I note there remains an inconsistency: if you request a specific operational attribute, it is not returned unless explicitly allowed by the mapping. However, if you request all operational attributes using "+", you get all.
This occurs because when returning search entries, operational attributes are ignored. I think that we should either:
- consistently ignore operational attributes when mapping; or
- treat them like other attributes.
The latter seems more appropriate to me, since mapping operational attributes could be useful when interacting with other implementations. In any case, the behavior should be consistent. It is up to system administrators to use it appropriately.
p.
Ing. Pierangelo Masarati OpenLDAP Core Team
SysNet s.r.l. via Dossi, 8 - 27100 Pavia - ITALIA http://www.sys-net.it ----------------------------------- Office: +39 02 23998309 Mobile: +39 333 4963172 Fax: +39 0382 476497 Email: ando@sys-net.it -----------------------------------