Michael Ströder wrote:
For the use-cases affecting LDAP access (data maintenance, data retrieval) set-based ACLs are in effect which are indeed very slow.
Ah, forgot to make that more clear (and people tend to miss that point):
Æ-DIR's ACLs are _static_ and work their way through the actual data which is changed to alter the effective access rights.
Ciao, Michael.