Andrew Morgan wrote:
I noticed that the memberOf tab in AD Users and Computers does not show group membership for groups that are not in the same domain as the user. Access controls were still correctly applied though, so those interfaces must be enumerating group membership some other way.
How about the 'tokenGroups' attribute? Samba would have to emulate this too. http://msdn2.microsoft.com/en-us/library/ms680275(VS.85).aspx Ciao, Michael. -- Fedora-directory-devel mailing list Fedora-directory-devel@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-directory-devel