>I'm setting up a smaba/ldap server and I'd really like "regular" samba
>users to not have local login privs. (LDAP will handle all unix and
>samba accounts.)
>So, to that end, I thought changing the options in smbldap.conf,
>to something like
>Is there some unanticipated impact that would make this unwise?
>Is this the best way to accomplish the task?
>Finally, are there other places I need to handle this for it to work
>as I intend?
I can't speak as an expert but I've been running Samba for years with 
the users not having a login shell and I've not had any problems.

