Saving User Passwords

So I got it working with the primary being authad and the secondary just being authplain. However when I do self registration it creates a user account and get all the groups he's apart of. Thats fine and awesome. What I dont want is that it also stores the password that the user logged on with. Yes its an MD5 has but I would just like it to not store it at all for security purposes. I can actually change it in the user file and it doesnt affect it, but just wondering if there is some setting to just say don't record the password the user logs on with.

Also why doesn't the user get put in the @user group automatically. That kind of stinks for setting up ACL's easier

feature request: a fallback for not athenticated (unknown ldap user) to local filebased auth were grait and would help a lot!

