Created attachment 855 [details] Visual description of problem If the administrator wants to require group membership in Domain Users@lab.lkpg.cendio.se to log in to ThinLinc, they could add the group name to /vsmserver/allowed_groups configuration via Web Administration. If they did add domain users@lab.lkpg.cendio.se via Web Administration, they would end up allowing two groups - domain and users@lab.lkpg.cendio.se instead however. This is *not* what the administrator intended. This bug does have quite a bit of overlap with bug 2534 but could be solved separately by, for instance, refusing to handle group names with spaces in them. Found when testing bug 5968 on a i386 Debian 9 system.