Michael Ströder wrote:
For the use-cases affecting LDAP access (data maintenance, data
retrieval) set-based ACLs are in effect which are indeed very slow.
Ah, forgot to make that more clear (and people tend to miss that point):
Æ-DIR's ACLs are _static_ and work their way through the actual data
which is changed to alter the effective access rights.