Unable to get memberOf (OpenLDAP, using memberof overlay)
Peter Schober
peter.schober at univie.ac.at
Tue Dec 10 18:24:55 EST 2019
* Stevens, M <michael.stevens at boku.com> [2019-12-10 23:57]:
> Querying with ldapsearch, I get group membership information using "\* \+",
> "\* memberof", etc., the ldap server clearly considers memberOf to be an
> operational attribute, I get it back when filtering only on "+"
The above only refers to your use of ldapsearch?
Or does everything above also work from the IDP when putting that as
content of an <ReturnAttributes> element /except/ the variant you want
"* +"?
Or does not of this work when putting it as content of ReturnAttributes?
Sorry, the above just isn't clear to me.
> I've tried about every combination possible. The logs clearly show
> "+" returning operational attributes ... just not memberOf.
Since you're looking at logs: You can always run the resolver or the
ldap stuff on DEBUG, that should show what it gets and your slapd logs
should show what the IDP requests (on the right loglevel).
-peter
More information about the users
mailing list