Restoring DB to alternate LDAP suffix

Jake Scott jake at poptart.org
Wed Jan 29 12:00:29 EST 2025


Hi there..

We are currently migrating data from an LDAP backend (MIT v1.18) to a new
suffix. We've dumped the data using kdb5_util and are attempting to restore
it using a new configuration with the updated suffix.

During the restore process, it appears that the principals are being added
back using their original DNs instead of under the new suffix. Is this
expected behavior? We were surprised to find the principal DNs included in
the dump file.

Any insight or advice would be much appreciated!


Thanks..

Jake


More information about the Kerberos mailing list