CAUTION: This email originated from outside Planet. Do not click links or open attachments unless you recognise the sender and know the content is safe. Please report all suspicious emails by clicking on the report
message button in Outlook.
On Mon, May 04, 2026 at 08:56:37AM +0000, Sebastian Perkins wrote:
> That’s what we are currently doing, especially in our ldapsearch based
> backup.
>
> The goal of the thread is to understand what is going on.
Hi Sebastian,
the issue as Howard already said is that these are dynamic attributes
and not meant to be stored. slapcat-based backups (which you should
prefer if possible, given that's the only way to guarantee a consistent
view of the DB) will only return stored data. But `ldapsearch -MM`
backups will also return these and should therefore be stripped, since
slapadd stores what is given to it.
From 2.6.14 onward, slapadd will skip dynamic attributes when processing
entries given to it (ITS#10501), however you should still prefer slapcat
for your ldif-based backups and mdb_copy -c for file based backups in
general.
Regards,
--
Ondřej Kuzník
Senior Software Engineer
Symas Corporation
https://eur03.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.symas.com%2F&data=05%7C02%7CSebastian.Perkins%40hoistgroup.com%7Cae2b82dc6750427664f708deb4bea5b9%7Cb607882112c74949982752da66c836c7%7C0%7C0%7C639146928092070863%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=gqyZfP2yB76%2FKxgO0Va5ysQ6FsTqSLTwcr0mgryPRwQ%3D&reserved=0
Packaged, certified, and supported LDAP solutions powered by OpenLDAP