squid_ldap_auth (of Squid 2.5 Stable 12) works fine with this script: /usr/local/squid/libexec/squid_ldap_auth \ -h ldapserver \ -D "cn=adminaccount,ou=Service Accounts,ou=_SiteMgmt,ou=BNN,ou=DE,dc=emea,dc=company,dc=com" \ -w "topsecret" \ -b "ou=DE,dc=emea,company,dc=com" \ -f sAMAccountName=%s "ou=DE" says "german user". But our AD structure looks like: emea.company.com CH CZ DE DK ES ... The script above should say "OK" if the user is valid in ou=DE or ou=CH or ou=CZ or ... I guess I need an intelligent filter "-f" to do this. Any ideas? Werner Rost