On 14/07/17 20:57, Josh Catana wrote:
Nice replica:-) I don't see how indexing aliasedObjectName could help.
If you have a deep structure with something like uid=username,ou=foo,ou=bar,ou=baz,dc=example,dc=com switch to a flat uid=username,cn=people,dc=example,dc=com where each person has a membership attribute or something similar which says where he belongs. See e.g. attribute eduPersonOrgUnitDN in the eduPerson schema: http://software.internet2.edu/eduperson/internet2-mace-dir-eduperson-201602.html#eduPersonOrgUnitDN If that's not feasible, go with with data duplication: Keep a single "master" copy of each user somewhere - in an LDAP server or somewhere else - and generate his other LDAP entries from that. |