On 12/03/12 18:23, up at 3.am wrote: > ...and you just hit on something that solved the problem. It seems that FR was > getting the group info from LDAP indirectly, through the PAM module, which was Actually, probably not. It probably gets the groups via nss_ldap, through nssswitch.