I have a use case to grab the DNs of all of the matching entries on an LDAPConnector.  These are groups with membership containing the principalName from the requestContext, but the users do not have entries in the directory.  It is an OpenLDAP directory.  I've tried various things for ReturnAttributes, like 1.1, dn, distinguishedName just as a shot in the dark.

The entries have objectClass organizationalUnit and eduMember.  I have no problem getting the OU of the entries as an IDP attribute and releasing it.  But I can't get DNs 🙁

It looks like a MappingStrategy would work, but I was hoping to not have to compile any Java 😄

Is anyone doing this already?  Is there any advice from people who have experience with shib?


