(I have no experience with OES) Are you talking about SMB groups? When upgrading to DSSv6 we noticed that DSS uses an updated LDAP (Samba) scheme and we had to "upgrade" our LDAP entries to conform to that.
But in our case it was as bad as DSS not recognizing the domain entries in the first place.