The general answer is "no". Access Control Models are implementation specific. The IETF is doing some work in this area. See http://www.ietf.org/html.charters/ldapext-charter.html for pointers to details.