Yes I adjusted the Domain by loading this variable first:
eval "$(ucr shell ldap/base)"
and then I used it like this:
by set="user & [cn=UserAdminGroup,cn=groups,$ldap_base]/uniqueMember*" write
by * read break
maybe there’s a problem with the slapd-conf file. this is how it looks:
access to dn.subtree="cn=users,dc=mydomain,dc=tld"
by set="user & [cn=UserAdminGroup,cn=groups,dc=mydomain,dc=tld]/uniqueMember*" write
by * read break
access to dn.subtree="cn=groups,dc=mydomain,dc=tld"
by set="user & [cn=UserAdminGroup,cn=groups,dc=mydomain,dc=tld]/uniqueMember*" write
by * read break
access to dn.subtree="cn=temporary,cn=univention,dc=mydomain,dc=tld"
by set="user & [cn=UserAdminGroup,cn=groups,dc=mydomain,dc=tld]/uniqueMember*" write
by * read break