In my OpenLdap we have ACL policies is there any script available to convert OpenLDAP acl policies to 389-ds policies.?
There is no script that I am aware of for such things. You will need to recreate them manually.
As for your IRC question, you can not have a single ACI with
allow and deny rules. You need two separate ACI's to do that. If
you give us some specific examples we can help with the syntax,
etc.