Using groups helps when apps want to get user info. In that there are ACI capability and also searchfilter, which makes it possible to control user login access. However if you use multiple application and each has its own method of authentication, there you face something that does not have searchfilter, or proxy account. Also there are application that only can Bind as user enters their credential and after that either they don't need other infos from Directory either the other info's are collected from another Data Store, like mysql,oracle, etc. -- All in all, I'm aware of such solution and already using it, but the problem I'm addressing is not that. I need to take control of Bind operation, based on IP, time, user's Attribute, .... which I could not find in 389ds. _______________________________________________ 389-users mailing list -- 389-users@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to 389-users-leave@xxxxxxxxxxxxxxxxxxxxxxx