.TH SLAPO_PPOLICY 5 "RELEASEDATE" "OpenLDAP LDVERSION"
-.\" Copyright 2004-2015 The OpenLDAP Foundation All Rights Reserved.
+.\" Copyright 2004-2017 The OpenLDAP Foundation All Rights Reserved.
.\" Copying restrictions apply. See COPYRIGHT/LICENSE.
.\" $OpenLDAP$
.SH NAME
is performed with the
.B rootdn
identity; all the operations, when performed with any other identity,
-may be subjected to constraints, like access control.
+may be subjected to constraints, like access control. This overlay
+requires a rootdn to be configured on the database.
.P
Note that the IETF Password Policy proposal for LDAP makes sense
when considering a single-valued password attribute, while
pwdLockout $ pwdLockoutDuration $
pwdMaxFailure $ pwdFailureCountInterval $
pwdMustChange $ pwdAllowUserChange $
- pwdSafeModify 4 pwdMaxRecordedFailure ) )
+ pwdSafeModify $ pwdMaxRecordedFailure ) )
.RE
This implementation also provides an additional