Hi Mal, thanks for the reply. I am using 6.0.2 and the group mapping I'm talking about is a master group resource mapping. I do LDAP authentication as well but that works fine and is out of scope of this topic. In this case I have several thousand user DNs that need to be mapped to the master group in question, but the Domino directory can't support that many DNs in one group.
I'm really just looking for working examples of how the "Dynamic members attribute" group resource mapping works so I can evaluate whether it can help me solve my problem.
I checked to see if I can wildcard the group object DN in an LDAP group object resource group mapping method and you can not, at least not using notation like "CN=AuthorizedGroup*" and having group DNs "CN=AuthorizedGroup1" and "CN=AuthorizedGroup2" defined with members in LDAP.