On Tue, 2007-05-08 at 01:50 +0400, ??????? ??????? wrote: > If your directory does not implement this, and instead requires > querying the group, support for that is not yet written (and may never > be as it is somewhat silly)." According to those docs, the way your groups are set up is not supported. For that to work as described, you would need to add the groupMembership attribute to each user.