# scientists, example.comdn: ou=scientists,dc=example,dc=comuniqueMember: uid=einstein,dc=example,dc=comuniqueMember: uid=galieleo,dc=example,dc=comuniqueMember: uid=tesla,dc=example,dc=comuniqueMember: uid=newton,dc=example,dc=comou: scientistscn: ScientistsobjectClass: groupOfUniqueNamesobjectClass: top
set VAULT_ADDR=http://127.0.0.1:8200
vault auth-enable ldap
vault write auth/ldap/config url="ldap://ldap.forumsys.com" \ binddn='cn=read-only-admin,dc=example,dc=com' \ bindpass='password' \ userdn='dc=example,dc=com' \ userattr='uid' \ groupfilter='(uniqueMember={{.UserDN}})' \ groupdn='dc=example,dc=com' \ groupattr='memberOf'
vault write auth/ldap/groups/scientists policies=foo
vault auth -method=ldap username=einsteinCode: 400. Errors:
* user is not a member of any authorized group