Le 19/11/2012 16:42, Mauricio Tavares a écrit :
Then you need to ldapmodify each user, adding something like
objectClass: pwdPolicy
to each of them.
That's incorrect.
The pwdPolicy object is a container for defining a policy, not for marking another object as being subject to such a policy. You don't need to modify individual users objects, unless you want them to use another policy than the default one.