r8667: Further simply the provision script, by removing the 'name' attribute.
[kai/samba.git] / source / setup / provision.ldif
index ca0c7f9051192635604d42d9b6ef1e95ab65f525..c42c73eda4cedd4d09efef381036fbf645749a6b 100644 (file)
@@ -1,52 +1,3 @@
-dn: @INDEXLIST
-@IDXATTR: name
-@IDXATTR: sAMAccountName
-@IDXATTR: objectSid
-@IDXATTR: objectClass
-@IDXATTR: member
-@IDXATTR: unixID
-@IDXATTR: unixName
-@IDXATTR: privilege
-
-dn: @ATTRIBUTES
-realm: CASE_INSENSITIVE
-userPrincipalName: CASE_INSENSITIVE
-servicePrincipalName: CASE_INSENSITIVE
-dnsDomain: CASE_INSENSITIVE
-cn: CASE_INSENSITIVE
-dc: CASE_INSENSITIVE
-name: CASE_INSENSITIVE
-name: WILDCARD
-dn: CASE_INSENSITIVE
-dn: WILDCARD
-sAMAccountName: CASE_INSENSITIVE
-sAMAccountName: WILDCARD
-objectClass: CASE_INSENSITIVE
-unicodePwd: HIDDEN
-ntPwdHash: HIDDEN
-ntPwdHistory: HIDDEN
-lmPwdHash: HIDDEN
-lmPwdHistory: HIDDEN
-createTimestamp: HIDDEN
-modifyTimestamp: HIDDEN
-
-dn: @SUBCLASSES
-top: domain
-top: person
-top: group
-domain: domainDNS
-domain: builtinDomain
-person: organizationalPerson
-organizationalPerson: user
-user: computer
-template: userTemplate
-template: groupTemplate
-
-#Add modules to the list to activate them by default
-#beware often order is important
-dn: @MODULES
-@LIST: samldb,timestamps
-
 ###############################
 # Domain Naming Context
 ###############################
@@ -54,9 +5,7 @@ dn: ${BASEDN}
 objectClass: top
 objectClass: domain
 objectClass: domainDNS
-name: ${DOMAIN}
 flatname: ${DOMAIN}
-realm: ${REALM}
 dnsDomain: ${DNSDOMAIN}
 dc: ${DOMAIN}
 objectGUID: ${DOMAINGUID}
@@ -65,8 +14,6 @@ forceLogoff: 0x8000000000000000
 lockoutDuration: -18000000000
 lockOutObservationWindow: -18000000000
 lockoutThreshold: 0
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 maxPwdAge: -37108517437440
@@ -87,6 +34,7 @@ objectCategory: CN=Domain-DNS,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 subRefs: CN=Configuration,${BASEDN}
 subRefs: CN=Schema,CN=Configuration,${BASEDN}
+canonicalName: ${REALM}/
 
 dn: CN=Users,${BASEDN}
 objectClass: top
@@ -94,13 +42,9 @@ objectClass: container
 cn: Users
 description: Default container for upgraded user accounts
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: FALSE
-name: Users
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -111,13 +55,9 @@ objectClass: container
 cn: Computers
 description: Default container for upgraded computer accounts
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: FALSE
-name: Computers
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -128,13 +68,9 @@ objectClass: organizationalUnit
 ou: Domain Controllers
 description: Default container for domain controllers
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: FALSE
-name: Domain Controllers
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=Organizational-Unit,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -145,13 +81,9 @@ objectClass: container
 cn: ForeignSecurityPrincipals
 description: Default container for security identifiers (SIDs) associated with objects from external, trusted domains
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: FALSE
-name: ForeignSecurityPrincipals
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -162,13 +94,9 @@ objectClass: container
 cn: System
 description: Builtin system settings
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: TRUE
-name: System
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -178,13 +106,9 @@ objectclass: top
 objectclass: rIDManager
 cn: RID Manager$
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: TRUE
-name: RID Manager$
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=RID-Manager,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -196,13 +120,9 @@ objectClass: top
 objectClass: container
 cn: DomainUpdates
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: TRUE
-name: DomainUpdates
-objectGUID: ${NEWGUID}
 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
 
 dn: CN=Windows2003Update,CN=DomainUpdates,CN=System,${BASEDN}
@@ -210,13 +130,9 @@ objectClass: top
 objectClass: container
 cn: Windows2003Update
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: TRUE
-name: Windows2003Update
-objectGUID: ${NEWGUID}
 objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
 revision: 8
 
@@ -225,13 +141,9 @@ objectclass: top
 objectclass: infrastructureUpdate
 cn: Infrastructure
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: TRUE
-name: Infrastructure
-objectGUID: ${NEWGUID}
 systemFlags: 0x8c000000
 objectCategory: CN=Infrastructure-Update,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
@@ -243,7 +155,6 @@ objectClass: builtinDomain
 cn: Builtin
 instanceType: 4
 showInAdvancedViewOnly: FALSE
-name: Builtin
 forceLogoff: 0x8000000000000000
 lockoutDuration: -18000000000
 lockOutObservationWindow: -18000000000
@@ -269,9 +180,6 @@ objectClass: organizationalPerson
 objectClass: user
 cn: Administrator
 description: Built-in account for administering the computer/domain
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 memberOf: CN=Group Policy Creator Owners,CN=Users,${BASEDN}
 memberOf: CN=Domain Admins,CN=Users,${BASEDN}
@@ -279,27 +187,14 @@ memberOf: CN=Enterprise Admins,CN=Users,${BASEDN}
 memberOf: CN=Schema Admins,CN=Users,${BASEDN}
 memberOf: CN=Administrators,CN=Builtin,${BASEDN}
 uSNChanged: 1
-name: Administrator
-objectGUID: ${NEWGUID}
 userAccountControl: 0x10200
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
-pwdLastSet: 0
-primaryGroupID: 513
 objectSid: ${DOMAINSID}-500
 adminCount: 1
 accountExpires: -1
-logonCount: 0
 sAMAccountName: Administrator
-sAMAccountType: 0x30000000
-objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 unicodePwd: ${ADMINPASS}
-unixName: root
+unixName: ${ROOT}
 
 dn: CN=Guest,CN=Users,${BASEDN}
 objectClass: top
@@ -308,29 +203,13 @@ objectClass: organizationalPerson
 objectClass: user
 cn: Guest
 description: Built-in account for guest access to the computer/domain
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 memberOf: CN=Guests,CN=Builtin,${BASEDN}
 uSNChanged: 1
-name: Guest
-objectGUID: ${NEWGUID}
 userAccountControl: 0x10222
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
-pwdLastSet: 0
 primaryGroupID: 514
 objectSid: ${DOMAINSID}-501
-accountExpires: -1
-logonCount: 0
 sAMAccountName: Guest
-sAMAccountType: 0x30000000
-objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 
 dn: CN=Administrators,CN=Builtin,${BASEDN}
@@ -341,13 +220,8 @@ description: Administrators have complete and unrestricted access to the compute
 member: CN=Domain Admins,CN=Users,${BASEDN}
 member: CN=Enterprise Admins,CN=Users,${BASEDN}
 member: CN=Administrator,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Administrators
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-544
 adminCount: 1
 sAMAccountName: Administrators
@@ -389,13 +263,8 @@ objectClass: group
 cn: Users
 description: Users are prevented from making accidental or intentional system-wide changes.  Thus, Users can run certified applications, but not most legacy applications
 member: CN=Domain Users,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Users
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-545
 sAMAccountName: Users
 sAMAccountType: 0x20000000
@@ -411,13 +280,8 @@ cn: Guests
 description: Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
 member: CN=Domain Guests,CN=Users,${BASEDN}
 member: CN=Guest,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Guests
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-546
 sAMAccountName: Guests
 sAMAccountType: 0x20000000
@@ -432,13 +296,8 @@ objectClass: top
 objectClass: group
 cn: Print Operators
 description: Members can administer domain printers
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Print Operators
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-550
 adminCount: 1
 sAMAccountName: Print Operators
@@ -456,13 +315,8 @@ objectClass: top
 objectClass: group
 cn: Backup Operators
 description: Backup Operators can override security restrictions for the sole purpose of backing up or restoring files
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Backup Operators
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-551
 adminCount: 1
 sAMAccountName: Backup Operators
@@ -481,13 +335,8 @@ objectClass: top
 objectClass: group
 cn: Replicator
 description: Supports file replication in a domain
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Replicator
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-552
 adminCount: 1
 sAMAccountName: Replicator
@@ -502,13 +351,8 @@ objectClass: top
 objectClass: group
 cn: Remote Desktop Users
 description: Members in this group are granted the right to logon remotely
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Remote Desktop Users
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-555
 sAMAccountName: Remote Desktop Users
 sAMAccountType: 0x20000000
@@ -522,13 +366,8 @@ objectClass: top
 objectClass: group
 cn: Network Configuration Operators
 description: Members in this group can have some administrative privileges to manage configuration of networking features
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Network Configuration Operators
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-556
 sAMAccountName: Network Configuration Operators
 sAMAccountType: 0x20000000
@@ -542,13 +381,8 @@ objectClass: top
 objectClass: group
 cn: Performance Monitor Users
 description: Members of this group have remote access to monitor this computer
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Performance Monitor Users
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-558
 sAMAccountName: Performance Monitor Users
 sAMAccountType: 0x20000000
@@ -562,13 +396,8 @@ objectClass: top
 objectClass: group
 cn: Performance Log Users
 description: Members of this group have remote access to schedule logging of performance counters on this computer
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Performance Log Users
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-559
 sAMAccountName: Performance Log Users
 sAMAccountType: 0x20000000
@@ -581,43 +410,28 @@ dn: CN=${NETBIOSNAME},OU=Domain Controllers,${BASEDN}
 objectClass: top
 objectClass: person
 objectClass: organizationalPerson
-objectClass: user
 objectClass: computer
 cn: ${NETBIOSNAME}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: ${NETBIOSNAME}
 objectGUID: ${HOSTGUID}
 userAccountControl: 532480
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
 lastLogon: 127273269057298624
 localPolicyFlags: 0
 pwdLastSet: 127258826171655328
 primaryGroupID: 516
 objectSid: ${DOMAINSID}-1000
 accountExpires: 9223372036854775807
-logonCount: 30
 sAMAccountName: ${NETBIOSNAME}$
 sAMAccountType: 805306369
 operatingSystem: Samba
 operatingSystemVersion: 4.0
 dNSHostName: ${DNSNAME}
-objectCategory: CN=Computer,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
-unicodePwd: ${JOINPASS}
+unicodePwd: ${MACHINEPASS}
 servicePrincipalName: HOST/${DNSNAME}
 servicePrincipalName: HOST/${NETBIOSNAME}
-servicePrincipalName: CIFS/${DNSNAME}
-servicePrincipalName: CIFS/${NETBIOSNAME}
-servicePrincipalName: LDAP/${DNSNAME}
-servicePrincipalName: LDAP/${NETBIOSNAME}
+msDS-KeyVersionNumber: 1
 
 dn: CN=krbtgt,CN=Users,${BASEDN}
 objectClass: top
@@ -626,50 +440,29 @@ objectClass: organizationalPerson
 objectClass: user
 cn: krbtgt
 description: Key Distribution Center Service Account
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
 showInAdvancedViewOnly: TRUE
-name: krbtgt
-objectGUID: ${NEWGUID}
 userAccountControl: 514
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
 pwdLastSet: 127258826179466560
-primaryGroupID: 513
 objectSid: ${DOMAINSID}-502
 adminCount: 1
 accountExpires: 9223372036854775807
-logonCount: 0
 sAMAccountName: krbtgt
 sAMAccountType: 805306368
 servicePrincipalName: kadmin/changepw
-objectCategory: CN=Person,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
-unicodePwd: ${RANDPASS}
+unicodePwd: ${KRBTGTPASS}
 
 dn: CN=Domain Computers,CN=Users,${BASEDN}
 objectClass: top
 objectClass: group
 cn: Domain Computers
 description: All workstations and servers joined to the domain
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Domain Computers
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-515
 sAMAccountName: Domain Computers
-sAMAccountType: 0x10000000
-groupType: 0x80000002
 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 
@@ -678,19 +471,11 @@ objectClass: top
 objectClass: group
 cn: Domain Controllers
 description: All domain controllers in the domain
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Domain Controllers
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-516
 adminCount: 1
 sAMAccountName: Domain Controllers
-sAMAccountType: 0x10000000
-groupType: 0x80000002
-objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 
 dn: CN=Schema Admins,CN=Users,${BASEDN}
@@ -699,19 +484,11 @@ objectClass: group
 cn: Schema Admins
 description: Designated administrators of the schema
 member: CN=Administrator,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Schema Admins
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-518
 adminCount: 1
 sAMAccountName: Schema Admins
-sAMAccountType: 0x10000000
-groupType: 0x80000002
-objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 unixName: ${WHEEL}
 
@@ -721,20 +498,12 @@ objectClass: group
 cn: Enterprise Admins
 description: Designated administrators of the enterprise
 member: CN=Administrator,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 memberOf: CN=Administrators,CN=Builtin,${BASEDN}
 uSNChanged: 1
-name: Enterprise Admins
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-519
 adminCount: 1
 sAMAccountName: Enterprise Admins
-sAMAccountType: 0x10000000
-groupType: 0x80000002
-objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 unixName: ${WHEEL}
 
@@ -743,17 +512,12 @@ objectClass: top
 objectClass: group
 cn: Cert Publishers
 description: Members of this group are permitted to publish certificates to the Active Directory
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Cert Publishers
-objectGUID: ${NEWGUID}
+groupType: 0x80000004
+sAMAccountType: 0x20000000
 objectSid: ${DOMAINSID}-517
 sAMAccountName: Cert Publishers
-sAMAccountType: 0x20000000
-groupType: 0x80000004
 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 
@@ -763,20 +527,12 @@ objectClass: group
 cn: Domain Admins
 description: Designated administrators of the domain
 member: CN=Administrator,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 memberOf: CN=Administrators,CN=Builtin,${BASEDN}
 uSNChanged: 1
-name: Domain Admins
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-512
 adminCount: 1
 sAMAccountName: Domain Admins
-sAMAccountType: 0x10000000
-groupType: 0x80000002
-objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 unixName: ${WHEEL}
 
@@ -785,19 +541,11 @@ objectClass: top
 objectClass: group
 cn: Domain Users
 description: All domain users
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 memberOf: CN=Users,CN=Builtin,${BASEDN}
 uSNChanged: 1
-name: Domain Users
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-513
 sAMAccountName: Domain Users
-sAMAccountType: 0x10000000
-groupType: 0x80000002
-objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 unixName: ${USERS}
 
@@ -806,19 +554,11 @@ objectClass: top
 objectClass: group
 cn: Domain Guests
 description: All domain guests
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 memberOf: CN=Guests,CN=Builtin,${BASEDN}
 uSNChanged: 1
-name: Domain Guests
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-514
 sAMAccountName: Domain Guests
-sAMAccountType: 0x10000000
-groupType: 0x80000002
-objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 
 dn: CN=Group Policy Creator Owners,CN=Users,${BASEDN}
@@ -827,17 +567,10 @@ objectClass: group
 cn: Group Policy Creator Owners
 description: Members in this group can modify group policy for the domain
 member: CN=Administrator,CN=Users,${BASEDN}
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Group Policy Creator Owners
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-520
 sAMAccountName: Group Policy Creator Owners
-sAMAccountType: 0x10000000
-groupType: 0x80000002
 objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 unixName: ${WHEEL}
@@ -848,12 +581,8 @@ objectClass: group
 cn: RAS and IAS Servers
 description: Servers in this group can access remote access properties of users
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: RAS and IAS Servers
-objectGUID: ${NEWGUID}
 objectSid: ${DOMAINSID}-553
 sAMAccountName: RAS and IAS Servers
 sAMAccountType: 0x20000000
@@ -867,12 +596,8 @@ objectClass: group
 cn: Server Operators
 description: Members can administer domain servers
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Server Operators
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-549
 adminCount: 1
 sAMAccountName: Server Operators
@@ -894,12 +619,8 @@ objectClass: group
 cn: Account Operators
 description: Members can administer domain user and group accounts
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: 1
 uSNChanged: 1
-name: Account Operators
-objectGUID: ${NEWGUID}
 objectSid: S-1-5-32-548
 adminCount: 1
 sAMAccountName: Account Operators
@@ -910,155 +631,6 @@ objectCategory: CN=Group,CN=Schema,CN=Configuration,${BASEDN}
 isCriticalSystemObject: TRUE
 privilege: SeInteractiveLogonRight
 
-dn: CN=Templates,${BASEDN}
-objectClass: top
-objectClass: container
-cn: Templates
-description: Container for SAM account templates
-instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
-uSNCreated: 1
-uSNChanged: 1
-showInAdvancedViewOnly: TRUE
-name: Templates
-objectGUID: ${NEWGUID}
-systemFlags: 0x8c000000
-objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
-isCriticalSystemObject: TRUE
-
-###
-# note! the template users must not match normal searches. Be careful
-# with what classes you put them in
-###
-
-dn: CN=TemplateUser,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: person
-objectClass: organizationalPerson
-objectClass: Template
-objectClass: userTemplate
-cn: TemplateUser
-name: TemplateUser
-instanceType: 4
-userAccountControl: 0x202
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
-pwdLastSet: 0
-primaryGroupID: 513
-accountExpires: -1
-logonCount: 0
-sAMAccountType: 0x30000000
-
-dn: CN=TemplateMemberServer,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: Template
-objectClass: userTemplate
-cn: TemplateMemberServer
-name: TemplateMemberServer
-instanceType: 4
-userAccountControl: 0x1002
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
-pwdLastSet: 0
-primaryGroupID: 513
-accountExpires: -1
-logonCount: 0
-sAMAccountType: 0x30000001
-
-dn: CN=TemplateDomainController,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: Template
-objectClass: userTemplate
-cn: TemplateDomainController
-name: TemplateDomainController
-instanceType: 4
-userAccountControl: 0x2002
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
-pwdLastSet: 0
-primaryGroupID: 513
-accountExpires: -1
-logonCount: 0
-sAMAccountType: 0x30000001
-
-dn: CN=TemplateTrustingDomain,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: Template
-objectClass: userTemplate
-cn: TemplateTrustingDomain
-name: TemplateTrustingDomain
-instanceType: 4
-userAccountControl: 0x820
-badPwdCount: 0
-codePage: 0
-countryCode: 0
-badPasswordTime: 0
-lastLogoff: 0
-lastLogon: 0
-pwdLastSet: 0
-primaryGroupID: 513
-accountExpires: -1
-logonCount: 0
-sAMAccountType: 0x30000002
-
-dn: CN=TemplateGroup,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: Template
-objectClass: groupTemplate
-cn: TemplateGroup
-name: TemplateGroup
-instanceType: 4
-groupType: 0x80000002
-sAMAccountType: 0x10000000
-
-dn: CN=TemplateAlias,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: Template
-objectClass: aliasTemplate
-cn: TemplateAlias
-name: TemplateAlias
-instanceType: 4
-groupType: 0x80000004
-sAMAccountType: 0x10000000
-
-dn: CN=TemplateForeignSecurityPrincipal,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: Template
-objectClass: foreignSecurityPrincipalTemplate
-cn: TemplateForeignSecurityPrincipal
-name: TemplateForeignSecurityPrincipal
-
-dn: CN=TemplateSecret,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: leaf
-objectClass: Template
-objectClass: secretTemplate
-cn: TemplateSecret
-name: TemplateSecret
-instanceType: 4
-
-dn: CN=TemplateTrustedDomain,CN=Templates,${BASEDN}
-objectClass: top
-objectClass: leaf
-objectClass: Template
-objectClass: trustedDomainTemplate
-cn: TemplateTrustedDomain
-name: TemplateTrustedDomain
-instanceType: 4
-
 ###############################
 # Configuration Naming Context
 ###############################
@@ -1067,13 +639,9 @@ objectClass: top
 objectClass: configuration
 cn: Configuration
 instanceType: 13
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Configuration
-objectGUID: ${NEWGUID}
 objectCategory: CN=Configuration,CN=Schema,CN=Configuration,${BASEDN}
 subRefs: CN=Schema,CN=Configuration,${BASEDN}
 masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
@@ -1084,13 +652,9 @@ objectClass: top
 objectClass: crossRefContainer
 cn: Partitions
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Partitions
-objectGUID: ${NEWGUID}
 systemFlags: 0x80000000
 objectCategory: CN=Cross-Ref-Container,CN=Schema,CN=Configuration,${BASEDN}
 msDS-Behavior-Version: 0
@@ -1101,13 +665,9 @@ objectClass: top
 objectClass: crossRef
 cn: Enterprise Configuration
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Enterprise Configuration
-objectGUID: ${NEWGUID}
 systemFlags: 0x00000001
 objectCategory: CN=Cross-Ref,CN=Schema,CN=Configuration,${BASEDN}
 nCName: CN=Configuration,${BASEDN}
@@ -1118,13 +678,9 @@ objectClass: top
 objectClass: crossRef
 cn: Enterprise Schema
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Enterprise Schema
-objectGUID: ${NEWGUID}
 systemFlags: 0x00000001
 objectCategory: CN=Cross-Ref,CN=Schema,CN=Configuration,${BASEDN}
 nCName: CN=Schema,CN=Configuration,${BASEDN}
@@ -1135,13 +691,9 @@ objectClass: top
 objectClass: crossRef
 cn: ${DOMAIN}
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: ${DOMAIN}
-objectGUID: ${NEWGUID}
 systemFlags: 0x00000003
 objectCategory: CN=Cross-Ref,CN=Schema,CN=Configuration,${BASEDN}
 nCName: ${BASEDN}
@@ -1153,13 +705,9 @@ objectClass: top
 objectClass: sitesContainer
 cn: Sites
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Sites
-objectGUID: ${NEWGUID}
 systemFlags: 0x82000000
 objectCategory: CN=Sites-Container,CN=Schema,CN=Configuration,${BASEDN}
 
@@ -1168,13 +716,9 @@ objectClass: top
 objectClass: site
 cn: Sites
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Sites
-objectGUID: ${NEWGUID}
 systemFlags: 0x82000000
 objectCategory: CN=Site,CN=Schema,CN=Configuration,${BASEDN}
 
@@ -1183,13 +727,9 @@ objectClass: top
 objectClass: serversContainer
 cn: Servers
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Servers
-objectGUID: ${NEWGUID}
 systemFlags: 0x82000000
 objectCategory: CN=Servers-Container,CN=Schema,CN=Configuration,${BASEDN}
 
@@ -1198,13 +738,9 @@ objectClass: top
 objectClass: server
 cn: ${NETBIOSNAME}
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: ${NETBIOSNAME}
-objectGUID: ${NEWGUID}
 systemFlags: 0x52000000
 objectCategory: CN=Server,CN=Schema,CN=Configuration,${BASEDN}
 dNSHostName: ${DNSNAME}
@@ -1216,12 +752,9 @@ objectClass: applicationSettings
 objectClass: nTDSDSA
 cn: NTDS Settings
 instanceType: 4
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: NTDS Settings
 systemFlags: 0x02000000
 objectCategory: CN=NTDS-DSA,CN=Schema,CN=Configuration,${BASEDN}
 dMDLocation: CN=Schema,CN=Configuration,${BASEDN}
@@ -1229,6 +762,39 @@ objectGUID: ${INVOCATIONID}
 invocationId: ${INVOCATIONID}
 msDS-Behavior-Version: 2
 
+dn: CN=Services,CN=Configuration,${BASEDN}
+objectClass: top
+objectClass: container
+cn: Services
+instanceType: 4
+uSNCreated: ${USN}
+uSNChanged: ${USN}
+showInAdvancedViewOnly: TRUE
+systemFlags: 0x80000000
+objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
+
+dn: CN=Windows NT,CN=Services,CN=Configuration,${BASEDN}
+objectClass: top
+objectClass: container
+cn: Windows NT
+instanceType: 4
+uSNCreated: ${USN}
+uSNChanged: ${USN}
+showInAdvancedViewOnly: TRUE
+objectCategory: CN=Container,CN=Schema,CN=Configuration,${BASEDN}
+
+dn: CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,${BASEDN}
+objectClass: top
+objectClass: nTDSService
+cn: Directory Service
+instanceType: 4
+uSNCreated: ${USN}
+uSNChanged: ${USN}
+showInAdvancedViewOnly: TRUE
+objectCategory: CN=NTDS-Service,CN=Schema,CN=Configuration,${BASEDN}
+sPNMappings: host=ldap,dns,cifs
+
+
 ###############################
 # Schema Naming Context
 ###############################
@@ -1237,13 +803,9 @@ objectClass: top
 objectClass: dMD
 cn: Schema
 instanceType: 13
-whenCreated: ${LDAPTIME}
-whenChanged: ${LDAPTIME}
 uSNCreated: ${USN}
 uSNChanged: ${USN}
 showInAdvancedViewOnly: TRUE
-name: Schema
-objectGUID: ${NEWGUID}
 objectCategory: CN=DMD,CN=Schema,CN=Configuration,${BASEDN}
 masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}
 msDs-masteredBy: CN=NTDS Settings,CN=${NETBIOSNAME},CN=Servers,CN=${DEFAULTSITE},CN=Sites,CN=Configuration,${BASEDN}