We use Open Directory as our primary LDAP service whcih normally works pretty well. I'm trying to get LDAP authentication profiles up and running and am only having limited success. By limited I mean I can authenticate a user against a simple config where I am looking for the "uid" login attribute in the users group using cn=users,dc=server,dc=mydomain,dc=com. If I try to authenticate a user in a group called sslvpn (cn=sslvpn,cn=groups,dc=server,dc=mydomain,dc=com) using "memberUid" as the login attribute the session login fails with an invalid username/password error. Just wondering if there is a limitation in PANOS when it comes to Open Directory attributes or if I'm doing something simple wrong? Jason
... View more