Using LDAP to determine allowed services

Hi All,
   I'm wondering if anyone out there is using OpenLDAP to allow disallow 
users access to services (i.e. POP vs. POPS, IMAP vs. POP). I'm pretty 
sure that there are schemas out there that would make integrating this 
easier but I've not been able to find them.
   I'm essentially looking to reproduce IPlanet behavior in terms of 
Directory Server/Mail Server.
   Any help would be greatly appreciated.