I honestly don't remember why the `use rfc2307` setting was only enabled on the first DC. All DCs seem to need this setting in order to use the UID/GID numbers from the directory, instead of using auto-generated numbers.