As far as I know you can only set it by person. By adding the pwdPolicySubentry object to the person and have it's value equal the dn of the policy you want to enforce upon it. If it is possible by group, I'd like to know.
Adam
When ppolicy is set as default, it applies globally to the entire LDAP tree:
dn: cn=default,ou=policies,dc=zednax,dc=com
Is it possible to set the ppolicy by group?
Regards,
Andy