Great, it woks! But I did it in a different way.
I have the SFU installed on my AD and this includes the attribute "msSFU30GidNumber", which I use for the UNIX GID. Now I set up a "nss_base_group" which filters out all groups without this attribute. nss_base_group ou=OU_Groups,dc=my,dc=domain,dc=com?sub?&(msSFU30GidNumber=*) Thanks again for the hint. -- LDAP and AD connection problem with hardy https://bugs.launchpad.net/bugs/227229 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libnss-ldap in ubuntu. -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs