Blame SOURCES/0027-RHEL-specific-document-the-ppolicy-option-default.patch

db96ff
diff -up nss-pam-ldapd-0.8.13/man/nslcd.conf.5.ppolicy_option_default nss-pam-ldapd-0.8.13/man/nslcd.conf.5
db96ff
--- nss-pam-ldapd-0.8.13/man/nslcd.conf.5.ppolicy_option_default	2019-09-17 09:53:26.723676439 +0200
db96ff
+++ nss-pam-ldapd-0.8.13/man/nslcd.conf.5	2019-09-17 09:59:44.182750835 +0200
db96ff
@@ -360,6 +360,14 @@ vulnerabilities which allow denial of se
db96ff
 The default is to perform case-sensitve filtering of LDAP search
db96ff
 results for the above maps.
db96ff
 .TP 
db96ff
+\*(T<\fBpam_authc_ppolicy\fR\*(T> yes|no
db96ff
+This option specifies whether password policy controls are requested
db96ff
+and handled from the LDAP server when performing user authentication.
db96ff
+
db96ff
+By default the controls are only requested and handled if this option
db96ff
+is selected. This differs from the upstream default in order to retain
db96ff
+backwards compatibility with previous RHEL-7 releases.
db96ff
+.TP 
db96ff
 \*(T<\fBpam_authz_search\fR\*(T> \fIFILTER\fR
db96ff
 This option allows flexible fine tuning of the authorisation check that
db96ff
 should be performed. The search filter specified is executed and