I have a domain structure similar to this:
DC=us,DC=earth,DC=com
DC=uk,DC=earth,DC=com
DC=au,DC=earth,DC=com
Each domain has a users OU and a groups OU.
Each domain has users (us,uk,au) 01 to 10 i.e. us01, us02,...., uk01, uk02,.... ,au01, au02..
There is a group:
cn=group1,ou=groups,DC=uk,DC=earth,DC=com
us01,uk01 and au01 are members of
cn=group1,ou=groups,DC=uk,DC=earth,DC=com.
I am trying to run an LDAP query to return all members of
cn=group1,ou=groups,DC=uk,DC=earth,DC=com
I believed a base DN of "DC=earth,DC=com" with a filter of
memberof=cn=group1,ou=groups,DC=uk,DC=earth,DC=com"
with a SUBTREE level scope should work however it isn't.
What am I doing wrong? Is it possible?
I am using JXplorer to test.
Furthermore I can only query/return objects contained in the local domain i.e. if I use earth.com as the BASE DN I can only "see" objects in the earth domain returned. It doesn't seem to be able to transverse the subdomains. Is this normal?
I also can't view objects in sibling domains i.e. I can't see uk users when using the au domain as the BASE DN. I believe this to be correct as the BASE DN needs to have the AD objects in its SUBTREE to be able to "see" them. Is this correct?