powered by Jive Software

Active Directory Groups Have No Members

I downloaded and installed Openfire 3.4.1 yesterday and installed it on a development server. I worked to connect openfire to our Active Directory. I am able to see all of the users and the groups, however there are no members in most of the groups. I am not sure what the problem is. Most groups show no members and all of the users show no groups.

Here is what I installed and configured.

  • Windows 2003 Standard Server

  • Microsoft SQL 2005

  • openfire_3_4_1.exe for Widows

I have the following for the LDAP section.





<alternateBaseDN>ou=associates;dc=something,dc=local</alternateBaseDN& gt;


















If there is a fix for this, that would be great. Not sure what other information would be helpful.

Thanks for your help.

Do you have this in your provider section?


<className>org.jivesoftware.openfire.ldap.LdapGroupProvider</className >


If so can you send more of the config?

use this as your group filter instead (taking for granted you want ALL AD groups)


This is show you all groups, populated.

Thanks for the suggestions above. I was never able to figure this out. The alternateBaseDNwas pointing to my groups OU. This never seemed to work. To resolve this, I removed the alternateBaseDN and moved the Groups OU to within the baseDN. All works now.




Nevermind i fixed it :). I forgot you have to actually create a group for IM users because it doesn’t use the Domain Users group. In all my other setups there were already multiple AD security groups, but this is a new client with only 5 users so I was just going to use the Domain Users group. I created a new group and put everyone in there and now all is good.

My groups container was not within the primary base DN. I moved the container to within the search base DN and now I have no problems. I am no longer using an alternateBaseDN.

Hope this helps.

Jarred Cleem

IT Manager

Multiband / NASDAQ: MBND

Direct: 701-281-5376

1-866-577-MBND (6263)


Just in case someone else comes across this thread like I did…

My groups were showing, but my group members were not.

My problem turned out to be that ldap.posixMode was set to ‘true’ and needed to be changed to ‘false’. I hope this saves someone some troubleshooting time.

1 Like