RE: sasl authz "dn:" type normalization (ITS#2852)

> When dealing with saslAuthz{To|From} attribute values,
> in some cases the "dn:" type doesn't pass normalization
> because of regex special chars.  This patch introduces
> a new type of saslAuthz* string, "regex:", which desn't
> undergo normalization before being compiled in regcomp().

Is this approach really necessary? Can we just defer the dnNormalize until
after the regexp has been expanded?

