4.1.10.8.1 Initial State

User "Kim Akers" is added to the group ([MS-ADSC] section 2.14.) "GroupA" on DC1.

Querying the repsFrom attribute on the NC root object for the domain DC=CONTOSO, DC=COM on DC2:

  • ldap_search_s("DC=contoso,DC=com", baseObject, "(objectclass=*)", repsFrom)

  • Result <0>: (null)

  • Matched DNs:

  • Getting 1 entries:

  • >> Dn: DC=contoso,DC=com

    • 1> repsFrom: dwVersion = 1,

      V1.cb: 276, V1.cConsecutiveFailures: 3 V1.timeLastSuccess: 12797643933 V1.timeLastAttempt: 12797645671 V1.ulResultLastAttempt: 0x2108 V1.cbOtherDraOffset: 216 V1.cbOtherDra: 60 V1.ulReplicaFlags: 0x70

      V1.rtSchedule: <ldp:skipped> V1.usnvec.usnHighObjUpdate: 29379 V1.usnvec.usnHighPropUpdate: 29379

      V1.uuidDsaObj: c20bc312-4d35-4cc0-9903-b1073368af4a V1.uuidInvocId: c20bc312-4d35-4cc0-9903-b1073368af4a V1.uuidTransportObj: 00000000-0000-0000-0000-000000000000 V1.mtx_address: c20bc312-4d35-4cc0-9903-b1073368af4a._msdcs.contoso.com

      V1.cbPASDataOffset: 0 V1.PasData: version = -1, size = -1, flag = -1 ;

Querying the group object "CN=GroupA, CN=Users, DC=CONTOSO, DC=COM" on DC1:

  • ldap_search_s("CN=GroupA, CN=Users, DC=contoso, DC=com", baseObject, "(objectclass=*)", [objectClass, cn ... objectCategory])

  • Result <0>: (null)

  • Matched DNs:

  • Getting 1 entries:

  • >> Dn: CN=GroupA,CN=Users,DC=contoso,DC=com

    • 2> objectClass: top; group;

    • 1> cn: GroupA;

    • 2> member: CN=Kim Akers,CN=Users,DC=contoso,DC=com;

    • 1> distinguishedName: CN=GroupA,CN=Users,DC=contoso,DC=com;

    • 1> instanceType: 0x4 = ( IT_WRITE );

    • 1> whenCreated: 07/13/2006 12:25:35 Pacific Standard Daylight Time;

    • 1> whenChanged: 07/17/2006 14:34:12 Pacific Standard Daylight Time;

    • 1> uSNCreated: 16023;

    • 1> uSNChanged: 29387;

    • 1> name: GroupA;

    • 1> objectGUID: 328ab893-b884-4e31-a73c-71740e261715;

    • 1> objectSid: S-1-5-21-254470460-2440132622-709970653-1114;

    • 1> sAMAccountName: GroupA;

    • 1> sAMAccountType: 536870912;

    • 1> groupType: 0x80000004 = ( GROUP_TYPE_RESOURCE_GROUP | GROUP_TYPE_SECURITY_ENABLED );

    • 1> objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=contoso,DC=com;

Querying the group object "CN=GroupA, CN=Users, DC=CONTOSO, DC=COM" on DC2, the member attribute value is not returned, as it is currently empty because this group has no members on DC2.

  • ldap_search_s("CN=GroupA, CN=Users, DC=contoso, DC=com", baseObject, "(objectclass=*)", [objectClass, cn ... objectCategory])

  • Result <0>: (null)

  • Matched DNs:

  • Getting 1 entries:

    >> Dn: CN=GroupA,CN=Users,DC=contoso,DC=com

    • 2> objectClass: top; group;

    • 1> cn: GroupA;

    • 1> distinguishedName: CN=GroupA,CN=Users,DC=contoso,DC=com;

    • 1> instanceType: 0x4 = ( IT_WRITE );

    • 1> whenCreated: 07/13/2006 12:25:35 Pacific Standard Daylight Time;

    • 1> whenChanged: 07/13/2006 12:36:03 Pacific Standard Daylight Time;

    • 1> uSNCreated: 26457;

    • 1> uSNChanged: 26543;

    • 1> name: GroupA;

    • 1> objectGUID: 328ab893-b884-4e31-a73c-71740e261715;

    • 1> objectSid: S-1-5-21-254470460-2440132622-709970653-1114;

    • 1> sAMAccountName: GroupA;

    • 1> sAMAccountType: 536870912;

    • 1> groupType: 0x80000004 = ( GROUP_TYPE_RESOURCE_GROUP | GROUP_TYPE_SECURITY_ENABLED );

    • 1> objectCategory: CN=Group, CN=Schema, CN=Configuration, DC=contoso, DC=com;

Show: