Andy Loughran wrote:
Gavin,
Ah, so that would suggest that adding a:
pwdPolicySubentry: cn: lesser,ou=ppolicy,dc=example,dc=com
to users of a specific group would allow the entire group to be managed by that particular policy.
"Every account that should be subject to password policy control should have a pwdPolicySubentry attribute containing the DN of a valid pwdPolicy entry, or they can simply use the configured default. In this way different users may be managed according to different policies."
That's what it says ;-)