Hallvard B Furuseth h.b.furuseth@usit.uio.no wrote:
Remember that even if it were, OpenLDAP does not support indexing for such filters. So each search would have to inspect every IP-subnet entry in scope.
Even if indexing is not available, the feature would still be useful for ACL.
BTW, one point to keep in mind: What do IP ranges look like in IPv6?
Same look: address "/" prefix IPv6 addresses contain ":", prefixes are from 0 to 128 IPv4 addresses contain ".", prefixes are from 0 to 32.