ldapsearch and Active Directory


Trying to query AD for a user account which can be in one of several Windows 2000/Active Directory domains to see which domain the account is in.  When I query the domain forest root, I get referrals back.  So my first question is:  is there a way to get ldapsearch to recursively follow referrals?  When I bind to a speicific domain which contains the account, I can dump the account's attributes only when I use -D and -w options, using which is not realistically feasible.  My second question is:  is it possible to get to this information anonymously in some other way?  Also, my impression is that Global Catalog is not compatible with ldapsearch - are there plans in the works to introduce this functionality?


- Slav Inger
- vinger@ford.com