Hi Nathan, >> The thing is that uniquemember does not have the DN syntax, it has >> "Name and Optional UID syntax" : >> >> attributeTypes: ( 2.5.4.50 NAME 'uniqueMember' >> ?EQUALITY uniqueMemberMatch >> ?SYNTAX 1.3.6.1.4.1.1466.115.121.1.34 >> ?X-ORIGIN 'RFC 4519' ) > > Please open a bug on this. ?My current thinking is that we should also allow > the grouping attribute to use this syntax, but you should be aware that > memberOf will not work if you actually have the optional UID part present. You were faster than me, thank you :) I think this notice ("one should be aware that memberOf will not work if the optional UID part present in an attribute with <Name and Optional UID > syntax") should be added to the documentation on memberOf plug-in of the future RedHat release. I will add this snippet to the bug. @+