I helped a customer who needed to reset the four default ACL's on all 7000 of their users back to the defaults. This perl program creates an LDIF which accomplishes this tasks.
Here are the steps you need to follow:
If you don't have it, install Perl. I prefer the one from www.activestate.com.
Create input file with all the user DN's c:> ldapsearch -h shiloh -b "o=novell" "objectclass=*" dn > users
Create the LDIF that adds the default ACL's c:> perl acl3.pl users