Rich Megginson wrote: > You need to enable global password policy. You need to set the > attribute "passwordIsGlobalPolicy" in cn=config to the value "1". Awesome, that works beautifully for what I need. Thanks for the reply. Of course, now comes the problem if a user fails their auth on a replica it isn't reflected in the master servers. I assume this is due to the inherent one-way master-to-replica replication. Having referrers doesn't seem to help. Is there a way around this, or is it a fact of life? --bryan