Hallo, by using more than one AD DC users and groups can created on all mashines and it replicated SID to everyone. That is fine. But xidNumber differ on the DCs. For windows-clients is that not a problem, but by data-replication between servers or future consolidation of storages it brings a lot of confusion. Incidentally I don't take pleasure mapping "domain users" per default to xidNumber 100 (unix group "users"). I think it is better to differ and all the world know "domain users" as gid 513 (and so on by other default-windows-groups). By correcting that with a ldapmodify-coomand, I notice that 516 und 521 not get any idmap by creation second DC - O.K. that is not fatally, but strange. With regards Andreas Matthus