Yes, the ACLs, because I'm not thinking on a single user with full
privileges and many users without any privileges.

Let say, I would like the DNS admins to modify their entries, and the
"user" administrator to create or modify user entries. That means
giving any of them only partial privileges. If you use any kind of
'proxy' (as phpldapadmin) it must be aware of existing ACL and the
most sensible way to acomplish that is to let the ldap server evaluate
them, using direct identification against the ldap server.
The phpldapadmin I remember (it might have evolved) has a single user
and wasn't capable to do this.

