Just wondering if this is caused by workstation import. On my DS servers with the LDAP trace turned on and dstrace running I am seeing workstations make an anonymous ldap bind and then request the "CanonicalName" attribute with a filter of their workstation name (not the NDS workstation object, just the name of the machine.)

I am guessing this is how it decides which workstation object it should create/update? Thanks.