<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Can you confirm whether the AD instances you’re working with support the LDAP_MATCHING_RULE_IN_CHAIN matching rule?</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Unfortunately, I don’t believe there is any way to ask via the LDAP protocol and know which matching rules are supported.</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Maybe your AD administrators can answer that question.</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
If you change your logging configuration to put org.ldaptive in DEBUG you can confirm what AD is responding with for these queries.</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
That might give some clues.</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
—Daniel Fisher</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="mail-editor-reference-message-container" style="color: inherit; background-color: inherit;">
<div class="ms-outlook-mobile-reference-message skipProofing" style="direction: ltr;">
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="text-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor; font-family: Aptos; font-size: 12pt; color: black;">
<b>From: </b>users <users-bounces@shibboleth.net> on behalf of Martin Hitschel via users <users@shibboleth.net><br>
<b>Date: </b>Monday, April 20, 2026 at 2:29 AM<br>
<b>To: </b>Fisher, Daniel via users <users@shibboleth.net><br>
<b>Cc: </b>Martin Hitschel <martin.hitschel@daasi.de><br>
<b>Subject: </b>Re: AD nested groups<br>
<br>
</div>
<p class="ms-outlook-mobile-reference-message skipProofing">Hi Daniel,</p>
<p class="ms-outlook-mobile-reference-message skipProofing">I see this with several customers, most of them run 5.2.x, some 5.1.6.</p>
<p class="ms-outlook-mobile-reference-message skipProofing">My documentation states this should spit out memberOfs for nested groups, at least that used to work before:</p>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <DataConnector id="myLDAP" xsi:type="LDAPDirectory"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> baseDN="%{idp.attribute.resolver.LDAP.baseDN}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> principal="%{idp.attribute.resolver.LDAP.bindDN}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> useStartTLS="%{idp.attribute.resolver.LDAP.useStartTLS:true}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> connectTimeout="%{idp.attribute.resolver.LDAP.connectTimeout}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> trustFile="%{idp.attribute.resolver.LDAP.trustCertificates}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <b>followReferrals="true"</b> exportAttributes="mail givenName sn cn
<b>memberOf</b>"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> responseTimeout="%{idp.attribute.resolver.LDAP.responseTimeout}"></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <FilterTemplate></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <![CDATA[</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> %{idp.attribute.resolver.LDAP.searchFilter}</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> ]]></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> </FilterTemplate></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> </DataConnector></span><span style="font-family: monospace;"><br>
<br>
</span>with <span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
idp.attribute.resolver.LDAP.searchFilter = (sAMAccountName=$resolutionContext.principal)</span></p>
<p class="ms-outlook-mobile-reference-message skipProofing">At least with an extra connector we should be getting the nested groups:</p>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <DataConnector id="myLDAPGroups" xsi:type="LDAPDirectory"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> baseDN="%{idp.attribute.resolver.LDAP.baseDN}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> principal="%{idp.attribute.resolver.LDAP.bindDN}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> useStartTLS="%{idp.attribute.resolver.LDAP.useStartTLS:true}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> connectTimeout="%{idp.attribute.resolver.LDAP.connectTimeout}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> responseTimeout="%{idp.attribute.resolver.LDAP.responseTimeout}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <b>followReferrals="true"</b> trustFile="%{idp.attribute.resolver.LDAP.trustCertificates}"</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> maxResultSize="0"></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <InputDataConnector ref="myLDAP" attributeNames="distinguishedName"/></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <FilterTemplate></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <![CDATA[</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<b>(member:1.2.840.113556.1.4.1941:=$distinguishedName.get(0))</b></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> ]]></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> </FilterTemplate></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <ReturnAttributes></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> distinguishedName</span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> </ReturnAttributes></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> </DataConnector></span></p>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: monospace;">with </span></p>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <AttributeDefinition id="</span>memberOf<span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">"
xsi:type="Simple"></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> <InputDataConnector ref="myLDAPGroups" attributeNames="distinguishedName"/></span><span style="font-family: monospace;"><br>
</span><span style="font-family: monospace; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);"> </AttributeDefinition></span><span style="font-family: monospace;"><br>
</span><br>
</p>
<p class="ms-outlook-mobile-reference-message skipProofing">This started failing maybe a year ago or so throughout most AD customers. So I believe there came a new AD default setting along. I remember on customer working with us and experimenting with their
AD settings, but the best we could get were timeouts, even up to 30 seconds without result.</p>
<p class="ms-outlook-mobile-reference-message skipProofing">My gut feeling is you need a recent freshly patched AD to reproduce this, you most probably won't be able to reproduce this with e..g OpenLDAP nested groups. So it would be great if someone who knows
more about AD settings could find the switch to re-enable this.</p>
<p class="ms-outlook-mobile-reference-message skipProofing">Cheers</p>
<p class="ms-outlook-mobile-reference-message skipProofing">Martin</p>
<p class="ms-outlook-mobile-reference-message skipProofing"><br>
</p>
<p class="ms-outlook-mobile-reference-message skipProofing"><br>
</p>
<p class="ms-outlook-mobile-reference-message skipProofing"><br>
</p>
<div class="moz-cite-prefix">Am 19.04.26 um 22:09 schrieb Fisher, Daniel via users:</div>
<blockquote>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-size: 16px; color: rgb(0, 0, 0);">What version of the IDP are you running?</span></p>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-size: 16px; color: rgb(0, 0, 0);">Are you setting followReferrals=</span>“<span style="font-size: 16px; color: rgb(0, 0, 0);">true</span><span style="font-size: 16px;">”</span><span style="font-size: 16px; color: rgb(0, 0, 0);"> directly
on the <DataConnector/> configuration? </span></p>
<p class="ms-outlook-mobile-reference-message skipProofing"><span style="font-size: 16px; color: rgb(0, 0, 0);">If you post your (redacted) configuration here I can review it.</span></p>
</blockquote>
<div class="moz-signature">--</div>
<p class="moz-signature"><b>Dr. MARTIN HITSCHEL | System Engineer</b></p>
<p class="moz-signature">Phone: +49 7071 407109-0<br>
Email: martin.hitschel@daasi.de</p>
<p class="moz-signature"><b>DAASI International GmbH</b><br>
Europaplatz 3<br>
D-72072 Tübingen, Germany<br>
<a href="http://www.daasi.de/" class="moz-txt-link-abbreviated" originalsrc="http://www.daasi.de/" data-outlook-id="78108ec5-d464-4a7f-af8d-31980e12492f" style="margin-top: 0px; margin-bottom: 0px;">www.daasi.de</a></p>
<p class="moz-signature">Registered Office: Tübingen<br>
Registration Court: Amtsgericht Stuttgart, HRB 382175<br>
CEO: Peter Gietz</p>
</div>
</body>
</html>