Somehow this one has a child?
# ipa-replica-manage del
ld4ipa1.xyz.com --force --cleanup
Updating DNS system records
Not allowed on non-leaf entry
# ldapdelete -x -D 'cn=directory manager' -W
'cn=ld4ipa1.xyz.com,cn=masters,cn=ipa,cn=etc,dc=xyz,dc=com'
Enter LDAP Password:
ldap_delete: Operation not allowed on non-leaf (66)
additional info: Entry has replication conflicts as children