On Wed, Sep 17, 2008 at 2:55 PM, Rich Megginson <rmeggins@redhat.com> wrote:

   The one thing I would like is to have group based host access control. E.g., I would like to define a new LDAP group (say, DBA-Production) that includes a bunch of host entries. When needed, I could add a user to the DBA-Production group and automatically give him/her access to the list of defined hosts. Anyone have suggestions on how to approach this?
see http://directory.fedoraproject.org/wiki/Howto:Netgroups

Wow.  Thank you.  It seems it will do exactly what I'm looking for...