Thanks Nathan. I found some old threads discussing the same issue. https://www.redhat.com/archives/fedora-directory-users/2006-November/msg0030 1.html Question1: Do I still need PassSync.msi installed on the Win server? Question2: How does this work exactly? This is what I understand: Any user who log on, the query first goes to FDS and then PTA-plugin quries the AD. Question3: What is exactly AD Chaining? I get the literal meaning that, AD is a symlink to the ldap DB on the FDS. I would like to know clear distinction between the two. (AD Chaining and Pass-thru) I am sorry, if I am repeating any questions. I am new to unix and learning on my own. Thank you so much, your help is greatly appreciated. Prashanth -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20090713/2b8bbd70/attachment.html