permissions (acl) for nss_ldap


hope it's not to OT here...

maybe somebody has allready checked out acl settings
for the use of nss_ldap (objectclass: possixAccount should
define the needed attributes).
I wanna have a minimum of needed permissions.
Thinking about adding a new "rootbinddn" (see ldap.conf)
for every host using nss_ldap...
Can somebody please tell me what permissions are needed
for nss_ldap?

Liebe Gruesse, with best regards
Stephan Lauffer

[ Pedagogical University Freiburg - Germany ]
[ http://www.ph-freiburg.de/zik/            ]