Query password expiration FreeIPA or RedHat IDM

ldapsearch -x -b cn=users,cn=accounts,dc=example,dc=com '(&(!(nsAccountLock=TRUE))(krbPasswordExpiration>=${d}))' krbPrincipalName krbPasswordExpiration -D 'uid=admin,cn=users,cn=accounts,dc=example,dc=com' -w Passw0rd!

References