> Set up a local root user on every box. I highly recommend not relying > on LDAP for that, or you're a bit screwed if, for example, your network > cable goes bad. Right, I just made my AllowGroups line look like this: AllowGroups root operations AllowUsers appears to trump AllowGroups so this is a good solution. -- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users