<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body>
<div dir="auto" style="direction: ltr; margin: 0; padding: 0; font-family: sans-serif; font-size: 11pt; color: black; ">
Have you tried explicitly requesting memberof instead of using the +?<br>
<br>
</div>
<div dir="auto" style="direction: ltr; margin: 0; padding: 0; font-family: sans-serif; font-size: 11pt; color: black; ">
Admittedly, we're not using openldap, but thats how we're getting other operational attributes back.
<br>
<br>
</div>
<div dir="auto" style="direction: ltr; margin: 0; padding: 0; font-family: sans-serif; font-size: 11pt; color: black; ">
As Peter said, up the log level. It'll print out what it got back and what the resolved did with it.
<br>
<br>
</div>
<div dir="auto" style="direction: ltr; margin: 0; padding: 0; font-family: sans-serif; font-size: 11pt; color: black; ">
<span id="OutlookSignature">
<div dir="auto" style="direction: ltr; margin: 0; padding: 0; font-family: sans-serif; font-size: 11pt; color: black; ">
Get <a href="https://aka.ms/ghei36">Outlook for Android</a></div>
</span><br>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Tuesday, December 10, 2019 6:24:55 PM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Unable to get memberOf (OpenLDAP, using memberof overlay)</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">[EXTERNAL EMAIL]<br>
<br>
* Stevens, M <michael.stevens@boku.com> [2019-12-10 23:57]:<br>
> Querying with ldapsearch, I get group membership information using "\* \+",<br>
> "\* memberof", etc., the ldap server clearly considers memberOf to be an<br>
> operational attribute, I get it back when filtering only on "+"<br>
<br>
The above only refers to your use of ldapsearch?<br>
Or does everything above also work from the IDP when putting that as<br>
content of an <ReturnAttributes> element /except/ the variant you want<br>
"* +"?<br>
Or does not of this work when putting it as content of ReturnAttributes?<br>
<br>
Sorry, the above just isn't clear to me.<br>
<br>
> I've tried about every combination possible. The logs clearly show<br>
> "+" returning operational attributes ... just not memberOf.<br>
<br>
Since you're looking at logs: You can always run the resolver or the<br>
ldap stuff on DEBUG, that should show what it gets and your slapd logs<br>
should show what the IDP requests (on the right loglevel).<br>
<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>