And neither do I ;-)
First thing is to get a support case out of the door - that enables our support people to look at your logs and data.
I would check if something went wrong in the ldap schema - then I would traverse through the service profile and account settings under ou=itim to see if there is some hint there....
HTH
------------------------------
Franz Wolfhagen
WW IAM Solution Engineer - Certified Consulting IT Specialist
IBM Security Expert Labs
------------------------------