Description
Users in my LDAP are in hierarchy (which represents supervising).
For example (rootContext is dc=company,dc=com and userFilterBase is o=users):
dn: uid=bigboss,o=users,dc=company,dc=com
dn: uid=employer,uid=bigboss,o=users,dc=company,dc=com
Now method org.apache.jetspeed.security.spi.impl.ldap.LdapPrincipalDaoImpl.getUserDN(String, boolean)
returns invalid DN: uid=employer,o=users,dc=company,dc=com
This cause that roles and groups are not resolved.
Let say I have a role:
dn: cn=admin,o=roles,dc=company,dc=com
objectClass: groupOfUniqueNames
objectClass: top
cn: admin
uniqueMember: uid=employer,uid=bigboss,o=users,dc=company,dc=com
but role admin is not assigned to user employer.