About Managing LDAP User Roles
A relative distinguished name (RDN) further qualifies a base distinguished name (DN). For example, if the base DN for a given LDAP directory is dc=domainName, dc=com, and the full DN is cn=group1,ou=users,dc=domainName,dc=com, then the RDN is cn=group1,ou=users.
The topics in this section describe how to use LDAP RDNs to determine user roles.