dn: dc=exampleA,dc=com dc: exampleA objectClass: top objectClass: domain aci: (targetattr != "userPassword || passwordHistory || passwordExpirationTime || passwordExpWarned || passwordRetryCount || retryCountResetTime || accountUnlockTime || passwordAllowChangeTime ") (version 3.0; acl "Anonymous access"; allow (read, search, compare)userdn = "ldap:///anyone";) aci: (targetattr != "nsroledn || aci || nsLookThroughLimit || nsSizeLimit || nsTimeLimit || nsIdleTimeout || passwordPolicySubentry || passwordExpirationTime || passwordExpWarned || passwordRetryCount || retryCountResetTime || accountUnlockTime || passwordHistory || passwordAllowChangeTime")(version 3.0; acl "Allow self entry modification except for nsroledn, aci, resource limit attributes, passwordPolicySubentry and password policy state attributes"; allow (write)userdn ="ldap:///self";) dn: ou=People,dc=exampleA,dc=com ou: People objectClass: top objectClass: organizationalunit dn: cn=Rock,ou=People,dc=exampleA,dc=com objectClass: top objectClass: inetorgperson cn: Rock sn: Anne givenname: Anne rock telephonenumber: 54300 userpassword: WelcomeA dn: cn=Sandy,ou=People,dc=exampleA,dc=com objectClass: top objectClass: inetorgperson cn: Sandy sn: Ketty manager: cn=Rock, dc=primary telephonenumber: 54301 userpassword: Welcome1 dn: cn=Rivry,ou=People,dc=exampleA,dc=com objectClass: top objectClass: inetorgperson cn: Rivry sn: Rod manager: cn=Rock, dc=secondary telephonenumber: 54303 description: Trainee for dept 543 departmentNumber: 543 userpassword: Welcome1 dn: cn=Woods,ou=People,dc=exampleA,dc=com objectClass: top objectClass: inetorgperson cn: Woods sn: Tent description: User with no title userpassword: Welcome1