similar to: More AD DC Questions - GPO Issues

Displaying 20 results from an estimated 50000 matches similar to: "More AD DC Questions - GPO Issues"

2019 Apr 03
0
GPO error after activating domain trust
Hello everyone, this is my first post, so please be kind :) I've a working Samba AD DC 4.7.6 installed on Ubuntu 18.04 I can join Windows Machine, manage everything with RSAT. Yesterday I tried to estabilish a Domain Trust between my Samba Domain and a Windows 2008 domain, using "Active Directory Domains and Trusts". The Win2008 AD is one-way on outgoing trust, and my Samba is
2016 Feb 09
0
Samba AD DC: LDAP Bind function call failed.
I've got an existing AD domain with a couple of Windows domain controllers, and I'm trying to migrate the AD domain over to Samba, or at least add a couple of Samba DCs. I've added the samba DCs, verified that DNS is correct, and I have all the sysvol stuff replicating over between the controllers. Things seem to be working correctly, except when I do a "gpupdate /force" on
2013 Oct 20
1
Samba AD DC Replication Problems
I've seen a couple of posts related to this, but nothing with definitive solutions or even hints that helped me in the right direction. I'm attempting to add Samba4 DCs to my existing AD domain. This mostly works - it replicates in information from the Windows DCs, starts the services, and appears to have all of the necessary information. Scheduled replications from the Windows DCs to
2016 Apr 06
0
GPO
this command >> samba-tool ntacl sysvolreset 2016-04-06 13:34 GMT+03:00 Eben Victor <eben.victor at vcontractor.co.za>: > Hi All, > I create a Samba domain and works it's great, the issue that I have is > with the GPO's.When applying GPO's then only the computer Policy is applied > and not the user GPO. I keep on receiving below error. > Has anybody else
2016 Apr 06
1
GPO
Any event id for this one? If its event id : 1110. Open CMD box, type ipconfig /all And post the result. I suppect one of the following. 1) pc cloned without sysprep, so multiple pc's with same SID. 2) wrong DNS-Domain suffix 3) wrong DNS-Search suffix Test this by remove you pc from domain, add it again, reboot. Login with the same user. Greetz, Louis >
2016 Apr 07
0
GPO
Hi Louis, I don't have a FW enabled on my PC. I even tried to disable the FW on my all my DC's I can telnet to port 389/636/53, they are all open and goes through to my all DC's. Primary DC # Global parameters [global] workgroup = DOMAIN realm = DOMAIN.CORP netbios name = ##SELECTION_END##ZACPRDC002 server role = active directory domain controller idmap_ldb:use rfc2307 = yes
2016 Feb 17
2
problems gpupdate and domain-trust
Hi! I have a problem with gpupdate having a trust with a M$ -ADS domain. Before creating the trust gpupdate worked fine. Then i added the trust and then gpupdate gives the following error: Updating policy... Computer Policy update has completed successfully. User Policy could not be updated successfully. The following errors were encount ered: The processing of Group Policy failed. Windows
2016 Apr 06
5
GPO
Hi All, I create a Samba domain and works it's great, the issue that I have is with the GPO's.When applying GPO's then only the computer Policy is applied and not the user GPO. I keep on receiving below error. Has anybody else perhaps been experiencing the same issues? C:\>gpupdate /force Updating Policy... User policy could not be updated successfully. The following errors were
2018 Jul 30
0
gpupdate /force not applied
Hai Elias, Lucky you, im in a good mood and im "still" at work ;-) .. # Add [sysvol] acl_xattr:ignore system acls = yes path = /var/lib/samba/sysvol read only = No Did you set the parameter: APPLY_CHANGES_DIRECT="no" To yes, if not do it. Restart samba-ad-dc. Then, goto you GPO editor in windows, and klik every GPO object once. Some might complain about
2016 Apr 07
2
GPO
Hi Louis, See below,  C:\>ipconfig /all Windows IP Configuration    Host Name . . . . . . . . . . . . : EBEN-TEST-PC    Primary Dns Suffix  . . . . . . . : domain.corp    Node Type . . . . . . . . . . . . : Hybrid    IP Routing Enabled. . . . . . . . : No    WINS Proxy Enabled. . . . . . . . : No    DNS Suffix Search List. . . . . . : domain.corp Ethernet adapter Local Area Connection:
2018 Jul 30
0
gpupdate /force not applied
I had set up a trust relationship between our domain and another configured domain on our network, and at first it seems that this is what caused the GPO problem. I removed the trust and it all worked again. In internal tests that I had done, everything worked normal. Of course this is different when we put it into production. :) I know the trust is not 100%, but would you have any way to
2013 Nov 28
1
Issues on Samba4 AD DC GPO's with Sites and Winbind
Hello Samba-List, Recently I ran into a few access rights problems with GPO's. I have an test environment running with four samba4 AD DC's (sernet 4.1.2/debian wheezy). Used the Script's from the samba wiki for sysvol replication. The AD Database is comming from an classic upgrade and i have "idmap_ldb:use rfc2307 = yes" in my smb.conf. Some groups like for example
2018 Jul 05
0
Having a trust with Windows domain breaks GPOs in Samba domain
Hi list, this might be related to my other mail with the subject "Domain trust and browsing users and groups problem". We have a forest trust of two domains. One domain in US (us.root.prv) running exclusively on Windows 2012 R2 and one in EU (spreadshirt.private) running exclusively Sernet Samba 4.8.3-11. Both domains run functional level "2008 R2". The trust validates
2023 Apr 18
1
gpo client linux sssd does not apply
On 4/18/23 4:44 AM, Rowland Penny via samba wrote: > I think what you are saying is this, using oddjob-gpupdate replaces > the 'apply group policies = yes' line in smb.conf > > Anderson compiled oddjob-gpupdate and it didn't work using sssd, but > the same basic setup on the OS using winbind did. > > As far as I can see, oddjob-gpupdate or 'apply group
2023 Apr 18
1
gpo client linux sssd does not apply
On 17/04/2023 15:47, David Mulder via samba wrote: > On 4/14/23 2:23 AM, Anderson Sampaio Mello via samba wrote: >> Hello Samba Team, how are you? >> >> I'm joining linux clients in the company's environment and I would >> like to >> apply GPOs to linux clients, I'm in the testing phase. >> >> I'm testing with ubuntu clients version
2014 Oct 14
2
Domain trust and GPO
Hi all. I am testing samba4 AD for my organisation. Almost all is ok, except trusts. When I setup trust on Samba4 domain side, at once GPO stops working. In windows event log on the domain members I see error with event id 1110: "The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the
2019 Jul 26
4
GPO issues - getting SYSVOL cleaned up again
new thread, old issue been fiddling off-list with tips from Louis over the last days, and putting it back to the list to ask for help from others: 2 samba-4.9.11 DCs 1 samba-4.8.12 DM file server GPOs not working cleanly anymore tried to resync completely etc etc - right now I test gpupdate/gpresult on an older (not productive) W2008R2 server which I use for editing stuff via RSAT/MMC I
2016 Oct 13
2
Samba4 Trusts and GPO
Hi all. I have installed Samba 4.5.0 in CentOS 7 for testing Samba AD for my organisation. Almost all is OK, except trusts. When I setup trust on Samba4 domain side, at once GPO stops working. In windows event log on the domain members I see error with event id 1110: "The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest.
2023 Apr 17
1
gpo client linux sssd does not apply
On 4/14/23 2:23 AM, Anderson Sampaio Mello via samba wrote: > Hello Samba Team, how are you? > > I'm joining linux clients in the company's environment and I would like to > apply GPOs to linux clients, I'm in the testing phase. > > I'm testing with ubuntu clients version 22.04 and the software I used to > join the samba AD was sssd. > > The 22.04 ubuntu
2018 Mar 29
0
Failed to find DC in keytab, gpupdate fails
Hi, you're right about kvno. kvno dc gives me: dc at DOMAIN.NET.PL: kvno = 1 I'm pretty sure I didn't change dc$ password nor keytab wasn't recreated (the file is from 2015). I've checked other DCs. It looks like two of them with CentOS 7 have kvno = 2, and one with CentOS 6 has also v 1. DCs on CentOS 7 are pretty new, with samba version 4.7.4 from the scratch. Main DC