Each object in your LDAP directory has at least one owner. Object owners have the power to delete the object. Owners and the server administrator are the only users that can change the ownership properties and the access control list (ACL) attributes of an object. Ownership of objects can be either inherited or explicit. That is, to assign ownership you can do one of the following:
Directory Server allows you to specify multiple owners for the same object. You can also specify that an object owns itself. To do this you include the special DN cn=this in the list of object owners. For example, assume that the object cn=A has the owner cn=this. Any user will have owner access to the cn=A object if he connects to the server as cn=A.
For more information about how to work with ownership properties, see Manage directory entries.