Bob of Donelson Trophy
2015-Jan-29 21:21 UTC
[Samba] W7 client cannot adjust file permissions via ADUC
Rowland, I think you have confused my email with a different thread. Uhm . . what? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] "Everyone deserves an award!!" On 2015-01-29 07:30, Rowland Penny wrote:> On 29/01/15 12:54, Bob of Donelson Trophy wrote: > Rowland, I have tried your various alteration suggestions and it is a "negative" result. Here is the output from wbinfo -u & wbinfo -g root at dtmbr01:~# wbinfo -u administrator dns-dtdc02 dns-dtdc01 krbtgt guest root at dtmbr01:~# wbinfo -g allowed rodc password replication group enterprise read-only domain controllers denied rodc password replication group read-only domain controllers group policy creator owners ras and ias servers domain controllers enterprise admins domain computers cert publishers dnsupdateproxy domain admins domain guests schema admins domain users dnsadmins root at dtmbr01:~# getent passwd Administrator administrator:*:50001:50006::/home/samba/DT***RM/users/administratorSERNAME%:/bin/bash Say what, "administratorSERNAME%"? After running the 'generation one' script to create the member server, I have changed nothing except the suggestions that have been made on this mailing list. Attempting to gain access to the member server to re-adjust the file permissionson "profiles" per the instructions on the samba wiki. Please, thoughts? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] "Everyone deserves an award!!" On 2015-01-28 13:09, Rowland Penny wrote: On 28/01/15 18:55, Bob of Donelson Trophy wrote: No, I did not try the alterations but, Louis had me remove the "domain users" line earlier. Put the line back in and try alterations? (If so, I will not have time until you are asleep, tonight.) By all means try it, you have nothing to lose :-) I take it that 'wbinfo -u' shows all the domain users on the member server and 'wbinfo -g' shows all the domain groups. Also 'getent passwd <domain user> shows the user. Rowland Links: ------ [1] http://www.donelsontrophy.com [1] What I should also have said, if what 'wbinfo -u' & 'wbinfo -g' is displaying is *all* your domain users, then *none* of your users need a 'uidNumber' and only 'Domain Users' & 'Domain Admins' need a 'gidNumber'. Try adding a new user and then give this user a 'uidNumber' Rowland Links: ------ [1] http://www.donelsontrophy.com
Rowland Penny
2015-Jan-29 21:25 UTC
[Samba] W7 client cannot adjust file permissions via ADUC
On 29/01/15 21:21, Bob of Donelson Trophy wrote:> > > Rowland, > > I think you have confused my email with a different thread. > > Uhm . . what? > > --- > > ------------------------- > > Bob Wooden of Donelson Trophy > > 615.885.2846 (main) > www.donelsontrophy.com [1] > > "Everyone deserves an award!!" > > On 2015-01-29 07:30, Rowland Penny wrote: > >> On 29/01/15 12:54, Bob of Donelson Trophy wrote: >> Rowland, I have tried your various alteration suggestions and it is a "negative" result. Here is the output from wbinfo -u & wbinfo -g root at dtmbr01:~# wbinfo -u administrator dns-dtdc02 dns-dtdc01 krbtgt guest root at dtmbr01:~# wbinfo -g allowed rodc password replication group enterprise read-only domain controllers denied rodc password replication group read-only domain controllers group policy creator owners ras and ias servers domain controllers enterprise admins domain computers cert publishers dnsupdateproxy domain admins domain guests schema admins domain users dnsadmins root at dtmbr01:~# getent passwd Administrator administrator:*:50001:50006::/home/samba/DT***RM/users/administratorSERNAME%:/bin/bash Say what, "administratorSERNAME%"? After running the 'generation one' script to create the member server, I have changed nothing except the suggestions that have been made on this mailing list. Attempting to gain access to the member server to re-adjust the file permissions > on > "profiles" per the instructions on the samba wiki. Please, thoughts? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] "Everyone deserves an award!!" On 2015-01-28 13:09, Rowland Penny wrote: On 28/01/15 18:55, Bob of Donelson Trophy wrote: No, I did not try the alterations but, Louis had me remove the "domain users" line earlier. Put the line back in and try alterations? (If so, I will not have time until you are asleep, tonight.) By all means try it, you have nothing to lose :-) I take it that 'wbinfo -u' shows all the domain users on the member server and 'wbinfo -g' shows all the domain groups. Also 'getent passwd <domain user> shows the user. Rowland > Links: ------ [1] http://www.donelsontrophy.com [1] > > What I should also have said, if what 'wbinfo -u' & 'wbinfo -g' is > displaying is *all* your domain users, then *none* of your users need a > 'uidNumber' and only 'Domain Users' & 'Domain Admins' need a > 'gidNumber'. > > Try adding a new user and then give this user a 'uidNumber' > > Rowland > > > Links: > ------ > [1] http://www.donelsontrophy.comVERY BIG OOPS sorry :-[
Bob of Donelson Trophy
2015-Jan-29 21:29 UTC
[Samba] W7 client cannot adjust file permissions via ADUC
Rowland, Let me resend the original message. It is a garbled mess being lost in email land for so long (sent at 7:00a local time, appeared 7 hours later.) HOLD ON A BIT. CLARITY COMING. --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] "Everyone deserves an award!!" On 2015-01-29 15:25, Rowland Penny wrote:> On 29/01/15 21:21, Bob of Donelson Trophy wrote: > Rowland, I think you have confused my email with a different thread. Uhm . . what? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] "Everyone deserves an award!!" On 2015-01-29 07:30, Rowland Penny wrote: On 29/01/15 12:54, Bob of Donelson Trophy wrote: Rowland, I have tried your various alteration suggestions and it is a "negative" result. Here is the output from wbinfo -u & wbinfo -g root at dtmbr01:~# wbinfo -u administrator dns-dtdc02 dns-dtdc01 krbtgt guest root at dtmbr01:~# wbinfo -g allowed rodc password replication group enterprise read-only domain controllers denied rodc password replication group read-only domain controllers group policy creator owners ras and ias servers domain controllers enterprise admins domain computers cert publishers dnsupdateproxy domain admins domain guests schema admins domain users dnsadmins root at dtmbr01:~# getent passwd Administratoradministrator:*:50001:50006::/home/samba/DT***RM/users/administratorSERNAME%:/bin/bash Say what, "administratorSERNAME%"? After running the 'generation one' script to create the member server, I have changed nothing except the suggestions that have been made on this mailing list. Attempting to gain access to the member server to re-adjust the file permissions on "profiles" per the instructions on the samba wiki. Please, thoughts? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] [1 [1]] "Everyone deserves an award!!" On 2015-01-28 13:09, Rowland Penny wrote: On 28/01/15 18:55, Bob of Donelson Trophy wrote: No, I did not try the alterations but, Louis had me remove the "domain users" line earlier. Put the line back in and try alterations? (If so, I will not have time until you are asleep, tonight.) By all means try it, you have nothing to lose :-) I take it that 'wbinfo -u' shows all the domain users on the membe r server and 'wbinfo -g' shows all the domain groups. Also 'getent passwd <domain user> shows the user. Rowland Links: ------ [1] http://www.donelsontrophy.com [1] [1 [1]] What I should also have said, if what 'wbinfo -u' & 'wbinfo -g' is displaying is *all* your domain users, then *none* of your users need a 'uidNumber' and only 'Domain Users' & 'Domain Admins' need a 'gidNumber'. Try adding a new user and then give this user a 'uidNumber' Rowland Links: ------ [1] http://www.donelsontrophy.com [1] VERY BIG OOPS sorry :-[ Links: ------ [1] http://www.donelsontrophy.com
Rowland Penny
2015-Jan-29 21:33 UTC
[Samba] W7 client cannot adjust file permissions via ADUC
On 29/01/15 21:21, Bob of Donelson Trophy wrote:> > > Rowland, > > I think you have confused my email with a different thread. > > Uhm . . what? > > --- > > ------------------------- > > Bob Wooden of Donelson Trophy > > 615.885.2846 (main) > www.donelsontrophy.com [1] > > "Everyone deserves an award!!" > > On 2015-01-29 07:30, Rowland Penny wrote: > >> On 29/01/15 12:54, Bob of Donelson Trophy wrote: >> Rowland, I have tried your various alteration suggestions and it is a "negative" result. Here is the output from wbinfo -u & wbinfo -g root at dtmbr01:~# wbinfo -u administrator dns-dtdc02 dns-dtdc01 krbtgt guest root at dtmbr01:~# wbinfo -g allowed rodc password replication group enterprise read-only domain controllers denied rodc password replication group read-only domain controllers group policy creator owners ras and ias servers domain controllers enterprise admins domain computers cert publishers dnsupdateproxy domain admins domain guests schema admins domain users dnsadmins root at dtmbr01:~# getent passwd Administrator administrator:*:50001:50006::/home/samba/DT***RM/users/administratorSERNAME%:/bin/bash Say what, "administratorSERNAME%"? After running the 'generation one' script to create the member server, I have changed nothing except the suggestions that have been made on this mailing list. Attempting to gain access to the member server to re-adjust the file permissions > on > "profiles" per the instructions on the samba wiki. Please, thoughts? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] "Everyone deserves an award!!" On 2015-01-28 13:09, Rowland Penny wrote: On 28/01/15 18:55, Bob of Donelson Trophy wrote: No, I did not try the alterations but, Louis had me remove the "domain users" line earlier. Put the line back in and try alterations? (If so, I will not have time until you are asleep, tonight.) By all means try it, you have nothing to lose :-) I take it that 'wbinfo -u' shows all the domain users on the member server and 'wbinfo -g' shows all the domain groups. Also 'getent passwd <domain user> shows the user. Rowland > Links: ------ [1] http://www.donelsontrophy.com [1] > > What I should also have said, if what 'wbinfo -u' & 'wbinfo -g' is > displaying is *all* your domain users, then *none* of your users need a > 'uidNumber' and only 'Domain Users' & 'Domain Admins' need a > 'gidNumber'. > > Try adding a new user and then give this user a 'uidNumber' > > Rowland > > > Links: > ------ > [1] http://www.donelsontrophy.comAGHHH I have done it again :-) Posting without thinking :-D I did mean what I posted, you don't seem to have any other users other than the default ones and these users do not need a 'uidNumber'. If you have given these users, including Administrator, a 'uidNumber' remove them, then create another user to test with and give this user a 'uidNumber' Rowland
Bob of Donelson Trophy
2015-Jan-29 21:44 UTC
[Samba] W7 client cannot adjust file permissions via ADUC
Okay, so I have not given any of the "default ones" (your words) users a uidNumber.So, nothing to remove, I assume. Where do I create a new user? W7 client with RSAT tools on DC01? Samba-tools? (In the past with other test setups, created users on the DC, which is a no-no, I know. So, creating new user outside of RSAT tool is new to me.) --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] "Everyone deserves an award!!" On 2015-01-29 15:33, Rowland Penny wrote:> On 29/01/15 21:21, Bob of Donelson Trophy wrote: > Rowland, I think you have confused my email with a different thread. Uhm . . what? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] "Everyone deserves an award!!" On 2015-01-29 07:30, Rowland Penny wrote: On 29/01/15 12:54, Bob of Donelson Trophy wrote: Rowland, I have tried your various alteration suggestions and it is a "negative" result. Here is the output from wbinfo -u & wbinfo -g root at dtmbr01:~# wbinfo -u administrator dns-dtdc02 dns-dtdc01 krbtgt guest root at dtmbr01:~# wbinfo -g allowed rodc password replication group enterprise read-only domain controllers denied rodc password replication group read-only domain controllers group policy creator owners ras and ias servers domain controllers enterprise admins domain computers cert publishers dnsupdateproxy domain admins domain guests schema admins domain users dnsadmins root at dtmbr01:~# getent passwd Administratoradministrator:*:50001:50006::/home/samba/DT***RM/users/administratorSERNAME%:/bin/bash Say what, "administratorSERNAME%"? After running the 'generation one' script to create the member server, I have changed nothing except the suggestions that have been made on this mailing list. Attempting to gain access to the member server to re-adjust the file permissions on "profiles" per the instructions on the samba wiki. Please, thoughts? --- ------------------------- Bob Wooden of Donelson Trophy 615.885.2846 (main) www.donelsontrophy.com [1] [1 [1]] [1 [1]] "Everyone deserves an award!!" On 2015-01-28 13:09, Rowland Penny wrote: On 28/01/15 18:55, Bob of Donelson Trophy wrote: No, I did not try the alterations but, Louis had me remove the "domain users" line earlier. Put the line back in and try alterations? (If so, I will not have time until you are asleep, tonight.) By all means try it, you have nothing to lose :-) I take it that 'wbinfo -u' shows all the domain users on the membe r server and 'wbinfo -g' shows all the domain groups. Also 'getent passwd <domain user> shows the user. Rowland Links: ------ [1] http://www.donelsontrophy.com [1] [1 [1]] What I should also have said, if what 'wbinfo -u' & 'wbinfo -g' is displaying is *all* your domain users, then *none* of your users need a 'uidNumber' and only 'Domain Users' & 'Domain Admins' need a 'gidNumber'. Try adding a new user and then give this user a 'uidNumber' Rowland Links: ------ [1] http://www.donelsontrophy.com [1] AGHHH I have done it again :-) Posting without thinking :-D I did mean what I posted, you don't seem to have any other users other than the default ones and these users do not need a 'uidNumber'. If you have given these users, including Administrator, a 'uidNumber' remove them, then create another user to test with and give this user a 'uidNumber' Rowland Links: ------ [1] http://www.donelsontrophy.com
Seemingly Similar Threads
- W7 client cannot adjust file permissions via ADUC
- Fwd: Re: W7 client cannot adjust file permissions via ADUC
- W7 client cannot adjust file permissions via ADUC
- W7 client cannot adjust file permissions via ADUC
- W7 client cannot adjust file permissions via ADUC