Hi, As Paul said, I think a ldif file containing the full schema and one or more ldif files containing updates from past versions of the schema could be shipped with every release of Kerberos. This would ease the installation and upgrade of the LDAP back end with OpenLDAP. Regards Yann