Migration from #LLDAP to #Kanidm didn't go as planned. Seems Kanidm is a rather shitty LDAP server, and being read-only is not the issue. You're able to query using 'cn', but cn is not among the results, as well as givenName, uid, or mail (there is actually a workaround to get that one).
1/2

