Oh. Answering my own question: The "missing" entry had turned into a glue entry, don't know how. I can modify it with "ldapmodify ... -M ..." (or maybe -MM), to turn it into a regular entry and make dotnet default auth work. Thanks for your time :-]
If you are using standard syncrepl for replication, this can happen when the system goes into REFERSH mode IIRC. It generally means a child entry was replicated before the parent was replicated.
--Quanah -- Quanah Gibson-Mount Product Architect Symas Corporation Packaged, certified, and supported LDAP solutions powered by OpenLDAP: <http://www.symas.com>