Access directive does not wokr properly


I am running openldap-2.0.4.
I cannot disable anonymous access to some of attributes on my server. I
have the following lines in my config file (global part):
access to attrs=aci,uidnumber,gidnumber,homedirectory,loginshell
        by dn=",<my organisational DN>$" read
        by * none
access to * by * read

But I am still able to access these attributes via base search at an
entry in my database.

What am I doing wrong?


