HCL
Skip to main content  
 
   


SPRTechnote


Group Authentication Fails With Comma In the Distinguished Name (DN)

Technote Number: 1170833


Problem:
This issue was reported to Quality Engineering and has been addressed in Domino
6.5.3.

Excerpt from the Lotus Notes and Domino Release 6.5.3 MR fix list (available at
http://www.ibm.com/developerworks/lotus):

Directory Services
SPR# JMOE5Z7PEC - This fix will no longer remove backslashes from the member
name when comprising an LDAP search filter.

The situation occurs if a user has a comma in his/her DN (distinguished name),
such as CN=McClure, Troy. If so, Domino cannot process the LDAP search filter
and the backslash is not sent by the Domino server. This problem also occurs
with the LDAPSearch Utility.

The proper LDAP search filter for group authentication is as follows:
(&(objectclass=groupOfNames)(Member=CN=McClure\,Troy,OU=Springfield,O=USA))

If you haven't yet upgraded, you can work around this issue by removing the
comma from the DN.
More >





  Document options
Print this document
Print view

  Search
Search Advanced Search


  Fix list views

 RSS feeds   RSS
Subscribe to the fix list

  Resources
Using this database
View notices

  HCL Support
HCL Support


    About HCL Privacy Contact