AD nested groups

Hong Ye hy93 at
Tue Jul 25 11:00:17 EDT 2017


Does anyone know how to get all the AD group membership including nested groups for a user in AttributeResolver? I tried the solution below, but it’s very slow. Is there any other solution?

<!-- get the user's DN from the main LDAP connector (myLDAP) for searching the groups the user is in -->
    <resolver:AttributeDefinition id="distinguishedName" xsi:type="ad:Simple"
        <resolver:Dependency ref="psdldap" />
        <!-- no encoder needed, use your existing ldap connector as dependency -->

    <!-- search for all groups the user is recursively in - and flatten the distinguishedName(s) of all the groups into a single multivalued attribute (copy from existing connector, note searchTimeLimit) -->
    <resolver:DataConnector id="groupLDAP" xsi:type="dc:LDAPDirectory" xmlns="urn:mace:shibboleth:2.0:resolver:dc" ldapURL="ldap://ldap-server:389" baseDN="your base dn" principal="Admin User CN" principalCredential="Admin Pass" useStartTLS="false" maxResultSize="1000" mergeResults="true" searchTimeLimit="0">
        <resolver:Dependency ref="distinguishedName" />
        <dc:LDAPProperty name="java.naming.referral" value="follow"/>

    <resolver:AttributeDefinition id="memberOf" xsi:type="ad:Simple"
        <resolver:Dependency ref="groupLDAP" />
        <!-- no encoder needed -->


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the users mailing list