Susan wrote: >Nevermind, got it! > >Turns out, in the memberuid attribute, you must specify the NAME of the user, NOT the UID. (I >know, makes perfect sense, doesn't it??? I mean, who in his infinite wisdom named the attribute >memberUID, when it doesn't work with a UID???) > > > Ah yes, that is all a little confusing. In RFC2307 parlance, a unix uid is referred to as uidNumber because in LDAP uid generally refers to textual representation of the user. >Anyway, after changing 1234 to test, it works: > ># id test -a >uid=1234(test) gid=666(sysadmin) groups=666(sysadmin),1234(testGroup) > > > Good stuff -- Pete -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3241 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20060314/3e2c8ad1/attachment.bin