If anybody is curious how to get subdomains working, you can 'trick' this to work by defining the triple this way: (ldap02.inside, , exampledomain.com) instead of this: (ldap02, , inside.exampledomain.com) This appears to allow this to work. Hope this helps.