ad_ldap_base now contains the entire base DN
The meaning of the ad_ldap_base configuration option has changed, and it's now mandatory for status synchronization. This setting should now contain the full DN of the tree in Active Directory where account information is stored (such as cn=Accounts,dc=example,dc=com). Previously, the dc components should be omitted and were derived from the realm; this is no longer done. If this configuration option is not set, principal status will not be synchronized to Active Directory.
Showing with 35 additions and 44 deletions