Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.Sign up
rlm_ldap: extract group name from group RDN #1788
If you configure a group membership query like this:
and of course the memberOf attribute contains a DN, but the group RDN is
There is an edge case to consider: what if the group entry has multiple values for the cn attribute? Arguably, you might want to map the group to multiple names.
Personally I'd just want the primary cn (i.e. the one in the RDN). Having additional cn's would raise the risk that one group could masquerade as another. If there really are people who want this, the extraction of name_attributes from DN could be optional.
Example on the list