Only users with the secret key for the certificate should be able to upload certificates to an LDAP keyserver.
This should be activatable via a configuration option (i.e. a registry setting in Windows).
This does not affect the capabilities of the command line.