> For my dn I was using cn=John Smith, o=Mycompany, c=UK which is simple but
> prevents you having two "John Smith"s. So - I've changed to using a numeric
> id number. 

The standard schema for persons use the "uid" attribute, which is like
an Unix login name, an abreviated unique name (it is not Unix' numeric


> Secondly, am I right in thinking there's no way to lock an entry to provide
> atomic updates?

Right. LDAP != DBMS