>I've checked the sources - rlm_ldap NEVER sets Ldap-Group attribute. It is used for comparison only :( > Only option seems to be testing for Ldap-Group != "". Ivan Kalik Kalik Informatika ISP