Hi, small question here... if I have all users, groups, machines and idmaps in LDAP and I set: ldapsam:trusted = yes ldapsam:editposix = yes then I *don't* need an "add machine script". Am I correct? TIA -- Mariano Absatz - "El Baby" el.baby at gmail.com www.clueless.com.ar