Thus, my original question stands: Is there a way, within OpenLDAP to extract info from an ADS?
Unknown, but if you look at recent messages on this list regarding AD you will see that there are some limitations to what you can get from AD -
You may be able to use an OpenLDAP backend to read data from AD on a request-by-request basis, or use a referral to you AD server.
back-ldap and back-meta comes to mind.
Does anyone know if there is any OpenLDAP-based "pull-type" synchronization component?
Ciao, Michael.