> I regard AD as broken by design in this regard. My question is, can > this be fixed? What would be the right way to approach this problem? Yes it's broken by design. As far as I know the way to work around it is to assign unique CN's (e.g. include middle initials, something like that).