https://bugs.openldap.org/show_bug.cgi?id=7788
--- Comment #3 from Ondřej Kuzník ondra@mistotebe.net --- Hi Clément, this should still be possible if you set a default policy with pwdMaxRecordedFailure == 0, is there a reason this would not be appropriate before we go changing the default behaviour?
Thanks, Ondrej