I sniffed the traffic between 389DS and W2003 and I saw an objectClass violation when 389 tried to add the userAccountControl atttr to a group. The group is created anyway.
I've searched in the web and it looks like userAccountControl is only for users, not for groups. Looking at the Windows Sync code it looks like 389 DS always add that attribute for both.
Regards,
Diego
--
Diego Woitasen
--
Diego Woitasen
-- 389 users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx https://admin.fedoraproject.org/mailman/listinfo/389-users