On May 2, 2012, at 6:48 PM, Rich Megginson wrote: >> Is there any way to expose the nsDS5ReplicationAgreement objectClass to a >> less privileged account; i.e., an account solely designed to check >> replication status? > > You also need to expose the RUV tombstone entry at the base of each suffix.
Good to know, thanks. I haven't messed with ACIs on 389ds/IPA before; any pointers? Cheers, Ian _______________________________________________ Freeipa-users mailing list Freeipafirstname.lastname@example.org https://www.redhat.com/mailman/listinfo/freeipa-users