[Date Prev][Date Next] [Chronological] [Thread] [Top]

extensible match quirks for Active Directory



Hi,

we recently found out that some versions of Active Directory don't 
accept some extensible matching filters. (Newer Versions seem to work 
correctly.)
The problem is that AD seems to be unable to decode the extensible 
match, when the "dnAttributes" field is missing in the request (which 
means it's using the default value "false"). Explicitly adding the 
boolean (with a false value) to the request makes AD work as expected. 
Would you accept the addition of a workaround for this problem to 
libldap (something that can be switched on by some ldap_set_option() 
call)?

-- 
regards,
	Ralf