Pierangelo Masarati wrote:
Partial correction: authz syntax is enabled by default in 2.4, while in 2.3 it's still protected by an #ifdef LDAP_DEVEL. As a consequence, yes, any DN must be in the form it would appear after normalization.
Hmm, in the mean-time I managed to get it working with 2.3.36 without "normalizing" what's added behind dn.onelevel or dn.children. Strange.
Also it behaves differently on different systems. "group:" works on openSUSE 10.2 but not on SuSE Linux 9.3. Is it highly dependent on version of libregex or similar? Still investigating it...
Ciao, Michael.