Hi all. I have installed Samba 4.5.0 in CentOS 7 for testing Samba AD for my organisation. Almost all is OK, except trusts. When I setup trust on Samba4 domain side, at once GPO stops working. In windows event log on the domain members I see error with event id 1110: "The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account." When I delete trust - GPO starts working. Can anyone help me with this issue? Thanks in advance -- Владимир Ельцов
Really nobody uses Samba 4 AD with trust relationships and GPOs? -- Владимир Ельцов 13.10.2016, 11:10, "Владимир Ельцов via samba" <samba at lists.samba.org>:> Hi all. > I have installed Samba 4.5.0 in CentOS 7 for testing Samba AD for my organisation. > Almost all is OK, except trusts. > When I setup trust on Samba4 domain side, at once GPO stops working. > In windows event log on the domain members I see error with event id 1110: > "The processing of Group Policy failed. Windows could not determine if > the user and computer accounts are in the same forest. Ensure the user > domain name matches the name of a trusted domain that resides in the > same forest as the computer account." > When I delete trust - GPO starts working. > Can anyone help me with this issue? > Thanks in advance > > -- > Владимир Ельцов > > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba
Trust support is still considered experimental per the wiki. https://wiki.samba.org/index.php/FAQ#Trust_Support One of the limitations is "You cannot add users and groups of a trusted domain into domain groups." This may be applicable to your issue. On 10/24/2016 9:59 PM, Владимир Ельцов via samba wrote:> Really nobody uses Samba 4 AD with trust relationships and GPOs? >-- - James