ACL issues

I've been fighting with ACL's for about a week now, and I've gotten
nowhere with them.  After looking through the FAQ, I decided to go with
what is specified in "What ACL's should I start with?":

  access to attr=userpassword
    by self write
    by anonymous auth

  access to *
    by self write
    by users read

However, this ACL actually doesn't allow a successfully-authenticated dn
to write to his own entry at all, and I can't figure out why.  What's even
more odd is that he *can* read his own userPassword attribute and no one
else's, leading me to assume that they're at least working partially.  I
guess that makes the situation even more puzzling.  Any ideas?

I'll have follow-up questions (I can't get 'access to dn.subtree' to work
either), but I guess this would be a better place to start...


John Madden
UNIX Systems Engineer
Ivy Tech State College