A suggestion was made that I should add the contents of my sambaAdmin.ldiffile to this post. They are below. The kerberosSecurityObject isn't in my schema, so thus the error. But why did migrate_password.pl put that in my ldif? Is there a config option somewhere that should be switched to disable Kerberos or do I just need to manually edit the ldif and delete the offending line? Thanks, -Mont dn: uid=Administrator,ou=People,dc=forayadams,dc=foray,dc=com uid: Administrator cn: Samba Admin givenName: Samba sn: Admin mail: Administrator at forayadams.foray.com mailRoutingAddress: Administrator at mail.forayadams.foray.com mailHost: mail.forayadams.foray.com objectClass: inetLocalMailRecipient objectClass: person objectClass: organizationalPerson objectClass: inetOrgPerson objectClass: posixAccount objectClass: top objectClass: kerberosSecurityObject userPassword: {crypt}x krbName: Administrator at FORAYADAMS.FORAY.COM loginShell: /bin/bash uidNumber: 0 gidNumber: 0 homeDirectory: /root gecos: Samba Admin -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20060324/690d579d/attachment.html