===== Query password expiration FreeIPA or RedHat IDM ===== ldapsearch -x -b cn=users,cn=accounts,dc=example,dc=com '(&(!(nsAccountLock=TRUE))(krbPasswordExpiration>=${d}))' krbPrincipalName krbPasswordExpiration -D 'uid=admin,cn=users,cn=accounts,dc=example,dc=com' -w Passw0rd! ==== References ==== * Requires authentication: https://access.redhat.com/solutions/75213