I suggest to allow substring searches for additional attributes (e.g. the domain name, logon script, ...). This allows users to run LDAP searches when they only know a part of the attribute value.
The attachment provides a patch for the samba.schema file.
Created attachment 5911 [details]
OpenLDAP schema patch
Reassigning to Günther for review.