> We are not much off. But you have mixed "samba/window" and
> "windows/windows" settings.
> Guess, which one i use.  ;-)

Okay that's good info. Keep in mind I wrote all that out purely by
memory so I'll repost if it differs at all from what I initially wrote. But
otherwise, yeah that sounds like a possible fix and I would certainly
welcome that! I think what may have mislead me was the roaming profile
section of the wiki refers to the fqdn to set permissions therefore in my
mind, the fqdn should be used for all references for config that's facing
the windows side.

> Now, do get where this is coming from.
> So use this (add CNAME for you member server ), Note, you MUST setup PTR
> records.

They have PTR records I know that for certain but I'll revisit that as well
to be certain they reflect what you show here.

> And offcourse this is not correct.