> Otherwise, like Scott said, you can pull the loginGraceRemaining attribute out > of the LDAPResponseContext in the authentication context. So the attributes there come back even if the bind fails? -- Scott