Ldap nested Groups membership not working as expected

Matthew Slowe Matthew.Slowe at jisc.ac.uk
Fri Jun 11 08:54:59 UTC 2021

> On 11 Jun 2021, at 09:42, Armando Martins <armando.mart1s at gmail.com> wrote:
> i'm trying to set up Ldap nested groups on my Shibboleth 4.1.2 but it seems that the value of $distinguishedName.get(0) is never replaced by the attribute resolved by my dependent LDAP DataConnector.

This may sound like a stupid question, but does OpenLDAP actually expose a distinguishedName attribute? It should show up in the IdP debug logs after the LDAP search if it does.

Matthew Slowe (GPG: 0x6BE0CF7D04600314)
Senior Technical Consultant and Support specialist - Trust & Identity, Jisc
Team: 0300 300 2212, option 2
Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG

More information about the users mailing list