hi, in this not: http://us2.samba.org/samba/docs/man/Samba-Guide/happy.html#id2536622 we can read that this's a samba bug and will be fixed. is this fixed? we curretnly keep: ldap machine suffix = ou=Computers ldap user suffix = ou=People ldap group suffix = ou=Groups ldap idmap suffix = ou=Idmap but as a workaround to the problem we use in /etc/ldap.conf in stead of: nss_base_passwd ou=People,dc=example,dc=com?one nss_base_shadow ou=People,dc=example,dc=com?one nss_base_group ou=Group,dc=example,dc=com?one this settings: nss_base_passwd dc=example,dc=com?sub nss_base_shadow dc=example,dc=com?sub nss_base_group ou=Group,dc=example,dc=com?one i'd be happy if i can switch back to the original one, but it doesn't seems to be working with the latest samba and nss_*:-( is there any progress or it's more deeper problem? yours. -- Levente "Si vis pacem para bellum!"