Canonification doesn't work through non-role groups (or, non-memberOf group membership).
The existing code path does not allow for both group membership as well as canonification to exist in parallel / sequentially.
ldap_group_base: dc=example,dc=org ldap_group_filter: (&(cn=%U)(objectclass=groupofnames)(|(objectclass=groupofuniquenames)(objectclass=groupofurls))) ldap_group_scope: sub ldap_member_base: dc=example,dc=org ldap_member_method: filter ldap_member_filter: (uniqueMember=%D) ldap_member_attribute: cn