Linux Commands

Linux LDAP Commands

“Managing and maintaining a Linux LDAP server can be very intimidating, particularly if you are going through it for the first time. However, this procedure should not send shivers down your spine. For the record, managing a Linux LDAP server is not as complicated as it often seems.

Getting started with Linux LDAP begins with understanding the OpenLDAP command line. Firstly, Linux LDAP often comes with three primary objectives. It can authenticate, interrogate, and finally update and control your systems. And to meet these functional capabilities, the LDAP C-API has the tools or commands that cover all the categories.

Thus, this article will discuss the basic Linux LDAP commands. More importantly, the write-up will show you how to use various commands to achieve the three LDAP commands.”

Let’s go!

1. ldapadd Command

If you want to add entries into the directory, the ldapadd command is the ideal tool. This command reliably opens a connection to your directory to authenticate. It comes in handy in two ways. Firstly, you can use it to open the .ldif file and add entries one at a go. It can also create a file from which ldapadd will read. The ldapadd syntax is;


The above command implies that user kenadmin is authenticating to the myhost directory at port 119. The tool will open a .ldif file, add the contents to your directory, and then add the necessary entries.

2. ldapmodify Command

The ldapmodify command changes the credentials in an existing entry. This command is pretty interactive. Thus, using it involves the following steps;

  1. Issue a ldapmodify command
  2. Inform the command of what you intend to modify
  3. Make modifications to the data
  4. Exit using CTRL-d.
  5. Confirm the changes effected by ldapmodify

The syntax is;

The file fetches the LDIF file due for modification and changes the LDAP entries specified by the modification request file. This command uses a modified version of the .ldif file. Utilize the changetype component within the file to select the change type you want to implement. The four various kinds of changes that you can effectively include;

  • add– Used for adding a new entry
  • Modify– Can add, delete, or replace an attribute to change an existing entry
  • delete– Used for deleting a current entry
  • modrdn– Used for modifying the RDN component of an existing entry


The above command implies that user kenadmin is authenticating to the myhost directory, which exists at port 119. The utility will open the kentech.ldif file and modify the relevant directory entries as requested.

3. ldapsearch Command

If you are looking for specific entries from your LDAP directory, the ldapsearch command will help you search successfully. And like most LDAP commands, ldapseach begins by opening a connection to the directory and authenticating whoever performs the search before searching the requested entry and printing the result. Of course, the command will also publish the results in the specified format.

The command’s syntax is;


In the above example, the search targets the myhost server located within port 119. The base is the –s (scope) of the search, and the base DN –b, is the section being searched.

4. ldapbind Command

This command has two primary objectives. Firstly, you can use it to authenticate to your directory server. Again, the ldapbind tool also comes in handy in determining if your server is up and running.

Below is the ldapbind syntax;


The above command authenticates kenadmin to myhost directory server, located at port 119. The password for the authentication is welcome.

5. ldapdelete Command

The ldapdelete tool comes in handy in removing leaf entries from the directory. It works by creating a connection to the directory server, authenticating the user, and finally deleting the specified entries.

The command’s syntax is;


The above command aims at authenticating kenadmin to the myhost directory. It will then delete the requested items. For example, it will get rid of the entry uid=linhint,ou=sales,ou=people,dc=team,dc=com.

6. ldapmoddn Command

The ldapmoddn tool also has two functions. Firstly, you can use this command to change RDN entries. You can also use the utility to move a subtree or an entry to a different location within the directory.

Its syntax;


The above command aims at authenticating kenadmin to the myhost directory. Once authenticated, it will assign the “uid=oball,ou=sales,ou=people,dc=team,dc=com” \ to a new parent entry, which will be “ou=marketing,ou=people,dc=team,dc=com”.

Understanding the LDAP Command Line Tools

The following command-line options are essential;

  • -h – Stands for the directory server’s hostname
  • -p – Port number
  • -D – This is the bind DN
  • -w – Stands for the bind password
  • -W – The wallet authentication for one-way or two-way SSL authentication
  • -P – The wallet password
  • -U – Defines the SSL authentication modes (1 means no authentication, 2 for single-way authentication, and 3 for two-way authentications)
  • -b – The base DN for the search
  • -s – The scope of the search
  • -f – The .ldif file bound for addition, modification, or deletion
  • -R – A new RDN
  • -N – A new parent for a subtree or an entry after removal


This article is an introduction to the various LDAP commands. With these illustrations, you now have an idea of the critical functional aspects of LDAP. Open your LDAP and attempt some of these commands since practicing is the best way to improve your knowledge and skills.

About the author

Linux Explorer

Linux Explorer -- Always exploring Linux and learning to advance the state of the art.