采纳

LDAP过滤器:仅从给定日期开始更新用户

I have trouble setting up an Active Directory filter to synchronize a MySQL database containing all my users. And I can not create a filter that only retrieves users with an update date greater than a given date.

I tried using uSNChanged attribute on my filter but it returns me 0 result.

Any suggestion is welcome thanks to all

  • 写回答

1条回答 默认 最新

  • douou1891 2018-04-25 19:17
    关注

    You would search by the whenChanged attribute. Something like this:

    (&(whenChanged>=20180425150000.0-0400)(objectClass=user)(objectCategory=person))
    

    The format is pretty straight forward:

    {year}{month}{date}{hour}{minute}{seconds}.{milliseconds}-{timezone}
    

    For example, in my example above I used today's date at 3:00pm eastern.

    There are a couple caveats to keep in mind:

    1. The whenChanged attribute is not exactly the same on every domain controller, but they will be close (within a half hour). The reason is because of replication - the time is set to the time each DC received the change.
    2. When a user logs in, the lastLogon time is updated, and that triggers the whenChanged attribute to be updated. So just because whenChanged changes, it doesn't mean someone modified the account. This also means that this search will return more accounts than you may expect.
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥30 VMware 云桌面水印如何添加
  • ¥15 用ns3仿真出5G核心网网元
  • ¥15 matlab答疑 关于海上风电的爬坡事件检测
  • ¥88 python部署量化回测异常问题
  • ¥30 酬劳2w元求合作写文章
  • ¥15 在现有系统基础上增加功能
  • ¥15 远程桌面文档内容复制粘贴,格式会变化
  • ¥15 这种微信登录授权 谁可以做啊
  • ¥15 请问我该如何添加自己的数据去运行蚁群算法代码
  • ¥20 用HslCommunication 连接欧姆龙 plc有时会连接失败。报异常为“未知错误”