Jon Roberts wrote:
I know this may be out of your control given your caveats, but it might work better to put the dn values for delegated users in an attribute on the account object itself. Then an ACL using the dnattr form in the who clause would do the trick.
Hi Jon,
Thank you,
François
Jon Roberts www.mentata.com