I know this is probably something very simple but I can't for the life of me figure out what's going on. This is a very basic setup using domain security and joined NT style in an AD running in Mixed Mode. I am *not* using winbind, all user and group accounts are represented locally in /etc/passwd and /etc/group. For the most part this is functional, from a windows client I am able to modify access permissions for users already in the ACL (using acl support, filesystem is mounted with acl option etc.). What I cannot do is add users to the acl from the windows side. Does anyone know what I am doing wrong? Christian