Hi Nathan, > > Prior to 1.2.7, how was this configuration working for you? What sort of > values were you setting in the "uniqueMember" attribute? The memberOf > plug-in really needs a full DN to work, which is why the restriction to use > an attribute with the DN syntax was added. We use the uniqueMember attribute in a rather typical manner for group objects: to list the DNs of the sub-groups and members : cn=My Group,ou=Groups,dc=example,dc=com objectClass: top objectClass: groupofuniquenames cn: My Group uniqueMember: uid=someone,ou=Users,dc=example,dc=com uniqueMember: cn=Another Group,ou=Groups,dc=example,dc=com It's a relatively common way of uniqueMember usage, not limited to our environment, i think. @+ -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users