Hi! I have a problem with gpupdate having a trust with a M$ -ADS domain. Before creating the trust gpupdate worked fine. Then i added the trust and then gpupdate gives the following error: Updating policy... Computer Policy update has completed successfully. User Policy could not be updated successfully. The following errors were encount ered: The processing of Group Policy failed. Windows could not determine if the user a nd computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer ac count. ----------- The trust works fine (i can authenticate trusted users on a PC in my samba domain and viceverse) Details of the Trust: samba-tool domain trust show klingons LocalDomain Netbios[GVCC] DNS[gvcc.net] SID[S-1-5-21-1608159440-4144762864-1017073214] TrusteDomain: NetbiosName: KLINGONS DnsName: klingons.imp SID: S-1-5-21-3288560663-12659786-2782445548 Type: 0x2 (UPLEVEL) Direction: 0x3 (BOTH) Attributes: 0x8 (FOREST_TRANSITIVE) PosixOffset: 0x00000000 (0) kerb_EncTypes: 0x4 (RC4_HMAC_MD5) Namespaces[2] TDO[klingons.imp]: TLN: Status[Enabled] DNS[*.klingons.imp] DOM: Status[Enabled] DNS[klingons.imp] Netbios[KLINGONS] SID[S-1-5-21-3288560663-12659786-2782445548] Regards, Heinz
Has someone else a domain with a trust to a othe domain? Does work all fine regarding gpo? Thanx! Am Mittwoch, 17. Februar 2016 15:17 CET, Heinz Hölzl <heinz.hoelzl at gvcc.net> schrieb:> Hi! > > I have a problem with gpupdate having a trust with a M$ -ADS domain.> > Before creating the trust gpupdate worked fine. Then i added the trust and then gpupdate gives the following error: > > > Updating policy... > > Computer Policy update has completed successfully. > User Policy could not be updated successfully. The following errors were encount > ered: > > The processing of Group Policy failed. Windows could not determine if the user a > nd computer accounts are in the same forest. Ensure the user domain name matches > the name of a trusted domain that resides in the same forest as the computer ac > count. > > ----------- > > The trust works fine (i can authenticate trusted users on a PC in my samba domain and viceverse) > > Details of the Trust: > samba-tool domain trust show klingons > LocalDomain Netbios[GVCC] DNS[gvcc.net] SID[S-1-5-21-1608159440-4144762864-1017073214] > TrusteDomain: > > NetbiosName: KLINGONS > DnsName: klingons.imp > SID: S-1-5-21-3288560663-12659786-2782445548 > Type: 0x2 (UPLEVEL) > Direction: 0x3 (BOTH) > Attributes: 0x8 (FOREST_TRANSITIVE) > PosixOffset: 0x00000000 (0) > kerb_EncTypes: 0x4 (RC4_HMAC_MD5) > Namespaces[2] TDO[klingons.imp]: > TLN: Status[Enabled] DNS[*.klingons.imp] > DOM: Status[Enabled] DNS[klingons.imp] Netbios[KLINGONS] SID[S-1-5-21-3288560663-12659786-2782445548] > > > > Regards, > > Heinz > > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba-- Heinz Hölzl EDV-Abteilung | Ripartizione EDP Südtiroler Gemeindenverband Genossenschaft Consorzio dei Comuni della Provincia di Bolzano Societá Cooperativa I – 39100 Bozen – Kanonikus-Michael-Gamper-Straße 10 I – 39100 Bolzano – via Canonico Michael Gamper 10
Hi, now i found a bug-report on https://bugzilla.samba.org/show_bug.cgi?id=11517 The problem still exists on samba 4.4.0rc3. let's hope the best ....> Hi! > > I have a problem with gpupdate having a trust with a M$ -ADS domain.> > Before creating the trust gpupdate worked fine. Then i added the trust and then gpupdate gives the following error: > > > Updating policy... > > Computer Policy update has completed successfully. > User Policy could not be updated successfully. The following errors were encount > ered: > > The processing of Group Policy failed. Windows could not determine if the user a > nd computer accounts are in the same forest. Ensure the user domain name matches > the name of a trusted domain that resides in the same forest as the computer ac > count. > > ----------- > > The trust works fine (i can authenticate trusted users on a PC in my samba domain and viceverse) > > Details of the Trust: > samba-tool domain trust show klingons > LocalDomain Netbios[GVCC] DNS[gvcc.net] SID[S-1-5-21-1608159440-4144762864-1017073214] > TrusteDomain: > > NetbiosName: KLINGONS > DnsName: klingons.imp > SID: S-1-5-21-3288560663-12659786-2782445548 > Type: 0x2 (UPLEVEL) > Direction: 0x3 (BOTH) > Attributes: 0x8 (FOREST_TRANSITIVE) > PosixOffset: 0x00000000 (0) > kerb_EncTypes: 0x4 (RC4_HMAC_MD5) > Namespaces[2] TDO[klingons.imp]: > TLN: Status[Enabled] DNS[*.klingons.imp] > DOM: Status[Enabled] DNS[klingons.imp] Netbios[KLINGONS] SID[S-1-5-21-3288560663-12659786-2782445548] > > > > Regards, > > Heinz > > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba