On 6/6/19 5:30 PM, Quanah Gibson-Mount wrote:
Right, the primary issue is that if a server goes into REFRESH mode, the order in which the entries are sent back may not allow the slapo-memberOf overlay to rebuild the groups correctly. [..] I gave some examples in https://www.openldap.org/its/index.cgi/?findid=8613. But none of it is pretty.
Personally I still fail to see why attribute 'memberOf' receives this special treatment compared to e.g. 'modifyTimestamp' etc.
IMO it should be generated on the slapd replica which received the write operation from the client and just replicated like many other operational attributes.
Ciao, Michael.