I have an AD group membership query which I'm executing from Linux (I am trying to use SSSD on RHEL 6.4 to authenticate users from Active Directory). From the SSSD logs the query is returning zero results, and when I run it from the same RHEL box with ldapsearch
it also returns zero results:
ldapsearch -H ldap://server1.mycompany.com/ -Y GSSAPI -b "ou=users,ou=dev,dc=mycompany,dc=com" "(&(sAMAccountName=d-test2)(objectclass=user)(memberOf=CN=LOC-RHEL-Admins,OU=Security Groups,OU=Dev,DC=mycompany,DC=com))"
However run it from ldp.exe on windows using the same query and base and it returns the group members as expected. For the ldapsearch command GSSAPI and all other params are all fine; if I take out the memberOf clause it returns results, so it's just the
memberOf bit that is failing.
Anyone know what is going on to cause this difference? thanks Dan