If you want to use an OpenLDAP server for identity federation, you must configure specific settings on the OpenLDAP server.
The memberof and refint overlays should be enabled. For more information, see the instructions for reverse group membership maintenance in the administrator’s guide for OpenLDAP.
In addition, ensure the fields mentioned in the help for Username are indexed for optimal performance.
See the information about reverse group membership maintenance in the administrator’s guide for OpenLDAP.