Restoring DB to alternate LDAP suffix

Jake Scott <[email protected]> Wed, 29 Jan 2025 12:00:29 -0500
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <CAExmWcgam_XtE+32_weR_hrO1ZDb-irNpWCaP0QxA3_c9zfcyw@mail.gmail.com>
Hi there..

We are currently migrating data from an LDAP backend (MIT v1.18) to a new
suffix. We've dumped the data using kdb5_util and are attempting to restore
it using a new configuration with the updated suffix.

During the restore process, it appears that the principals are being added
back using their original DNs instead of under the new suffix. Is this
expected behavior? We were surprised to find the principal DNs included in
the dump file.

Any insight or advice would be much appreciated!


Thanks..

Jake
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos