a partial solution seems to be:
$ sudo vi /etc/pam.d/common-auth
# add line
auth optional pam_group.so
Set group permissions for all authenticated users (not NIS specific)
$ sudo vi /etc/security/group.conf
# add line
"*;*;*;Al0000-2400; audio,video,cdrom,plugdev,fuse"
any better solutions?