If a user changes passwords on and ldap client machine, the shadow entry disappears. This is true for all hash methods except for {CRYPT}. Clearly I would like {SSHA} or {MD5} over {CRYPT}. The client machines are pretty standard RHEL 5 machines. I have exop in the config on the client. Setting the password on the LDAP server works correctly. Running the server in debug didn't make anything jump out at me. Anyone have any ideas? Perhaps I'm missing an ACL I don't know about.
Matt