Specify the DN that the LDAP-SASL plugin search for groups where the authenticated user belongs. If specified DN in URI, this is a relative DN from that. Example: "ou=Groups,dc=example,dc=jp"