We are considering using the AD to eDir driver to create an LDAP
authentication tree and I've got a couple of questions about account
restriction synchronisation.

If I use the out of the box IDM3.5.1 AD driver configuration does the
account lockout status synchronise each way, for example if the eDir account
gets locked the AD one is also locked and vice versa? Also, is it possible
to lock an eDir account via LDAP authentication? We will be using eDir on Suse 9.