auth ldap/ad: compare group member dn case-insensitively