hi Quanah, 

Thanks for guiding me. 
I have figured it out. It is working now. 


On Sun, 16 Feb 2020 at 01:22, Quanah Gibson-Mount <quanah@symas.com> wrote:


--On Saturday, February 15, 2020 9:21 PM +0530 keerthi krishnan
<keerthikrishnan1369@gmail.com> wrote:

> Hi Quanah, 

> Now the user replmonitor has admin privilege, where it can list all cn
> ,. I have tried adding attrs=contextcsn , but no luck. Could you please
> guide me, how can i restrict this. 

contextcsn is an internally managed operational attribute, which means you
need to explicilty request it as a part of your search operation, or
request that all operational attrs be returned.  How are you testing
whether or not the bind DN has the ability to read the attribute?

Regards,
Quanah


--

Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
<http://www.symas.com>