> Anyway, I think I'd need to look at the internals of the plugin at this > point to work out for sure what's going on. > Looks like someone already did this. nsslapd-pluginAllowReplUpdates It looks like there is no documentation about how this config value works though: and the values it influences aren't widely through the code so I can't confirm if it's a finished feature. If you set this on the plugin, to "on" (I think it defaults to off), then on certain operations the integrity checks are bypassed on replicated operations. You can see this on line 726 of ds/ldap/servers/plugins/referint/referint.c Can someone confirm if how I'm interpreting this is correct, and if we should open a documentation bug to get this documented? -- William <william@xxxxxxxxxxxxxxx> -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users