DNS is actually pretty nice for ACL [1]. Just make sure you use it with DNSSEC.
Want to check if Tom has access to /web/mike? Just do a lookup on the user in question with the reversed path you want to check.
"Can Tom read /web/mike?" => tom.mike.web.server.net
Advantages:
- Replication to multiple machines is trivial (piggybacking of DNS, after all).
- Lookups are fast. Can also be easily cached.
- All sane programming languages have built-in DNS resolution in their stdlib out-of-the-box.
- Manual override using /etc/hosts for debugging/emergency.