On Sep 28, 2011, at 5:13 PM, Allen, Dedrick wrote: > it sends an empty bind dn no matter how I specify it How about testing an empty authzFrom, just for test/debug? idassert-authzFrom "*" That should match anything you're supplying. If that works, you can go back and figure out why it didn't work :). -- If something's hard to do, then it's not worth doing. - Homer Simpson