From: Francis Cianfrocca Date: 2007-05-01T13:27:15+09:00 Subject: Re: ruby scripting on microsoft active directory plus exchange ------=_Part_291393_28761914.1177993634046 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 4/19/07, Clifford Heath wrote: > > > Beware that if you encounter a group that has more than 1000 members, > Microsoft AD has a custom extension to the standard LDAP protocol to > handle paging. Basically you get an attribute returned that has an > extended name, and not all values. IIRC the extension is ";min-max" > where min and max are the index numbers of the first and last value > returned from the members array. You need then to repeat the query, > asking for a similarly-named attribute with larger min and max > numbers, until a query returns fewer than you asked for. I'm sorry, I just noticed this, although it's quite a few days old now. The extension you're talking about is RFC-2696, so although it's definitely a hack invented by Microsoft for their own purposes, it's probably a misnomer to call it a "custom extension" to the standard. They did implement it as a V3-standard LDAP "control." Recent versions of the OpenLDAP server support it as well, but it's not mandatory as it is with A/D. However, paged searches behave just differently enough on OpenLDAP to keep things interesting. If you try a query against A/D that will return more than 1000 rows, you should find that it "just works" with Net::LDAP. As far as I know, none of the other implementations (including ldapsearch) work correctly without setting extra parameters, but that may have changed since the last time I looked. ------=_Part_291393_28761914.1177993634046--