ACL to replicate a single value of an attribute


Is it possible to create an ACL entry that will allow only the first value of an attribute to be read ( an example would be nice ) ?

For example having userPassword with a first value using MD5 hashing and a second value as plain text. We plan on replicating that object but we don't want to include the plain text value of the attribute userPassword.

Using another attribute to store the user's password is out of the question.

We need to add plain text passwords for some users in a country that use Active Directory ( AD password sync ).


Internal Support
CCNA Security, CCIP
StreamWIDE Romania