i cannot believe...but it's true ;( the scenario: Centos 5.3 fully updated, Fedora that one i downloded by repository for Centos 5.3 last saturday samba: rpm -qa |grep samba system-config-samba-1.2.41-3.el5 samba-client-3.0.33-3.7.el5 samba-common-3.0.33-3.7.el5 samba-3.0.33-3.7.el5 rpm -qa |grep fedora fedora-ds-base-1.2.0-2.fc6 fedora-ds-dsgw-1.1.2-1.fc6 fedora-ds-admin-1.1.7-3.fc6 fedora-ds-1.1.3-1.fc6 fedora-ds-console-1.2.0-1.fc6 fedora-ds-admin-console-1.1.3-1.fc6 fedora-idm-console-1.1.3-1.fc6 samba is pdc with fds backend trying to change Administrator pasword using smbldap-passwd i get: Failed to modify UNIX password: attribute "shadowLastChange" not allowed changing for test user is fine checking with admin console i find that Administrator is without shadowAccount object. i folowed the samba howto to installa pdc, but i recovered a backup of previous pdc server taht was damaged and reinstalled my question is: when is added this object and who adds it? tia m. -- Maurizio Marini Via Collemare, 14 - 61039 San Costanzo (PU) - Italy GSM +39-335-8259739 RTG : +39-0721950396 0721870286 Skype: maumar at datalogica.com C.F. MRNMRZ59E17G920X P. Iva: 01332360419 -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 190 bytes Desc: This is a digitally signed message part. Url : http://lists.fedoraproject.org/pipermail/389-users/attachments/20090714/8af5ee5f/attachment.bin