vault write auth/ldap/config \Â Â url="ldaps://ldap.test.com" \Â Â starttls=true \Â Â insecure_tls=false \Â Â binddn="uid=vault,ou=applications,dc=test,dc=com" \Â Â bindpass="**SNIP**" \Â Â userdn="ou=users,dc=test,dc=com" \Â Â userattr="uid" \Â Â groupdn="ou=groups,dc=test,dc=com" \Â Â groupattr="cn" \Â Â groupfilter="(&(objectClass=posixGroup)(&(cn=*)(memberUid={{.Username}})))"57bc0ab5 conn=319658 op=3 SRCH base="ou=groups,dc=test,dc=com" scope=2 deref=0 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bc0ab5 conn=319658 op=3 SRCH attr=cn57bc0ab5 conn=319658 op=3 SEARCH RESULT tag=101 err=32 nentries=0 text=57bc0c91 conn=319751 op=2 SRCH base="ou=groups,dc=test,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bc0c91 conn=319751 op=2 SRCH attr=cn57bc0c91 conn=319751 op=2 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea018 conn=351332 fd=139 ACCEPT from IP=000.000.000.000:51413 (IP=0.0.0.0:636)57bea018 conn=351332 fd=139 TLS established tls_ssf=128 ssf=12857bea019 conn=351332 op=0 BIND dn="uid=vault,ou=applications,dc=redacted,dc=com" method=12857bea019 conn=351332 op=0 BIND dn="uid=vault,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea019 conn=351332 op=0 RESULT tag=97 err=0 text=57bea019 conn=351332 op=1 SRCH base="ou=users,dc=redacted,dc=com" scope=2 deref=3 filter="(uid=acurtis)"57bea019 conn=351332 op=1 SEARCH RESULT tag=101 err=0 nentries=1 text=57bea019 conn=351332 op=2 BIND anonymous mech=implicit ssf=057bea019 conn=351332 op=2 BIND dn="cn=acurtis,ou=users,dc=redacted,dc=com" method=12857bea019 conn=351332 op=2 BIND dn="cn=acurtis,ou=users,dc=redacted,dc=com" mech=SIMPLE ssf=057bea019 conn=351332 op=2 RESULT tag=97 err=0 text=57bea019 conn=351332 op=3 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea019 conn=351332 op=3 SRCH attr=cn57bea019 conn=351332 op=3 SEARCH RESULT tag=101 err=32 nentries=0 text=57bea119 conn=351384 fd=142 ACCEPT from IP=000.000.000.000:57883 (IP=0.0.0.0:636)57bea119 conn=351384 fd=142 TLS established tls_ssf=128 ssf=12857bea119 conn=351384 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" method=12857bea119 conn=351384 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea119 conn=351384 op=0 RESULT tag=97 err=0 text=57bea119 conn=351384 op=1 SRCH base="ou=users,dc=redacted,dc=com" scope=1 deref=3 filter="(&(objectClass=inetOrgPerson)(uid=acurtis))"57bea119 conn=351384 op=1 SRCH attr=uid displayName mail labeledUri57bea119 conn=351384 op=1 SEARCH RESULT tag=101 err=0 nentries=1 text=57bea119 conn=351384 op=2 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea119 conn=351384 op=2 SRCH attr=cn57bea119 <= bdb_equality_candidates: (memberUid) not indexed57bea119 conn=351384 op=2 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea119 conn=351384 op=3 UNBIND57bea119 conn=351384 fd=142 closed57bea119 conn=351385 fd=142 ACCEPT from IP=000.000.000.000:57900 (IP=0.0.0.0:636)57bea119 conn=351385 fd=142 TLS established tls_ssf=128 ssf=12857bea119 conn=351385 op=0 BIND dn="cn=acurtis,ou=users,dc=redacted,dc=com" method=12857bea119 conn=351385 op=0 BIND dn="cn=acurtis,ou=users,dc=redacted,dc=com" mech=SIMPLE ssf=057bea119 conn=351385 op=0 RESULT tag=97 err=0 text=57bea119 conn=351385 op=1 UNBIND57bea119 conn=351385 fd=142 closed57bea119 conn=351386 fd=142 ACCEPT from IP=000.000.000.000:57901 (IP=0.0.0.0:636)57bea119 conn=351386 fd=142 TLS established tls_ssf=128 ssf=12857bea119 conn=351386 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" method=12857bea119 conn=351386 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea119 conn=351386 op=0 RESULT tag=97 err=0 text=57bea119 conn=351386 op=1 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea119 conn=351386 op=1 SRCH attr=cn57bea119 <= bdb_equality_candidates: (memberUid) not indexed57bea119 conn=351386 op=1 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea119 conn=351386 op=2 UNBIND57bea119 conn=351386 fd=142 closed57bea119 conn=351387 fd=142 ACCEPT from IP=000.000.000.000:57906 (IP=0.0.0.0:636)57bea119 conn=351387 fd=142 TLS established tls_ssf=128 ssf=12857bea119 conn=351387 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" method=12857bea119 conn=351387 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea119 conn=351387 op=0 RESULT tag=97 err=0 text=57bea119 conn=351387 op=1 SRCH base="ou=users,dc=redacted,dc=com" scope=1 deref=3 filter="(&(objectClass=inetOrgPerson)(uid=acurtis))"57bea119 conn=351387 op=1 SRCH attr=uid displayName mail labeledUri57bea119 conn=351387 op=1 SEARCH RESULT tag=101 err=0 nentries=1 text=57bea119 conn=351387 op=2 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea119 conn=351387 op=2 SRCH attr=cn57bea119 <= bdb_equality_candidates: (memberUid) not indexed57bea119 conn=351387 op=2 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea119 conn=351387 op=3 UNBIND57bea119 conn=351387 fd=142 closed57bea119 conn=351388 fd=142 ACCEPT from IP=000.000.000.000:57914 (IP=0.0.0.0:636)57bea119 conn=351388 fd=142 TLS established tls_ssf=128 ssf=12857bea119 conn=351388 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" method=12857bea119 conn=351388 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea119 conn=351388 op=0 RESULT tag=97 err=0 text=57bea11a conn=351388 op=1 SRCH base="ou=users,dc=redacted,dc=com" scope=1 deref=3 filter="(&(objectClass=inetOrgPerson)(uid=acurtis))"57bea11a conn=351388 op=1 SRCH attr=uid displayName mail labeledUri57bea11a conn=351388 op=1 SEARCH RESULT tag=101 err=0 nentries=1 text=57bea11a conn=351388 op=2 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea11a conn=351388 op=2 SRCH attr=cn57bea11a <= bdb_equality_candidates: (memberUid) not indexed57bea11a conn=351388 op=2 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea11a conn=351388 op=3 UNBIND57bea11a conn=351388 fd=142 closed57bea11a conn=351389 fd=142 ACCEPT from IP=000.000.000.000:57965 (IP=0.0.0.0:636)57bea11a conn=351389 fd=142 TLS established tls_ssf=128 ssf=12857bea11a conn=351389 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" method=12857bea11a conn=351389 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea11a conn=351389 op=0 RESULT tag=97 err=0 text=57bea11a conn=351389 op=1 SRCH base="ou=users,dc=redacted,dc=com" scope=1 deref=3 filter="(&(objectClass=inetOrgPerson)(uid=acurtis))"57bea11a conn=351389 op=1 SRCH attr=uid displayName mail labeledUri57bea11a conn=351389 op=1 SEARCH RESULT tag=101 err=0 nentries=1 text=57bea11a conn=351389 op=2 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea11a conn=351389 op=2 SRCH attr=cn57bea11a <= bdb_equality_candidates: (memberUid) not indexed57bea11a conn=351389 op=2 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea11a conn=351389 op=3 UNBIND57bea11a conn=351389 fd=142 closed57bea2f8 conn=351481 fd=142 ACCEPT from IP=000.000.000.000:41453 (IP=0.0.0.0:636)57bea2f8 conn=351481 fd=142 TLS established tls_ssf=128 ssf=12857bea2f8 conn=351481 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" method=12857bea2f8 conn=351481 op=0 BIND dn="uid=nexus2,ou=applications,dc=redacted,dc=com" mech=SIMPLE ssf=057bea2f8 conn=351481 op=0 RESULT tag=97 err=0 text=57bea2f8 conn=351481 op=1 SRCH base="ou=users,dc=redacted,dc=com" scope=1 deref=3 filter="(&(objectClass=inetOrgPerson)(uid=*))"57bea2f8 conn=351481 op=1 SRCH attr=uid displayName mail labeledUri57bea2f8 conn=351481 op=1 SEARCH RESULT tag=101 err=0 nentries=3 text=57bea2f8 conn=351481 op=2 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))"57bea2f8 conn=351481 op=2 SRCH attr=cn57bea2f8 <= bdb_equality_candidates: (memberUid) not indexed57bea2f8 conn=351481 op=2 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea2f8 conn=351481 op=3 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=jjackson)))"57bea2f8 conn=351481 op=3 SRCH attr=cn57bea2f8 <= bdb_equality_candidates: (memberUid) not indexed57bea2f8 conn=351481 op=3 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea2f8 conn=351481 op=4 SRCH base="ou=groups,dc=redacted,dc=com" scope=2 deref=3 filter="(&(objectClass=posixGroup)(&(cn=*)(memberUid=mfenn)))"57bea2f8 conn=351481 op=4 SRCH attr=cn57bea2f8 <= bdb_equality_candidates: (memberUid) not indexed57bea2f8 conn=351481 op=4 SEARCH RESULT tag=101 err=0 nentries=2 text=57bea2f8 conn=351481 op=5 UNBIND57bea2f8 conn=351481 fd=142 closedldapsearch -x -H ldaps://ldap.test.com -b ou=groups,dc=redacted,dc=com -s sub -D cn=acurtis,ou=users,dc=redacted,dc=com -W -E pr=1000/noprompt -o ldif-wrap=no '(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))'
vs.
ldapsearch -x -H ldaps://ldap.test.com -b ou=groups,dc=redacted,dc=com -s sub -D uid=vault,ou=applications,dc=redacted,dc=com -W -E pr=1000/noprompt -o ldif-wrap=no '(&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))'# extended LDIF## LDAPv3# base <ou=groups,dc=redacted,dc=com> with scope subtree# filter: (&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))# requesting: ALL# with pagedResults control: size=1000#
# search resultsearch: 2result: 32 No such object
# numResponses: 1# extended LDIF## LDAPv3# base <ou=groups,dc=redacted,dc=com> with scope subtree# filter: (&(objectClass=posixGroup)(&(cn=*)(memberUid=acurtis)))# requesting: ALL# with pagedResults control: size=1000#
# admin, groups, mooloop.comdn: cn=admin,ou=groups,dc=redacted,dc=comcn: admingidNumber: 500objectClass: posixGroupobjectClass: topmemberUid: acurtismemberUid: mfennmemberUid: jjackson
# users, groups, mooloop.comdn: cn=users,ou=groups,dc=redacted,dc=comcn: usersgidNumber: 501objectClass: posixGroupobjectClass: topmemberUid: acurtismemberUid: mfennmemberUid: jjackson
# search resultsearch: 2result: 0 Successcontrol: 1.2.840.113556.1.4.319 false MAUCAQAEAA==pagedresults: cookie=
# numResponses: 3# numEntries: 2