I need some help about this: Is it possible write something like this in acl? access to dn.regex=".*vd=([^,]+),o=hosting,dc=example,dc=tld$" by self write by set="user/editAccounts & [TRUE] vd & [$1]" write by set="user/editAccounts & [FALSE] vd & [$1]" read by * none Or the pattern for set is only a single attribute? TIA -- Mirko Grava (ML) <ops@klez.it>