Does the group ACL's require a "groupofNames" instead of using posixGroups under an OrganizationUnit?
Just read the docs: man slapd.access and read about "by group":
"The defaults are groupOfNames and member, respectively."
The objectClass in configurable and it's all stated in our documentation.