On Wed, 23 May 2012 14:26:01 +0000, plummb wrote:

> When trying to rename any associated group in my vault, AD driver throws
> the following error:
> <ldap-err ldap-rc="65" ldap-rc-name="LDAP_OBJECT_CLASS_VIOLATION">
> <client-err ldap-rc="65"
> ldap-rc-name="LDAP_OBJECT_CLASS_VIOLATION">Object Class
> Violation</client-err>
> <server-err>00002014: UpdErr: DSID-031A11DA, problem 6002
> </server-err>
> <server-err-ex win32-rc="8212"/>
> </ldap-err>

The error is interesting, but without a level 3 (engine) trace showing
what led up to the error, there's not much we can tell you about it.

> I have tried removing attribute: L from the filter, as described here:
> 'Support | LDAP_OBJECT_CLASS_VIOLATION when syncing L attribute on a
> Group' (http://www.novell.com/support/kb/doc.php?id=3440949) but it did
> not help - same error

I'm not seeing how having "L' in the filter, or not, is going to affect
a rename. So, let's see the trace (use pastebin.com) of the event, all
rules processing the event, and the eventual document submitted to the

