> Is there a way to restrict the manager's account to log to the LDAP > server only from the local machine (127.0.0.1) so he can do whatever > he wants with LDAP entries and all other users(from remote machines) > have only read access and they can't log to the server as manager. Yes, create the appropriate ACLs.