I'm not sure whether it's better to nest groups under each of my organizational units or to make an organization unit directly under the root DN just for groups. Is one considered best practice over the other? I want to keep my configuration as vanilla as possible to maximize compatibility with LDAP-aware applications.
My immediate needs include:
- SSO with Atlassian Crowd
- Google Apps Directory Sync (LDAP Groups -> Mailing Lists)
- pGina for Windows Authentication
Here is a diagram showing the two strategies I'm considering: