Trying to understand LDAP behavior

Hi people,

while I was somewhere in my dreams on some island I changed our LDAP configuration.
I wanted to add a group in LDAP-Filter where we have already a few. So last “line” was looking like this:
So there was a ‘cn=’ missing and it led to unusable behavior --> fpm ran on limit.
While I’m a LDAP noob but like to understand things: Can anybody explain what was happen? I can just guess…