FM Field Manual smhansen.dev

FM 8-05 Chapter 8 · Email and identity

LDAP DN

Parse distinguished names, convert to canonical name form, and escape values for DNs and search filters.

Local only Runs in your browser. Nothing you enter leaves this page.

Usable as a step in Chain

Distinguished name

  • DC=com
    • DC=example
      • DC=corp
        • OU=Oslo
          • OU=Staff
            • CN=Smith, John
RDNs
6
Normalised (RFC 4514)
CN=Smith\, John,OU=Staff,OU=Oslo,DC=corp,DC=example,DC=com
Parent
OU=Staff,OU=Oslo,DC=corp,DC=example,DC=com
Canonical name
corp.example.com/Oslo/Staff/Smith, John

Canonical name to DN

Last element is
DN
CN=Jane Doe,CN=Users,DC=corp,DC=example,DC=com

A canonical name does not say which parts are OUs. Parts in between become OU, except the default containers directly under the domain (Builtin, Computers, ForeignSecurityPrincipals, Infrastructure, Keys, LostAndFound, Managed Service Accounts, NTDS Quotas, Program Data, System, TPM Devices, Users), which are CN.

Escape a value

For a DN (RFC 4514)
Smith\, John (Oslo)*
For a filter (RFC 4515)
Smith, John \28Oslo\29\2a

The two are different. A DN escapes , + " \ < > ; and a leading # or space with a backslash. A filter escapes * ( ) \ and NUL as \2a \28 \29 \5c \00. Using the wrong one, or none, lets input change the query (LDAP injection).

Build a search filter

Match
Filter
(&(objectClass=user)(sAMAccountName=j\2asmith))

Values are escaped, so * in a value matches a literal star, not anything.

  • No entry in this manual matches “”.

↑ ↓ move · Enter open · Esc close