SUSE Support

Here When You Need Us

The createTimestamp and entryUUID of an LDAP group are seen to have changed

This document (7014302) is provided subject to the disclaimer at the end of this document.

Environment

SUSE Linux Enterprise Server 11 Service Pack 3

Situation

After creation of an LDAP (Lightweight Directory Access Protocol) group and looking at the attributes of that group using for example "slapcat -l", it is noticed that the "createTimestamp" and "entryUUID" have changed.

Resolution

The behaviour is expected; not creating empty LDAP groups will prevent this.

Cause

This only happens if a LDAP group is created without any users or if all users are removed from an existing LDAP group. Currently the LDAP group objectclass, "groupOfNames", does not allow creating LDAP groups without any members since "member" is a required attribute of "groupOfNames".

Additional Information

YaST works around the problem by creating empty groups with a different objectclass, "namedObject". When then adding a member or members to the LDAP group, the group is recreated with the proper "groupOfName" objectclass which is when the "createTimestamp" and "entryUUID" change.

The group is re-created due to the fact that the LDAP standards forbid changing the structural objectclass of an LDAP object.

Disclaimer

This Support Knowledgebase provides a valuable tool for SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:7014302
  • Creation Date: 17-Dec-2013
  • Modified Date:03-Mar-2020
    • SUSE Linux Enterprise Server

< Back to Support Search

For questions or concerns with the SUSE Knowledgebase please contact: tidfeedback[at]suse.com

SUSE Support Forums

Get your questions answered by experienced Sys Ops or interact with other SUSE community experts.

Support Resources

Learn how to get the most from the technical support you receive with your SUSE Subscription, Premium Support, Academic Program, or Partner Program.

Open an Incident

Open an incident with SUSE Technical Support, manage your subscriptions, download patches, or manage user access.