The set of changes made to a directory server is given by the set of all entries in the changelog, ordered by changeNumber, which strictly increases for a given server.

Note The changeNumber is unique to a server, and not necessarily shared or synchronized across servers. The change numbers for ForgeRock servers can be synchronized using the dsrepl reset-change-number command. ForgeRock servers also provide an alternative changeLogCookie attribute, which can be used reliably across a replicated topology.

A client application may synchronize its local copy of directory data by reading the server's changelog for entries where the changeNumber is greater than or equal to the last change that the client read from the server. A server can, however, trim its changelog. If the last change read from the changelog is not returned in search results, the client application must fall back to rebuilding its entire copy of directory data.

Origin draft-good-ldap-changelog
Usage userApplications
Description a number which uniquely identifies a change made to a directory entry
OID 2.16.840.1.113730.3.1.5
Substring Matching Rule caseExactSubstringsMatch
Equality Matching Rule integerMatch
Single Value true
Names changeNumber
Ordering Matching Rule integerOrderingMatch
User Modification Allowed true
Used By changeLogEntry
Schema File 03-changelog.ldif
Syntax Integer
Read a different version of :