The installation of software through GPO on the existing DSfW domain controllers with OES 2015 SP1 fails because of insufficient ACLs for certain attributes on the domain root partition. This causes the failure of the group policy update performed on a workstation.
To resolve this issue, update the ACLs by executing the script software_gpo_setup.pl on the OES 2015 SP1 domain controller as follows. This script is made available with Update 30 - OES 2015 SP1 maintenance release.
ADM_PASSWD=<domain admin password> perl /opt/novell/xad/sbin/software_gpo_setup.pl
Or
perl /opt/novell/xad/sbin/software_gpo_setup.pl with the domain admin password as input.
After successful execution of the script on the domain controller, the group policy update performed on the workstation should be successful.
If a user with a Universal password policy is moved from non-domain partition to a DSfW partition, the user will not be able to login into the DSfW domain.
To resolve this issue, delete the old password policy using iManager. After this step is done, the user will be able to login to the workstation.
If a member of the GroupPolicy Creator Owner group tries editing the group policy through the Group Policy Management Console(GPMC), and if the GPMC is referring the ADC, the user will not be permitted to change the DFS referral to make it point to the first domain controller. To make changes, you will require administrator privileges
You might get 'access denied' warnings while backing up Group Policies in XP and Vista clients connected to DSfW. It is safe to ignore them.
WMI filters are not supported in this release.