by users write
access to dn.onelevel="ou=Groups,dc=example,dc=com"
- attrs=entry
- by dnattr=creatorsName write
+ attrs=entryTtl
+ by dnattr=member manage
by * read
access to dn.onelevel="ou=Groups,dc=example,dc=com"
- attrs=member
by dnattr=creatorsName write
- by users selfwrite
+ by * break
+
+access to dn.onelevel="ou=Groups,dc=example,dc=com"
+ attrs=entry
by * read
access to dn.onelevel="ou=Groups,dc=example,dc=com"
- attrs=entryTtl
- by dnattr=member manage
+ attrs=member
+ by users selfwrite
by * read
access to *