Restoring AuthLdap to previous search filter. Determined that the problem was
a missing o: attribute in the UCNRS LDAP directory. Adding it in makes the old
method work. The change I had made caused some confusion about authentication
because using just uid for a filter caused too many return dn's, and it was just
luck if the one we wanted came first. Adding o: back into the filter means
indirect DN lookups for orgs like PISCO and UCNRS work now.