<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — group query returns group as member of itself]]></title>
	<link rel="self" href="http://www.iredmail.org/forum/feed-atom-topic4194.xml" />
	<updated>2012-11-24T03:01:19Z</updated>
	<generator>PunBB</generator>
	<id>http://www.iredmail.org/forum/topic4194-group-query-returns-group-as-member-of-itself.html</id>
		<entry>
			<title type="html"><![CDATA[Re: group query returns group as member of itself]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post19207.html#p19207" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>crawleyinc wrote:</cite><blockquote><p>==== Required information ====<br />- iRedMail version: 0.8.3<br />- Store mail accounts in which backend : LDAP (AD)<br />- Linux/BSD distribution name and version: Debian Squeeze<br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>Whenever I query a group in AD for a list of members (as a distribution group), the values I get returned are as expected, with the unwanted addition of the group itself (so it returns sam@xxx.com,joe@xxx.com,team@xxx.com).&nbsp; So whenever I send a message to the DL, I get a bounce back that says team@xxx.com doesn&#039;t exist as a user (to be expected).&nbsp; I&#039;ve set up iRedMail before and I don&#039;t remember encountering this issue.</p><p>Here is a copy of my ad_virtual_group_maps:</p><p>server_host&nbsp; &nbsp; &nbsp;= xxx.yyy.local<br />server_port&nbsp; &nbsp; &nbsp;= 389<br />version&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= 3<br />bind&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; = yes<br />start_tls&nbsp; &nbsp; &nbsp; &nbsp;= no<br />bind_dn&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= mail<br />bind_pw&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= -------------<br />search_base&nbsp; &nbsp; &nbsp;= ou=zzz,dc=yyy,dc=local<br />scope&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= sub<br />query_filter&nbsp; &nbsp; = (&amp;(objectClass=group)(mail=%s))<br />special_result_attribute = member<br />#leaf_result_attribute = mail<br />result_attribute = mail<br />debuglevel&nbsp; &nbsp; &nbsp; = 0</p><p>I checked to make sure that the DL wasn&#039;t a member of itself, and it&#039;s not.&nbsp; The only members that AD and ADExplorer list in that group are the correct ones.</p><p>Any ideas?</p></blockquote></div><p>Answered my own question:&nbsp; As far as I can tell, the special_result_attribute will return all users plus the group itself, the leaf_result_attribute will return just the members (which kind of makes sense).&nbsp; This will probably mostly affect people whose internal domain isn&#039;t a TLD/doesn&#039;t match their mail domain so they have to change the LDAP queries around to make it work (hence me breaking it).</p><p>Hope this is able to help someone else out in the future.</p>]]></content>
			<author>
				<name><![CDATA[crawleyinc]]></name>
				<uri>http://www.iredmail.org/forum/user31874.html</uri>
			</author>
			<updated>2012-11-24T03:01:19Z</updated>
			<id>http://www.iredmail.org/forum/post19207.html#p19207</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[group query returns group as member of itself]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post19206.html#p19206" />
			<content type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.3<br />- Store mail accounts in which backend : LDAP (AD)<br />- Linux/BSD distribution name and version: Debian Squeeze<br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>Whenever I query a group in AD for a list of members (as a distribution group), the values I get returned are as expected, with the unwanted addition of the group itself (so it returns sam@xxx.com,joe@xxx.com,team@xxx.com).&nbsp; So whenever I send a message to the DL, I get a bounce back that says team@xxx.com doesn&#039;t exist as a user (to be expected).&nbsp; I&#039;ve set up iRedMail before and I don&#039;t remember encountering this issue.</p><p>Here is a copy of my ad_virtual_group_maps:</p><p>server_host&nbsp; &nbsp; &nbsp;= xxx.yyy.local<br />server_port&nbsp; &nbsp; &nbsp;= 389<br />version&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= 3<br />bind&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; = yes<br />start_tls&nbsp; &nbsp; &nbsp; &nbsp;= no<br />bind_dn&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= mail<br />bind_pw&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= -------------<br />search_base&nbsp; &nbsp; &nbsp;= ou=zzz,dc=yyy,dc=local<br />scope&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;= sub<br />query_filter&nbsp; &nbsp; = (&amp;(objectClass=group)(mail=%s))<br />special_result_attribute = member<br />#leaf_result_attribute = mail<br />result_attribute = mail<br />debuglevel&nbsp; &nbsp; &nbsp; = 0</p><p>I checked to make sure that the DL wasn&#039;t a member of itself, and it&#039;s not.&nbsp; The only members that AD and ADExplorer list in that group are the correct ones.</p><p>Any ideas?</p>]]></content>
			<author>
				<name><![CDATA[crawleyinc]]></name>
				<uri>http://www.iredmail.org/forum/user31874.html</uri>
			</author>
			<updated>2012-11-24T02:53:24Z</updated>
			<id>http://www.iredmail.org/forum/post19206.html#p19206</id>
		</entry>
</feed>
