RE: rootdn DN is invalid.

> realm is an invalid attribute

Of course, the whole point of using a sasl-regexp is to turn the
"xxx,cn=auth" form of DN into one that you can actually use. So keeping that
"xxx,cn=auth" DN in your rootdn directive is completely missing the point.
Given the regexp you used, your rootdn ought to be something like
  rootdn uid=astrldapadmin,ou=admin,dc=astro-lsa-umich,dc=edu

Of course, to use domainComponent as it was intended, your suffix ought to be
instead of

