I'm trying to configure individual shares to have access lists conterolled by the '@' method of group specificiation. We're running Samba 2.2 and NIS, and here's what the problem is: I know that NIS is functioning properly, and I can access shares if I add my username into 'valid user' for that share. If I set 'valid user = @group' and attempt to access the share (as I'm in the group 'group'), I get an auth error. Server is having its user authentication handled by a Samba 2.2 PDC. Any ideas? Here's the [global] section of smb.conf: [global] workgroup = EXAMEN log level = 1 netbios name = fileserv netbios aliases = yosemite2 server string = Yosemite (Samba) security = user encrypt passwords = yes allow trusted domains = no kernel oplocks = no oplocks = no max log size = 10000 wins support = no wins server = 158.222.64.239 name resolve order = lmhosts host wins bcast dns proxy = no preserve case = yes short preserve case = yes unix password sync = false invalid users = root load printers = no os level = 65 domain logons = yes domain master = no -- Don Werve <donw@examen.com> Unix System Administrator Plus je vois les hommes, plus j'admire les chiens.