Hi All, I'm testing DS upgrade from 1.2.5 to 1.2.7.5 on RHEL 5 I'm getting a lot of new error messages in the 1.2.7.5 error log (default logging config). These errors do not appear on the 1.2.5 (default logging config as well) when doing an LDAP search and mod to a user on a certain tree: "NSACLPlugin - acllas__client_match_URL: url [ldap:///ou=something,o=the university of queensland,c=au??sub?(objectclass=*)] scope is subtree but dn [ou=something,o=the university of queensland,c=au] is not a suffix of [uid=modadmin,ou=privileged,o=the university of queensland,c=au]" It's saying that the tree that I am searching is not a suffix of the user DN I use to bind. It looks more like a warning because the operation completed successfully, located the user and modified the attributes. Is this just a new feature that can be turned off? Is there anything else I can do to disable these error messages? I've tried to adjust the error log level from the console as per the RedHat documentation for DS 8.2 but I couldn't find any functions to do so on config tab->error log. I have also added nsslapd-errorlog-level: 256 to the dse.ldif but it didn't do anything. Any help is much appreciated! Thanks, Baz -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users