AD sssd.conf ldap_access_filter
Приветствую!
Может кто подскажет, почему игнорируется ldap_access_filter в таком конфиге:
[domain/default]
enumerate = true
cache_credentials = true
id_provider = ldap
auth_provider = krb5
chpass_provider = krb5
access_provider = ldap
ldap_access_filter = mebberOf=cn=group002,ou=Tests,ou=Groups,ou=Center,dc=pass,dc=local
ldap_search_base = dc=pass,dc=local
#ldap_access_filter = cn=group002
#ldap_access_filter = &(uidNumber>=400001)(uidNumber<=400002)
ldap_access_order = filter
ldap_sasl_mech = GSSAPI
ldap_sasl_authid = host/test.pass.local@PASS.LOCAL
ldap_schema = rfc2307bis
debug_level = 9
ldap_user_object_class = user
ldap_user_home_directory = unixHomeDirectory
ldap_user_principal = userPrincipalName
ldap_user_name = sAMAccountName
ldap_group_object_class = group
ldap_access_order = expire
ldap_account_expire_policy = ad
ldap_force_upper_case_realm = True
krb5_realm = PASS.LOCAL
[sssd]
services = nss, pam
config_file_version = 2
domains = default
debug_level = 9
[nss]
[pam]