| access to < what > | by < who > | < Access level > |
| Directory tree level or objectclass attribute | LDAP user specifier | none, auth, compare, search, read, write |
# lock down passwords
access to attr=userPassword
by self write
by anonymous auth
by dn="cn=Manager,dc=example,dc=com" write
# everything else is read-only
access to *
by dn="cn=Manager,dc=example,dc=com" write
by * read
|
by * none |