Migrate to using Rover groups for LDAP group membership verification
This means that we query for the specific user and get the memberOf
attribute instead of filtering by memberUid on the groups. This means
that we can't safely use the common names of the group since it is not
unique. This is because the groups are not filtered to a specific LDAP
base DN since we are querying for the user.