1
votes

I have written a Java application that searches Active directory via LDAP for user information. I have a list of instances of custom Person class that is passed in. In it I have either DN or email defined. I am modifying the search criteria accordingly. Here is the code:

for (Person person : members) {
    boolean ready = false;
    String filter = getConfig().getUserSearchFilter();
// (&(|(objectclass=user)(objectclass=person)(objectclass=inetOrgPerson)(objectclass=organizationalPerson)))
    String base = person.getDistinguishedName();
    if (base != null && !base.isEmpty()) {
       ready = true;
    } else if (person.getEmail() != null) {
       base = getConfig().getMemberSearchBase();
// ou=Users,ou=Managed,dc=division,dc=company,dc=com
       String mail = person.getEmail();
       StringBuilder filterBuilder = new StringBuilder(filter);
       int pIdx = filterBuilder.lastIndexOf(")");
       filterBuilder.insert(pIdx, "(|(mail=" + mail + ")(x-personalmail=" + mail + "))");
       filter = filterBuilder.toString();
       LOG.debug("New value of a filter = {}", filter);
       ready = true;
    }
    if (ready) {
       try {
           NamingEnumeration<SearchResult> search = getContext().search(base, filter, searchControls);
           ...
       } catch (NamingException nex) {
                        throw new IOException(nex);
       }
   } else {
        LOG.error("Incorrect search criteria for user {} of group {}. Person skipped", person.getName(), this.group.getName());
   }
}

Code is working without errors, but when DN is specified it does find a person, but when email is defined it finds nothing. However, If I copy generated filter string and pass it to ldapsearch command in a form of:

ldapsearch -LLL -x -H ldaps://my.ldap.server.com -D '[email protected]' -W -b "ou=Users,ou=Managed,dc=division,dc=company,dc=com" '(&(|(objectclass=user)(objectclass=person)(objectclass=inetOrgPerson)(objectclass=organizationalPerson))(|([email protected])([email protected])))'

It does find this person perfectly. Did anyone faced similar problem? Do you see any flaws in my code? Please, do help me.

1
Here is a little bit, maybe it can untie your problem: stackoverflow.com/questions/11341688/… AND stackoverflow.com/questions/2172831/…Vasyl Lyashkevych
Unfortunately, these questions describes very basic problem. I do not have problem establishing LDAP connection. My problem is that filter does not work (i.e. not finding a person) when email is specified in Java code, while it works perfectly well in ldapsearch command.Gary Greenberg

1 Answers

1
votes

I did find the cause of my problem. In the search control I had scope defined as OBJECT_SCOPE. It does work when you are specifying DN, but with the search per one of the fields it fails finding the object. I changed the scope to SUBTREE_SCOPE and everything started working as expected.