> I'm now working on scripting an AD-to-MySQL synchronization tool.

We've been using a custom tool for this internally for the last couple of
months to be able to manage connection permissions on a group level. We were
hoping to be able to ditch that in favor of official LDAP group support but
it looks like I'll be updating our tool to support the new database
structure instead...
I'll open an issue for this. At first I wasn't sure whether this was a
problem with our specific setup so I took to the mailing list but it looks
like we're not alone.

I think it's probably already covered under this issue: