Create user on Active Directory from Linux.

Posted on Wed 12 June 2013 by Pavlo Khmel

Manage Active Directory from Linux.

Changes on Windows Server 2008 r2

Add new role - Active Directory Certificate Services in Windows Server 2008 R2

Create sertificate - LDAP over SSL (LDAPS) Certificate

Linux (CentOS)

Install adtool

tar xvzf adtool-1.3.3.tar.gz
cd adtool-1.3.3
make install


uri ldaps://
binddn cn=Administrator,cn=Users,dc=ad,dc=test,dc=local
bindpw xxxxxxxxx
searchbase dc=ad,dc=test,dc=local


URI ldap://
BASE dc=example,dc=com

Test list and search examples

adtool search ou Users
adtool list cn=Users,dc=ad,dc=test,dc=local
adtool list ou=Users,ou=MYNAME,dc=ad,dc=test,dc=local

Real example - Create new user:

adtool useradd testuser ou=Users,ou=MYNAME,dc=ad,dc=test,dc=local
adtool userrename testuser 'First-Name Lastname'
adtool setpass 'First-Name Lastname' 'xxxxxxxxx'
adtool userunlock 'First-Name Lastname'
adtool attributereplace 'First-Name Lastname' userPrincipalName testuser
adtool attributereplace 'First-Name Lastname' sAMAccountName testuser
adtool attributereplace 'First-Name Lastname' mail
adtool attributereplace 'First-Name Lastname' givenName 'First-Name'
adtool attributereplace 'First-Name Lastname' sn 'Lastname'
adtool attributereplace 'First-Name Lastname' displayName 'First-Name Lastname'
# Get user attribut
adtool attributeget testuser mail


# Create user

adtool useradd testuser ou=Users,ou=MYNAME,dc=ad,dc=emgs,dc=local
adtool userrename testuser 'First-Name Lastname'

# Create and rename because "Name Length Limits from the Schema":
# backward compatibility the limit is 20 characters for login name.

# Set password and unlock
adtool setpass "First-Name Lastname" 'xxxxxxxxx'
adtool userunlock "First-Name Lastname"

# Login name
adtool attributereplace "First-Name Lastname" userPrincipalName testuser
# Logon Name (pre-Windows 2000)
adtool attributereplace "First-Name Lastname" sAMAccountName testuser

# Email
adtool attributereplace "First-Name Lastname" mail

# First name and Last name
adtool attributereplace "First-Name Lastname" givenName "First-Name"
adtool attributereplace "First-Name Lastname" sn "Lastname"

# Display name
adtool attributereplace "First-Name Lastname" displayName "First-Name Lastname"

Useful links:
List of attributes to modify:
adtool home page: