I'm using pam_winbind to authenticate users on my mailserver. The problem I'm having is that it authenticates ANY user who has an account on the NT server. I don't want every single user to have a mail account, and it would appear very simple to just put all mail users into a new group on the NT Server if they require a mail account (say "Mail Users" for example). This would work if Winbind filtered based on NT group membership. Does such a function exist anywhere in winbind? Can it be set though that 'getent passwd' only returns the user info of all local users on the Linux machine and those who are in a particular group on the NT server? Regards Richard ------------------------------------------------ This message was sent using InSPire Net Webmail. http://www.inspire.net.nz