one can create a ou=users,dc=test,dc=lan or a ou=system,dc=test,dc=lan Organizational Unit on a Samba-AD DC. It is however forbidden on a MS-AD (error message when trying with RSAT). Moreover, having such an OU in the Samba-AD domain prevents joining a MS-AD domain controller (join fails). So in order to be compliant with Microsoft behavior, Samba-AD should refuse to create those OU : * OU=users,DC=test,DC=lan * OU=system,DC=test,DC=lan
I guess the name attribute needs to be unique at each level and cn=users ad cn=system already exist...
*** This bug has been marked as a duplicate of bug 14225 ***