[Samba] XP Client cannot join Samba3 PDC

#server naming
        netbios name = CHARON
        workgroup = GPNET
        server string = GPNET PDC Server

#authentication as PDC
        domain logons = yes
        domain master = yes
        security = user
        password level = 8
        username level = 8
        smb passwd file=/usr/local/samba/private/smbpasswd
        logon script = logon.bat
        encrypt passwords = yes
        domain admin group = @root
        username map = /usr/local/samba/lbin/map.user

#user group scripts
        add user script=/usr/sbin/useradd -d /dev/null -c "Samba account %u"
-s /bin/false -M %u
	  add machine script =/usr/sbin/useradd -d /dev/null -g machines -c
"Machine account %u" -s /bin/false -M %u

#wins server
        wins support = yes
        time server = yes
        local master = yes
        lm announce = yes
        lm interval = 120
        browse list = yes
        remote announce =
        os level = 64
        preferred master = yes
#wins client
        name resolve order = wins bcast lmhosts
        wins proxy = yes
        dns proxy = yes

#IP Networking
        interfaces =
        hosts allow = 192.168.201. 192.168.202. 127. 192.168.12.
        socket options = TCP_NODELAY IPTOS_LOWDELAY SO_RCVBUF=8192

        printer = pshplj5
        load printers = yes
        printcap name = /etc/printcap

#log files
        log level = 0
        max log size = 50
        log file = /var/log/samba/log.%m

#default share
        map archive = yes
        map system = yes
        map hidden = yes
        browseable = yes
        writable = yes
        public = yes

# items that prevent domain join-must be removed for successful operations
	  force group=nobody
	  force user = nobody

   comment = Home Directory for %U
   browseable = no
   write list = %U
   valid users= %U
   path = /home/%U
   force user=%U
   force group=%U

   browseable = no
   write list = %U
   valid users= %U
   force user=%U
   force group=%U

   comment = Network Logon Service
   path = /home/netlogon
   writable = no
   public = no
   write list=administrator root

   comment = Network Public Executables
   path = /home/exe

   comment = Movie files
   path = /home/movie

   comment = Audio files
   path = /home/audio

	When u used these FORCE user and group settings, you didn't have to
tell it
	which user and group to force?

	Can you send a copy of your smb.conf file.

	The problem I am having is that sometimes a machine that is
connected to the
	domain will not allow a user to authenticate.. but it allows other
users to
	authenticate.. Im wondering if this could be related...


	Resolved problem:
	Had decided to use global force user/force group options for the
	It worked like a charm.  All my shares now had default groups and
	I did not realize how truly global these settings were.  After a
	review of the logs,  I noticed that root indeed logged in.  However,
	effective user always morphed into nobody.  At that time, I thought
this was
	nominal behavior.  NOT!

	The global settings for:
	FORCE USER = unix user
	FORCE GROUP= unix group
	Sets the Effective User ID to those forced ID's for EVERYTHING,
	non share oriented communications.
	Check your configs and eliminate these GLOBAL settings.  

	30 hours!  DOH!


