Hi @ll! We had the need for checking group membership and user permission level because of the fallback to group "user", so we extended the ldap debugging. If you're interested feel free to use this auth.php (or the diff), it's from the 2006-06-09 devel version. One note from me: It's slightly confusing if you have to use urlencoded names in acl.auth.php and NOT encoded names in local.php (superuser). Even if it's mentioned at acl.auth.php... ;) Sorry, for the bug message again. Lothar