You can restrict access based on the security strength factor (SSF)

access to dn="cn=example,cn=edu"
      by * ssf=64 read

0 (zero) implies no protection,
1 implies integrity protection only,
56 DES or other weak ciphers,
112 triple DES and other strong ciphers,
128 RC4, Blowfish and other modern strong ciphers.

