Quoting Pierangelo Masarati ando@sys-net.it:
that slapo-ppolicy(5) enforces a single value for the password attribute, even though such constraint is not present in the specification of userPassword.
That was not the issue, the issue was that I was authenticated with my SASL (Krb5 key) _even though I did not have {SASL} in userPassword_.