Hello, I'm testing samba3 to shutdown our existing NT4 Domain. OS=UL1 Samba3 OpenLdap as backend All users and machine account are in a ldap backend (posix & samba). We will create the account manually into ldap before we went to a windows client (W2kPro) and join them manually into the domain. Witch users can join machines to the domain from a windows client directly? At the moment just the "ldap admin dn = cn=root,dc=xy,dc=com" user can join machines to the domain. When I try to do this with an other account, who has the ACL rights from LDAP to write into, and is also member of the Group "DomainAdmin" (SID-xxxx-512), I become the error message "LoginFailure: unknown user or bad password" on the windows client. What are nessesary skills for a useraccount to join machines into a samba3 domain? Is it really just the PDC ldap admin dn , who has enough rights to do that? Regards Manuel Piessnegger -- To unsubscribe from this list go to the following URL and read the instructions: http://lists.samba.org/mailman/listinfo/samba