Hi,

I would like to control host access via groups/role? Has anyone done this? If so, can you give me some pointers in the correct direction? 

I've done my own research, but found that I need to allow more than one group to log into a system. So, pam_groupdn is out of the question. The other way of doing it would be to use SSH, but this involves a lot of client configuration. The 3rd option would be to use a netgroup style in 389. 

Please advice???

Thanks!