On Thu, May 21, 2026 at 04:48:51AM +0000, Sebastian Perkins wrote:
Hello Ondřej
Thanks, we will go ahead on that road, the answer and consistency of the 2 dynamic attributes throughout openldap 2.4 / 2.6 in Debian 11, 12 and 13 is fine for us.
Just a last question before totally moving on...
From 2.6.14 onward, slapadd will skip dynamic attributes when processing entries given to it (ITS#10501), however you should still prefer slapcat for your ldif-based backups and mdb_copy -c for file based backups in general.
We also use the password policy which exports / imports fine, these are extended attributes but not dynamic ones and hence will be fine ?
So long as you use the ManageDSAiT control (ldapsearch -MM) when making the backup, the right attributes will be omitted (both right now and in 2.7 where ppolicy also populates pwdPolicySubentry based on the configured rules).
Regards,