ldap acl question

Dear all,


I've got a little ACL problem with openldap 2.2. My ldap tree is very simple, like this:















I want to set an ACL, what allow:


- postmaster can write all attributes only in own OU

- when the postmaster bind to the ldap server, see only own ou as a "root dn", ( like an "ldap jail" :) )


Thanks for help, and sorry for my bad English,


Best Regards,