> ldap user suffix = ou=people,dc=example,dc=com > ldap group suffix = ou=groups,dc=example,dc=com > ldap suffix = dc=example,dc=com Since your suffix is already in "ldap suffix", the other entries should be: ldap user suffix = ou=people ldap group suffix = ou=groups Don't you need the entry "ldap machine suffix"?