https://bugs.openldap.org/show_bug.cgi?id=9671
--- Comment #7 from Ondřej Kuzník ondra@mistotebe.net --- On Wed, Sep 08, 2021 at 10:09:10AM +0000, openldap-its@openldap.org wrote:
Additionally you should ask yourself:
Does adding NO-USER-MODIFICATION solve any real-world problem?
IMO the answer is clearly no.
There is an argument that it signals to the requester "you are messing with password policy internal state". For pwdHistory, that is definitely the right way to go, for pwdPolicySubentry, maybe not just yet.