https://issues.apache.org/bugzilla/show_bug.cgi?id=46646 check group membership is sometimes case sensitive "AuthLDAPRemoteUserAttribute uid AuthLDAPGroupAttribute memberUid AuthLDAPGroupAttributeIsDN Off AuthBasicProvider ldap require ldap-group cn=Domain Admins,ou=Group, dc=DOMAIN,dc=de" memberUid is not case insensitive (memberUid from posixGroup, which is also used by samba domain groups). diff -Nur httpd-2.2.11-orig/modules/aaa/mod_authnz_ldap.c httpd-2.2.11/modules/aaa/mod_authnz_ldap.c --- httpd-2.2.11-orig/modules/aaa/mod_authnz_ldap.c 2009-02-06 16:50:02.000000000 +0100 +++ httpd-2.2.11/modules/aaa/mod_authnz_ldap.c 2009-02-06 17:07:43.000000000 +0100 @@ -454,6 +454,7 @@ if (sec->remote_user_attribute && !strcmp(sec->remote_user_attribute, sec->attributes[i])) { r->user = (char *)apr_pstrdup(r->pool, vals[i]); + req->user = r->user; remote_user_attribute_set = 1; } i++;