I managed to implement a single sign on system with MIT-Kerberos and windows clients using pgina with the PAM plugin (www.pgina.org). So my clients login via PAM having effectively a local user on the windows machine. Now I would like to add a public share (security=share) with the correct ACLs for my "local" users. Its somewhat like NFS with trusted accounts. So is it possible to connect the local user with the unix user in the samba share. tia, J?rg