Re: apache + openldap

>  I don't know how the netscape web server does nested groups, but I bet
>  there is some kind of LDAP server-side optimization that they use.
Given a good cache for the authorization information, the perfor-
mance impact would hurt only the first time a user hits the site.
I don't know either how Netscape does  it,  but  I  think  it  is
feasible  to  do  this  in the client. However, I agree with Dave
that chasing around groups is not a good idea.  One  particularly
nice case would be if the group inclusion graph happened to  have

