Im facing issue mentioned in subject, after upgrading from oes2 sp2 to oes2 sp3.

Right after upgrade following error appeared in messages file.

xadsd: [LSASS] LsapOpenPolicy: failed to open policy handle for server \\ Invalid credentials

Also rpcclient shows following error

rpcclient -k localhost -c dsroledominfo
Connecting to host=localhost
resolve_lmhosts: Attempting lmhosts lookup for name localhost<0x20>
Connecting to at port 445
Doing spnego session setup (blob length=123)
got OID=1 2 840 113554 1 2 2
got OID=1 2 840 48018 1 2 2
got OID=1 3 6 1 4 1 311 2 2 10
got principal=cifs/
Doing kerberos session setup
ads_cleanup_expired_creds: Ticket in ccache[FILE:/tmp/krb5cc_0] expiration Mon, 21 Mar 2011 05:08:00 CET
rpc_pipe_bind: Remote machine localhost pipe \lsarpc fnum 0x719a bind request returned ok.
lsa_io_sec_qos: length c does not match size 8
You have new mail in /var/mail/root


xadcntrl validate is ok

phobos:/var/opt/novell/xad/log # xadcntrl validate
Server Name: .CN=phobos.OU=OESSystemObjects.dc=lan.dc=aaa.dc=bb b.T=aaa.
Binary Version: 20602.00
Root Most Entry Depth: 0
Product Version: eDirectory for Linux x86_64 v8.8 SP6 [DS]

Checking for nameserver BIND
number of zones: 3
debug level: 0
xfers running: 0
xfers deferred: 0
soa queries in progress: 0
query logging is OFF
recursive clients: 0/1000
tcp clients: 0/100
server is up and running
zone details are dumped at /var/opt/novell/log/named/
Checking for Name Service Cache Daemon: running
Checking for RPC Endpoint Mapper Service running
Checking for Kerberos KDC Service running
Checking for Kerberos Password Change Server running
Checking for Domain Services Daemon running
Checking for Samba NMB daemon running
Checking for Samba WINBIND daemon running
Checking for Samba SMB daemon running
Checking for service sshd running
Checking for rsync daemon: running

The reason is that user Administrator is not able add workstations to domain, edit group policy etc ...

Does anyone has any hint how to get over this issue ?? Thx.