Aaron Richton wrote:
- The consumer LDAP automaticly becomes readonly, when "syncrepl" is set
in it's config. Is it possible to have a consumer (slave) LDAP, which is not readonly?
This isn't readily achievable.
No, but the chain overlay can be used to huge advantage to simulate this and I thank heaven that this has been implemented in the stable 2.3 tree. We have a 2.3 LDAP slave Samba server on which all shell/Perl scripts have to run to make sure that the Windows domain SIDs are correct; without the chain overlay chasing referrals to the master life would be much harder.
[...]
--Tonni