I am led to believe that editing /etc/ldap.conf and uncommenting the bind_policy line and changing it to: bind_policy soft solves this problem (with a sledge hammer). I will be trying it shortly after I've diagnosed another problem (in fact I found it while looking for clues to another problem), but be my guest and try it first, just let the list (and me) know how it works out :-) Cheers, Andrew -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users