I hope that this post can help someone.
We spent a couple of hours trying to make it work.
ldap.bind.user=user distinguished name
We had also to customize LDAPUserGroupCallbackImpl to set the search scope to SubTree.
SearchControls constraints = new SearchControls(2, 0,0,null,false,false);
thanks for sharing this!
would be great if you could provide pull request for that extansion as it might be useful for others and thus including that in code base sounds reasonable. What do you think about making the search controls configurable as well? Not sure if making the subtree will be applicable for all the cases...