BTW, it would be interesting to create an LDAP authorization association based upon the Unix domain credential via getsockopt SCM_CREDENTIALS (and like mechanisms) and SASL EXTERNAL.... Kurt