Creating a limited LDAP admin user

Hello!

We are planning to have an external system use our LDAP, and want to create an administrative user in the LDAP with limited capabilities, only read and compare, and NOT modify. 

Does anyone have information on how one would set this up? I'm sure we have to create an LDIF file with the user informaiton, but I'm just not sure where the user would be, and how to limit the privlidges.

Thanks!
Christine

Syndicate content