You say, "So use NFS version 4 with RPCSEC_GSS to blast past the 16 group identifier limitation." My question is: Will doing so get us to at least 32 groups per user (or are we still tied to individual client and server implementations)? Also, does using ACLs and NFSv4 automatically get rid of any 16, 32, or other group count limit (since ACLs are completely different beasts)? Finally, does RPCSEC_GSS + NFSv3 get us past the 16 group limit except for the NLM issue you mentioned?
Thanks in advance!