Here is my goal: Computers A -- MS PDC B -- Linux which maintains all local accounts, and cached accounts C -- Linux which uses A and/or B for authentication User authentication on B will use Winbind to autheticate against A (AD) User authentication on C will first try A, and fall back to B (using Winbind) nss on C is configured to locate information on B (via winbind or ldap) I've been trying to use idmap ldap backend, but haven't been successful yet, and just want to know if this path is doable before spending more time on it. Thanks, Craig This message and/or attachments may include information subject to GDC4S O.M. 1.8.6 and GD Corporate Policy 07-706 and is intended to be accessed only by authorized personnel of General Dynamics and approved service providers. Use, storage and transmission are governed by General Dynamics and its policies. Contractual restrictions apply to third parties. Recipients should refer to the policies or contract to determine proper handling. Unauthorized review, use, disclosure or distribution is prohibited. If you are not an intended recipient, please contact the sender and destroy all copies of the original message.