I'm creating an LDAP driver for a SUN LDAP DB utilising the changelog
facility. In test it wouldn't work unless I used an LDAP admin account
on the driver to talk to the changelog. The account is cn=directory
manager. Now that I'm ready to put it into production the SUN
administrator is telling me there is only two access rights he can give
me "user" and "admin". User doesn't have enough and admin is TOO much.

My question is does anybody know if there is a middle ground to give
access just to the changelog facility and not the rest of the LDAP

