include /etc/openldap/schema/core.schema modulepath /opt/openldap-debug/libexec/openldap moduleload back_ldap.la moduleload rwm.la loglevel stats none threads 32 disallow bind_anon require authc require bind database ldap uri "ldapi://my.socket" rebind-as-user yes suffix "o=test" overlay rwm rwm-rewriteEngine on rwm-rewriteContext bindDN rwm-rewriteRule "^(cn=root,o=test)$" "${&&sub(a)}%1,ou=a,o=test" ":@" rwm-rewriteRule ".*" "" "#@" rwm-rewriteContext default rwm-rewriteRule "(.+)$" "$1,ou=${**sub},o=test" ":" rwm-rewriteContext searchEntryDN