Thomas Reith has written a superb utility, ldapdiff (https://launchpad.net/ldapdiff) for generating differential LDIF updates from a complete LDIF dump file and an LDAP server's
current contents. ldapdiff is smart enough to support a configuration file
which can specify what object types and attributes should be handled in the
diff comparison. ldapdiff looks like the perfect thing to enable management
of an LDAP server from an external master database, be it some relational
database schema, or something like Ganymede (http://www.arlut.utexas.edu/gash2/).
|