Hi, I haven't seen this addressed in the docs I've read. If I missed one, please let me know. I want to allow users from any of 3 different groups to access a certain class of machine. However, I don't know if I can open /etc/ldap.conf and enter "pam_groupdn cn=group1,dc=example,dc=com cn=group2,dc=example,dc=com" or if I have to have multiple instances of 'pam_groupdn', or if it's completely unsupported. If it's not supported, does anyone have a good workaround that doesn't require putting all of these people in the same group? Thanks. _______________________________________________ Pam-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/pam-list