I remembered reading that most AD changes (new users, groups,...) must be done on the PDC. In particular, I remembered this when I created new users and groups on the BDC and they never replicated to the PDC. So, I snapped both boxes back to just after a clean join of the BDC to the AD and did the OC install on the PDC instead and most everything worked just fine. Existing users became OC-enabled but I still had to enable new users even tho I had set the option to auto-enable new users. That's NBD IMHO.
Time to continue playing.
See ya...