how does the authorization system work when using such an overlay ? can
one write acl giving access to a user dn not in the directory ?
In general, unless you actually need to perform all of the functions of a
backend, you can usually get by with something much smaller - like an overlay
that only intercepts Bind operations, or a password hash module in this case.