It seems that the search is subject to the sizelimit.
        sizelimit -1            (or appropriate number)
to the slapd.conf of the provider.

I think we should make sure this is noted in the Admin
Guide then. ;)

It would be very useful to allow the sizelimit to vary based on the
DN/group which is doing the search... then you could limit
the ordinary
users from loading all the records, but allow the LDAP Sync
replicas or
administrators to do this sort of thing.

See the "limit" directive in slapd.conf(5); this is already implemented.

How do I specify a group to set the limit for? It seems to only allow DNs.