You want to determine if an object has the permissions defined in the schema for its object class as part of its ACL.
> acldiag <ObjectDN> /schema
For more on the default security descriptor, see Recipe 14.11.
Recipe 14.13 for resetting an object's ACL to the default defined in the schema
|