RE: Setting up groups under OpenLDAP

According to my understanding of the FAQ page
(http://www.openldap.org/faq/data/cache/52.html), I can set up the entry
"cn=Administrators,ou=groups,o=cascade,c=au", and set its objectclass
attribute to groupofNames.  Then I set its member attribute to include the
value "uid=dan,ou=people,o=cascade,c=au".

access to *
   by group "cn=Administrators,ou=groups,o=cascade,c=au" write
   by dn=".+" read
   by * read

rule then should hopefully mean that if I bind to the server as any name
specified in the named group's member attribute, I should be given write
permission to any entry in the database.  Is this a correct assumption?

I've just noticed that I haven't set the objectclass for
cn=Administrators... to "top". Will this affect things?


> >