For whatever reason, James hasn’t moderated-in my comment on his Random Thoughts for 2009-01-18, so here it is in blog entry form…

For some reason, James has a bee in his bonnet over referential integrity and LDAP. I’m really not sure where he’s coming from here - both OpenDS and OpenLDAP offer referential integrity (OpenDS ref int doc, OpenLDAP ref int doc), and Sun Directory Server has offered it for years (Sun Directory Server ref int doc). Does this answer your question, James, or am I missing something?

By the way, if you’re wondering about the title of this post, it’s an allusion to the mighty Half Man Half Biscuit’s 1986 track Architecture and Morality, Ted & Alice, which itself was a play on the titles of Orchestral Manoeuvres in the Dark’s 1981 album Architecture & Morality and the 1969 movie Bob and Carol and Ted and Alice. If there was any justice in the world, there’d be a neat link back to the world of identity here, but there isn’t, so there’s not…



Paul Walker

Hey Pat, might be worth mentioning that the OpenDS ref int plugin isn't enabled by *default*.

By default, the referential integrity plug-in is disabled. When you enable the plug-in by using dsconfig, it performs integrity updates on the member,uniquemember attributes immediately after a delete, rename, or move operation. Whenever you delete, rename, or move a user or group entry in the directory, the operation is logged to the referential integrity log file install-dir/logs/referint.

