RE: Syncrepl and mmr

My current ACL is:

olcAccess: {0}to attrs=userPassword,shadowLastChange by self write by anonymous auth by * none
olcAccess: {1}to * by * read

Supposed this allows the user to modify their userPassword and (in so doing) modifying the shadowLastChange, allows anonymous to authenticate against these entries and allows others to read these entries

To give my syncrepl user (ldapadmin) access, my new ACL would another olcAccess:

olcAccess:{2}to * by cn=ldapdmin manage

> olcAccess: {0}to attrs=userPassword,shadowLastChange by self write by 
> anonymou s auth by * none

Obviously this ACL allows no access to the userPassword or shadowLastChange attributes by your replication user.  Clearly this will result in the behavior you have described.



