Omit group referential integrity control

The Omit group referential integrity control explains its use with the server and provides the results.

Description
This control enables an administrator to request that group referential integrity must not be run. The control applies only to modrdn and delete operations. When present on a delete or rename operation, the entry is deleted from or renamed in the directory. But the entry membership is not removed or renamed in the groups in which the entry is a member.
Note: This control is always enabled.
OID
1.3.18.0.2.10.26
Syntax
This control has no value.
Behavior
This control is registered for the following operations:
  • Delete
  • Modrdn
The following persons are enabled to send the control:
  • Primary Directory Administrator
  • Local Administration Group members
  • Global Administration Group members
Note: If the control is sent by a user who does not have access, LDAP_INSUFFICIENT_ACCESS is returned.
This control has the following possible return codes:
  • LDAP_SUCCESS
  • LDAP_DECODING_ERROR
  • LDAP_UNWILLING_TO_PERFORM

The Administration Server does not support this control.

Scope
The control lasts for the term of one operation. The control is only recognized when a delete, moddn, or modrdn request goes to the RDBM back-end.
Auditing
When the server receives this control, the audit plug-in adds the following lines to the audit entry:
controlType: control ID
criticality: true | false