El 1/4/19 a las 18:07, Michael Ströder escribió:
Note that semantics for 'pwdAccountLockedTime' are defined herein:
https://tools.ietf.org/html/draft-behera-ldap-password-policy
It does not mean what you want to achieve.
For Æ-DIR I defined custom meta attributes aeStatus, aeExpiryStatus, aeNotAfter etc.
I'm curious... how do you use these attributes to enforce the user doesn't authenticate outside of this range? Does openldap check it? Is responsibility of the application authenticating?