FM 8-05 Chapter 8 · Email and identity
LDAP DN
Parse distinguished names, convert to canonical name form, and escape values for DNs and search filters.
Local only Runs in your browser. Nothing you enter leaves this page.
Usable as a step in ChainDistinguished name
- DC=com
- DC=example
- DC=corp
- OU=Oslo
- OU=Staff
- CN=Smith, John
- OU=Staff
- OU=Oslo
- DC=corp
- DC=example
- RDNs
- 6
- Normalised (RFC 4514)
- CN=Smith\, John,OU=Staff,OU=Oslo,DC=corp,DC=example,DC=com
- Parent
- OU=Staff,OU=Oslo,DC=corp,DC=example,DC=com
- Canonical name
- corp.example.com/Oslo/Staff/Smith, John
Canonical name to DN
- DN
- CN=Jane Doe,CN=Users,DC=corp,DC=example,DC=com
A canonical name does not say which parts are OUs. Parts in between become OU, except the default containers directly under the domain (Builtin, Computers, ForeignSecurityPrincipals, Infrastructure, Keys, LostAndFound, Managed Service Accounts, NTDS Quotas, Program Data, System, TPM Devices, Users), which are CN.
Escape a value
- For a DN (RFC 4514)
- Smith\, John (Oslo)*
- For a filter (RFC 4515)
- Smith, John \28Oslo\29\2a
The two are different. A DN escapes , + " \ < > ; and a leading # or space with a backslash. A filter escapes * ( ) \ and NUL as \2a \28 \29 \5c \00. Using the wrong one, or none, lets input change the query (LDAP injection).
Build a search filter
- Filter
- (&(objectClass=user)(sAMAccountName=j\2asmith))
Values are escaped, so * in a value matches a literal star, not anything.