slapo-refint(5) — Linux manual page


SLAPO-REFINT(5)            File Formats Manual           SLAPO-REFINT(5)

NAME         top

       slapo-refint - Referential Integrity overlay to slapd

SYNOPSIS         top


DESCRIPTION         top

       The Referential Integrity overlay can be used with a backend
       database such as slapd-mdb(5) to maintain the cohesiveness of a
       schema which utilizes reference attributes.

       Integrity is maintained by updating database records which
       contain the named attributes to match the results of a modrdn or
       delete operation. For example, if the integrity attribute were
       configured as manager, deletion of the record
       "uid=robert,ou=people,dc=example,dc=com" would trigger a search
       for all other records which have a manager attribute containing
       that DN. Entries matching that search would have their manager
       attribute removed.  Or, renaming the same record into
       "uid=george,ou=people,dc=example,dc=com" would trigger a search
       for all other records which have a manager attribute containing
       that DN.  Entries matching that search would have their manager
       attribute deleted and replaced by the new DN.

       rootdn must be set for the database.  refint runs as the rootdn
       to gain access to make its updates.  rootpw is not needed.


       These slapd.conf options apply to the Referential Integrity
       overlay.  They should appear after the overlay directive.

       refint_attributes <attribute> [...]
              Specify one or more attributes for which integrity will be
              maintained as described above.

       refint_nothing <string>
              Specify an arbitrary value to be used as a placeholder
              when the last value would otherwise be deleted from an
              attribute. This can be useful in cases where the schema
              requires the existence of an attribute for which
              referential integrity is enforced. The attempted deletion
              of a required attribute will otherwise result in an Object
              Class Violation, causing the request to fail.  The string
              must be a valid DN.

       refint_modifiersname <DN>
              Specify the DN to be used as the modifiersName of the
              internal modifications performed by the overlay.  It
              defaults to "cn=Referential Integrity Overlay".

       Modifications performed by this overlay are not propagated during
       replication. This overlay must be configured identically on
       replication consumers in order to maintain full synchronization
       with the provider.

FILES         top

              default slapd configuration file

SEE ALSO         top

       slapd.conf(5), slapd-config(5).


       OpenLDAP Software is developed and maintained by The OpenLDAP
       Project <>.  OpenLDAP Software is derived
       from the University of Michigan LDAP 3.3 Release.

COLOPHON         top

       This page is part of the OpenLDAP (an open source implementation
       of the Lightweight Directory Access Protocol) project.
       Information about the project can be found at 
       ⟨⟩.  If you have a bug report for this
       manual page, see ⟨⟩.  This page was
       obtained from the project's upstream Git repository
       ⟨⟩ on 2023-12-22.
       (At that time, the date of the most recent commit that was found
       in the repository was 2023-12-19.)  If you discover any rendering
       problems in this HTML version of the page, or you believe there
       is a better or more up-to-date source for the page, or you have
       corrections or improvements to the information in this COLOPHON
       (which is not part of the original manual page), send a mail to

OpenLDAP LDVERSION             RELEASEDATE               SLAPO-REFINT(5)

Pages that refer to this page: slapd.overlays(5)