> objectclass (
>     NAME 'nssBisGroup'
>     DESC 'Adds POSIX Attributes To A GroupOfNames'
>     SUP top
>     MUST ( cn, gidNumber )
>     MAY ( userPassword, description )
>  )

Uh... gee, on second thought I don't see how this is going to work with 
the smbldap scripts nor do I know if this will take a sambaGroupMapping. 
It would be pointless to have the database structure correct (or at 
least more correct) if in the process we invalidate the provided 
management tools or make it so that samba cannot also use the group.

I mean I know you are sharp enough to write your own scripts and there 
is the likelihood that I could also given the time.  Unfortunately we 
cannot assume this about our newbie admins who will be reading the 
resulting HOWTO.

