Hi Vinay, you could add an aci to deny "replication user" from doing "delete" operations on the whole replicated suffix. But note this aci will be by "user" and not by "host". If not, you could also restrict the aci by ip address of primary node to achieve exactly what you want to do. Regards, German. ----- Original Message ----- > From: "vinay garg" <vinay.garg@xxxxxxxxxxxxxxxxxx> > To: 389-users@xxxxxxxxxxxxxxxxxxxxxxx > Sent: Monday, August 10, 2015 10:57:07 AM > Subject: Restict master-master replication > > hi list, > > we have multi-master settup > 1. Primary master > 2. Secondary Master > > HOw can we apply restriction on Primary master that primary master can > replicaiton only modify, add on secondary master. But Primary master dont > have permission to delete replication data on secondary master. > > Any idea how to restrict From Primary Master to Secondary master > > -- > Regards > Vinay Garg > Keen & Able Comp. Pvt. ltd. > 9990770734 > > -- > 389 users mailing list > 389-users@xxxxxxxxxxxxxxxxxxxxxxx > https://admin.fedoraproject.org/mailman/listinfo/389-users -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users