dsidm should fully operation to determine account inactivation status and like the current perl scripts. additionally, we should be able to inactivate accounts and reactivate them from this sgcript, and understand account lock based on time or other acct policies.
We should AVOID using COS templates and the nsDisabledRole for this, but we should still support reading if it exists (there is no benefit over just setting nsAccountLock: true)
Metadata Update from @firstyear: - Issue set to the milestone: 1.1.0
Login to comment on this ticket.