I'm facing a problem: I'm afraid we're going to need ACIs
with subtree scope; I browsed the archives both of OpenLDAP
and of ieft-ldapext-* hosted mailing lists and I found previous
dicussions on entry/subentry/prescriptive ACIs. I also see
an (expired ) draft-ietf-ldapext-acl-model-xx.txt with many
interesting considerations and extensions to the current
implementation. After playing a bit with current ACIs I see
they seem to work well, but there's room for improvements
(I note pre-parsing and caching could speed up things a bit).

Is there any news about an eventual standardization, or any
reference we might like to follow in improving ACIs? ideas?
suggestions? before I start coding ...

Thanks, Pierangelo.

Dr. Pierangelo Masarati | voice: +39 02 2399 8309 Dip. Ing. Aerospaziale | fax: +39 02 2399 8334 Politecnico di Milano | mailto:pierangelo.masarati@polimi.it via La Masa 34, 20156 Milano, Italy | http://www.aero.polimi.it/~masarati