> If so, it seems unnecessary in the case of Active Directory, since AD allows you > to bind simply giving username and password (you don't have to give a full DN > when binding). It is unnecessary to perform the search if your users provide something that can bind to the LDAP server directly. Patches welcome (but it's unfortunately complicated by the mod_ldap/mod_authnz_ldap separation) -- Eric Covener covener@xxxxxxxxx --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx