7.8. OpenLDAP (slapd)

The following configuration will work after boot and while LIDS_GLOBAL is on because it gives slapd the CAP_NET_BIND_SERVICE capability.
/sbin/lidsconf -A -s /usr/local/libexec/slapd \
                  -o /usr/local/ldapdb 			-j WRITE
/sbin/lidsconf -A -s /usr/local/libexec/slapd \
                  -o CAP_NET_BIND_SERVICE                -j GRANT
/sbin/lidsconf -A -s /usr/local/libexec/slapd \
                  -o CAP_INIT_KILL                       -j GRANT
/sbin/lidsconf -A -s /usr/local/libexec/slapd \
                  -o CAP_SYS_MODULE                      -j GRANT