Ok, this is done, committing now. To summarize, there is now a -g flag to ckpasswd, which causes "user at group" to be returned instead of just "user". By using this in a "auth:" parameter in readers.conf, system group information will be available to match in access blocks. -- Jeffrey M. Vinocur jeff at litech.org