Sun Java System Directory Server Enterprise Edition 6.2 Administration Guide

ACI “Read only”

In LDIF, to grant subscribers the right to read the entry dc=example,dc=com for company contact information, but not allow access to any entries below it, you would write the following statement:

aci: (targetscope="base") (targetattr="*")(version 3.0;
 acl "Read only";  allow (read,search,compare)

This example assumes that the ACI is added to the dc=example, dc=com entry.