On Tue, 9 Sep 2014, Jakub Hrozek wrote:
On Tue, Sep 09, 2014 at 10:58:54AM +0100, Rowland Penny wrote:
> Can I jump in here and point out the base filter will never work against a
> windows AD server, windows AD does not use the posixAccount objectclass
> directly, it is an auxiliary class of 'User' and as such never appears but
> its attributes do.
Well, we do use different objectclasses for different back ends. For AD
we use 'group'.
You're also free to change this with the ldap backend without modifying the
filter via:
ldap_group_object_class = group
At least, I /assume/ that's how things are working at my end...
jh