RE: ldap proxy to AD returns no results - take#2

> What does the binddn and bindpw do then if it doesn't specifically bind
> the proxied query to AD?

It is used internally by back-ldap to bind to the remote server when
accessing data on behalf of the proxy itself, not on behalf of clients,
e.g. for ACL purposes or so.  E.g if you have a "group" ACL, the server
needs to be allowed to fetch the "group" entry to see the client user has
appropriate permissions.  Note that the client itself doesn't need access
to the "group" entry for appropriate use of the ACLs.  In regular
databases this is not an issue because the information is local.  However,
in back-ldap information is stored remotely so the proxy may need a
privileged identity to access it.


