summaryrefslogtreecommitdiff
path: root/sbin/itzks-check-ldap-group-not-in-correct-ou
blob: 5a1057f21125f617b351a61f5c645cefec8791d9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
#!/bin/sh

# Copyright (C) 2023 by Mike Gabriel <mike.gabriel@it-zukunft-schule.de>

# This script is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# This script is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the
# Free Software Foundation, Inc.,
# 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA.

OUTPUT_CMD=${OUTPUT_CMD:-cat}

set -e

ldapsearch -xLLL "(&(uid=*)(objectClass=posixAccount)(!(objectClass=gosaUserTemplate)))" \
    dn uid 2>/dev/null | perl -p0e 's/\n //g' | \
while read KEY VALUE ; do
	case "$KEY" in
		dn:)  UID=; USERDN="$VALUE" ;;
		dn::) UID=; USERDN="$(echo $VALUE | base64 -d)" ;;
		uid:) UID="$VALUE" ;;
		"")
			ldapsearch -xLLL "(&(cn=$UID)(objectClass=posixGroup))" \
			    dn 2>/dev/null | perl -p0e 's/\n //g' | \
			while read G_KEY G_VALUE ; do
				case "$G_KEY" in
					dn:)  GROUPDN="$G_VALUE" ;;
					dn::) GROUPDN="$(echo $G_VALUE | base64 -d)" ;;
					"")
						U_BASEDN=$(echo $USERDN | cut -d"," -f3-)
						G_BASEDN=$(echo $GROUPDN | cut -d"," -f3-)

						if [ "${U_BASEDN}" != "${G_BASEDN}" ]; then
							(
							echo "${USERDN}"; \
							echo "${GROUPDN} -> ${U_BASEDN}"; \
							echo; ) | ${OUTPUT_CMD}

						fi

					;;
				esac
			done
		;;
	esac
done

exit 0