Hello, Is there any way to have 389 DS automatically update the shadowLastChange attribute when the userPassword attribute is changed for an entry? I know that pam_ldap will attempt to update the shadowLastChange attribute, but this either requires that the user has the privileges to update this attribute. What I would like is for the server to update the attribute directly without having to grant extra privileges to the user. Is there any way to do this? Thanks -- Iain Morgan -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users