RE: Require SSL transport?

Hrm... It's not entirely clear to me what needs to happen. For example, I
have the following
in my slapd.conf

security ssf=128

and I can't seem to find a disallow or require which does the right thing.
seems to turn OFF SSL in many cases, and require only has requirements for
SASL, whereas
I need plaintext binding.

and the following ACL (which sounds like it'd do roughly what I want)
doesn't work

access to *
	by ssf=0 none

I considered trying something like

access to *
	by ssf=112 none

but I have no idea whether this would only forbid 3DES binds, or anything
3DES or lower (the docs don't say, and I wouldn't know where to look in the

I can live with not having this sort of restriction, but it changes,
somewhat, my plans
for implementation.

> >> Thanks!