Hi,
just an unfinished thought, but one important point seems to be that it's not easily possible to compare the current configuration state when using back-config with a defined config state stored in a configuration. Shouldn't ldapdiff (https://launchpad.net/ldapdiff) be able to do this (compare the state of cn=config with a known config state managed in a central repository)?
Yours Karsten