access to dn.subtree="ou=pki,dc=local,dc=debian-fr,dc=org" by group.exact="cn=PKI,ou=Security roles,dc=local,dc=debian-fr,dc=org" write by dn="cn=admin,dc=local,dc=debian-fr,dc=org" write by * auth