Accept the default, or supply the name of the dynamic member attribute
in the Name of dynamic member attribute field. The name of the
dynamic member attribute defines the filter for dynamic group members in LDAP,
for example, memberURL is the name of a commonly used dynamic member attribute.If
both member and dynamic member attributes are specified for the same group
type, this group type is a hybrid group with both static and dynamic members.
A
dynamic group defines its members differently than a static group. Instead
of listing the members individually, the dynamic group defines its members
using an LDAP search. The filter for the search is defined in a dynamic member
attribute. For example, the dynamic group uses the structural objectclass
groupOfURLs, or auxiliary objectclass ibm-dynamicGroup, and the attribute
memberURL, to define the search using a simplified LDAP URL syntax:
ldap:///<base
DN of search> ? ? <scope of search> ? <searchfilter>
The
following is an example of the LDAP URL that defines all entries that are
under o=Acme with the objectclass=person:
ldap:///o=Acme,c=US??sub?objectclass=person