Hi Guys,
Haven't posted here in a while... but I ran across something I need help with, so I'm hoping someone can point me in the right direction.
I've got an open LDAP implementation running right now, but the only thing I can't seem to get a grasp of are ACLs. With anonymous access turned off, I'm trying to create a user which has read-only access to a portion (or whole) of the directory tree... this would only be used for binding to verify authentication (all passwords are {shha} hashes).
I've as yet been unable to write ACLs to allow this to happen... and I don't like binding as a normal user (since the user/pass need to be in some scripts). Has anyone else run across the need for something like this?
Thanks in advance,
-Griffin-

