I'm also wondering how a user can bind to the directory using only its "cn" and "userPassword", without having to enter all the "dn" info, so Bind DN could be just "joe.user@hipergate.org".
use SASL. See Admin guide for details. See sasl-regexp (will become authz-regexp) for determinig how to map user identity into a DN.
--Quanah
-- Quanah Gibson-Mount Principal Software Developer ITSS/TSS/Computing Systems ITSS/TSS/Infrastructure Operations Stanford University GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html