https://bugzilla.novell.com/show_bug.cgi?id=242520 ------- Comment #2 from rhafer@novell.com 2007-02-13 03:25 MST ------- IIRC we used the nss_compat with ldap because we needed an easy was to deny shell access to all LDAP users on a machine (without touching all the separate pam config files). But if nss_compat really uses setgrent/getgrent to emulate the initgroups function we should better switch away from it. But from a quick look at the source it does seem that if the underlying module (nss_ldap in this case) support initgroups, it uses initgroups and only does a fallback if initgroups is not implemented in the module. I must admit though, that I am not very familiar with the nss_compat code. Thorsten might know it better ... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.