Wow, I never realized that Alfresco's LDAP implementation was so poor
Configuring somewhere something like "ldap.authentication.UserNameFormat" is clearly meaningless, at least from LDAP standpoint
1 - what is set here is DN and not username format
2 - hardcoding this would mean that
- ALL ldap entries are within same branch, using same RDN
- any change LDAP side in DIT will prevent to authenticate using Alfresco