I guess some people must be maintaining mail groups with ldap. How are you doing this?

The netscape documentation shows how to create a group and then give people access to that group. On the other hand, the openldap mail500 example describes a method whereby individuals become members of a group by adding the dn for that group as an attribute to their own record.
This second approach avoids having to give access to a group record to users.
