I reinstalled the 389 Windows Management Console. I also reran the command: certutil -A -d "C:\Users\<useracct>\.389-console" -n "CA Certificate" -t CT,, -i cacert.asc -a from the administrative command line within the "C:\Program Files (x86)\389 Management Console" directory. This system has another certutil that was getting in the way. This allowed me to connect with the "cn=Directory Manager" userdn and the "https://zigzag.ccbox.com:9830" URL However when I go to the samba server I still see where it is not translating the LDAP Group ID of 513 into the name "Domain Users". While I was in the console I verified the Group still exists, and I think it exists in the correct place. I think that PAM handles this, but please correct me if I am wrong. -- 389-users mailing list 389-users@xxxxxxxxxxxxxxxxxxxxxxx http://lists.fedoraproject.org/admin/lists/389-users@xxxxxxxxxxxxxxxxxxxxxxx