Quote from: mimugmail on May 14, 2018, 01:56:37 PMTried that as well, if I do it stops authenticating users altogether :(
Shouldn't the extended query not something like (&memberof(fw-admins))?
In my case it would be: (memberOf=cn=fw-admins,ou=Groups,dc=redacted,dc=redacted)
It works in ApacheDS, though, so I assume the filter is written correctly (I use similar filters for other pieces of software and they work fine)
By the way in theory that should only filter out which users are available to opnSense, by leaving it empty I'll just allow it to use every user it can find laying around - the major issue here is that it's not getting group membership for users at all :-\