FYI, this has been resolved by adding ObjectClass"domain" to the "dc=xxxx,dc=xx" # ldapsearch -h ca-ldap01 -b "dc=redhats,dc=rs" -s sub "objectclass=nisdomainobject" version: 1 dn: dc=redhats,dc=rs nisDomain: redhats.rs objectClass: top objectClass: domain objectClass: nisdomainobject dc: redhats -- 389-users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx http://lists.fedoraproject.org/admin/lists/389-users@xxxxxxxxxxxxxxxxxxxxxxx