Pierangelo Masarati wrote:
I think the groups should not even have been cached in the first place; lookups for auth purposes usually set op->o_nocaching.
Just to clear out: what's the difference between o_nocaching and o_do_not_cache? The latter seems more appropriate in this case, since in slap.h there's a comment that explicitly refers to group ACL caching.
p.
Ing. Pierangelo Masarati OpenLDAP Core Team
SysNet s.n.c. Via Dossi, 8 - 27100 Pavia - ITALIA http://www.sys-net.it ------------------------------------------ Office: +39.02.23998309 Mobile: +39.333.4963172 Email: pierangelo.masarati@sys-net.it ------------------------------------------