http://qs321.pair.com?node_id=557791

mce has asked for the wisdom of the Perl Monks concerning the following question:

Hi All,
I am a great fan of Net::LDAP, and I wrote a nice synchronisation tool that synchronises groups in LDAP directories. For Example, from SUN1 to ADAM.

Now, we just found a problem that in Windows AD, users are a member of a group, without being an actual member attribute.
This is called the PrimaryGroupID, and in fact is a workaround for a bad design in AD. see this.
Does anyone have a workaround for this issue?
What I want is a routine that can be called to search the AD directory, and return a mapping for all users with their groups (or vise versa).
Of course, in perl, but that is obvious.

Many thanks,


---------------------------
Dr. Mark Ceulemans
Senior Consultant
BMC, Belgium