I'm quite aware they backport some bugs fixes. However, I'm also well
aware that I've never seen a member of the RedHat group who maintains the
OpenLDAP packages on the openldap-devel list or tracking the various CVS
commits that come in. Looking at the RedHat changelog for their OpenLDAP
package, shows a total of *2* fixes imported into their 2.2.13 release
from the 2.2 branch, one from 2.2.15, and one from 2.2.16. No
modifications or updates since that time. Given the many bug fixes by
the time 2.2.30 was released, their version is horribly out of date, and
has one or two DOS attacks present in it. I would hardly call that
"updating" their distribution.
sh-3.00# rpm -q --changelog openldap | more
* Tue Apr 19 2005 Nalin Dahyabhai <nalin@redhat.com> 2.2.13-3
- move nptl libraries into arch-specific subdirectories on %{ix86} boxes,
to match glibc's layout
- update notes on upgrading from previous releases
- pull in fix for ITS #3201 from 2.2.15
- pull in fix for ITS #3326 from 2.2.16