Sorry folks, please forgive me, i forgot to let you know i am using kerberos (SASL); so i bind via sasl mechanism not as the dn owned by me. Thanks once more for your help.
If you have correctly set up SASL/GSSAPI, then when someone binds, they are mapped to their DN in the database, and the access rules I reported would work correclty.
--Quanah -- Quanah Gibson-Mount Sr. Member of Technical Staff Zimbra, Inc A Division of VMware, Inc. -------------------- Zimbra :: the leader in open source messaging and collaboration