Simon MacMullen simon at rabbitmq.com
Tue Jun 10 11:21:57 BST 2014


On 10/06/14 02:23, Mueller, Peter wrote:
> {in_group,"cn=rabbitmq_write,ou=Group,dc=company,dc=com"}

> uniqueMember: uid=crawforb,ou=People,dc=company,dc=com
> uniqueMember: uid=dasilvai,ou=People,dc=company,dc=com
> uniqueMember: uid=muellerpe,ou=People,dc=company,dc=com

There's your problem. LDAP servers determine group membership by the 
presence of a variety of differently-named attributes. The 2-tuple 
version of in_group looks for an attribute called "member", but yours 
are "uniqueMember".

So you want to change the above to:

{in_group,"cn=rabbitmq_write,ou=Group,dc=company,dc=com", "uniqueMember"}

Cheers, Simon

