Hi, Is the following acl supposed to work: access to dn.subtree="ou=adminstructure,dc=mydomain,dc=com" by group/agroupclass/anmemberattribute=".*" write ? It doesn't in my directory, whereas the man of slapd says that the who clause can be: group[/objectclass[/attrname]][.style] = <pattern> Does exist another way to express: "Give access to people member of any 'agroupclass', " ? Michaël P.