We have two edirectory trees in which groups (one is the IDV and the
other is a resource tree) are created. The main purpose of these groups
in the resource tree is to be used by external applications to read (via
ldap) and grant application authorizations to only group members.

So my question is in this case is it really needed to synchronize
security equals, equivalent to me, and the group membership attribute on
the user object (some of which the vanilla edir2edir drivers do by


