On Dec 19, 2013, at 11:44 AM, steve <>

> On Thu, 2013-12-19 at 17:32 +0000, Daniel Givens wrote:
>> base    group   ou=POSIXGroups,o=org
>> filter  group   (objectClass=posixGroup)
>> scope   group   one
>> base    passwd  ou=users,o=org
>> filter  passwd  (objectClass=posixAccount)
>> base    shadow  ou=users,o=org
>> filter  shadow  (objectClass=posixAccount)
> Hi
> I think your filter is forcing the group lookup. Here against AD and
> with objectClass: posixGroup in the group DN, it works fine without it.
> Worth a try?
> Steve

The filters were added in an attempt to speed things up. No difference with 
them gone. By the way, the LDAP server is Novell eDirectory.


