Hello Folks,
On my openldap server I was using shadowAccount to enforce password change for my users. It works, but it's not really secure. Users can reuse old passwors, etc.
So I had a look to ppolicy and appli this tutorial: http://theslashroot.blogspot.fr/2011/12/openldap-with-ppolicy.html
Some things are not clear for me. Did I have to disable shadowAccount on my schema?
If not is shadowLastChange will be updated?
I hope I need to include ppolicy schema on all my replica.
Thanks in advance for your help, Jacques Foucry