First I want to say cpu is a great tool for me and probably others, thanks for your efforts.

One question though, does cpu support  rfc2307bis like groupnames like:

uniqueMember: uid=someuser,ou=users,dc=company,dc=com
(see RFC2307bis section 5.2)

Since pam_ldap supports this feature, it will be easier to use those members in ACL's. It seems to me, that a DN as a member is less error prone because it ensures "uniqueness" .

greets   Paul