Then, it's probably a bug in Mahara. Those settings should be disabled to be compatible with SME's LDAP schema. Especially the "Member's attribute is a DN". With this enabled, there's no way group membership will work, because mahara would search full user's DN in memberUid attribute, while it's just plain user uid.