JBoss retrieves LDAP user's groups only with the "Common Name" (cn), not the Fully Distinguished Name (dn)

Solution Verified - Updated -

Issue

We have a security domain successfully configured to use LDAP. Both authentication and authorization work fine, but we have an issue with the group names returned.

We have two groups in LDAP:
cn=Admin,ou=Dev,ou=Groups,dc=example,dc=com
cn=Admin,ou=Prod,ou=Groups,dc=example,dc=com

When JBoss retrieves the user's groups, we only get "Admin" so we cannot differentiate these two groups.
We need the Fully Distinguished Name returned instead of Common Name

Environment

  • Red Hat JBoss Enterprise Application Platform (EAP)
    • 5.x
    • 6.x
  • Windows Active Directory
  • Red Hat Directory Server
  • Sun Directory Server
  • other LDAP servers

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.