https://bugs.openldap.org/show_bug.cgi?id=10169
--- Comment #1 from Ondřej Kuzník ondra@mistotebe.net --- Maybe the overlay could intercept a Compare against the oathH/TOTPToken but not sure we should react to a missing userPassword differently. Concerned some security would be compromised, people might be able to set an empty userpassword if they really want this? Might not be a good idea for SASL binds on the other hand so probably not.