See also <http://www.openldap.org/lists/openldap-devel/200811/msg00000.html> and specifically <http://www.openldap.org/lists/openldap-devel/200811/msg00006.html> dontUseCopy needs to be fixed, but specific "disallow" flags could be added to alter per-RFC4511 behavior. p.