Quoting Pierangelo Masarati <ando@sys-net.it>:
> that slapo-ppolicy(5) enforces a single value for the
> password attribute, even though such constraint is not present in the
> specification of userPassword.
That was not the issue, the issue was that I was authenticated with my
SASL (Krb5 key) _even though I did not have {SASL} in userPassword_.