similar to: samba-tool gpo aclcheck error

Displaying 20 results from an estimated 2000 matches similar to: "samba-tool gpo aclcheck error"

2015 Dec 28
3
Wrong ACL on GPO
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello, I use Samba 4.3.3 and Rowland it dosn't metter if I build it by my self or install tehe SerNet-Packages ;-) Everytime I craete a new GPO or change something in an existing GPO, the test with "samba-tool ntacl sysvolcheck" fails with the following Error: - ---------------- ERROR(<class
2017 Apr 25
1
"This security ID may not be assigned as the owner of this object" when trying to create a GPO
I have upgraded Samba from a NT PDC to an AD DC about a week ago. Everything went pretty well until today. I've already configured about 25 GPO's (through RSAT on a Windows 10 machine) - but when I came to add more GPO's - it wouldn't let me with the above error message. My specs are: Samba 4.5.0 Slackware -current 64bit Kernel 4.4.20 The client machine is a Windows 10 Pro.
2016 Nov 26
2
Everyone ACL problem
Hello list, I have problems with my PDC Samba Servers and all file servers. All DC Server have a compiled Samba 4.4.5. File servers have Samba Debian packages. In all shared folders, the ACL has the group "Everyone" and I can't remove it. The biggest problem concern SYSVOL, I can't modify GPO, I have an error in MMC. I have tried to resolv the problem with the
2015 Jun 12
1
samba 4.1.13 not applying domain policy in windows XP clients
Hello, i configured group policy via RSAT in my samba 4.1.13 implementation the policy applies correctly to my windows 7 clients but not to my windows XP clients. when i run gpupdate /force in windows XP it replies that the policies are apply correctly .... when i run ./samba-tool ntacl sysvolcheck ERROR(<class 'samba.provision.ProvisioningError'>): uncaught exception -
2015 Dec 28
2
Wrong ACL on GPO
On 28/12/15 10:07, L.P.H. van Belle wrote: > Hai Stefan, > > If you look from within windows, are you sysvol rights ok? > If so, just ignore these message. > There think there is nothing wrong with your sysvol rights, old bug imo. > > Greetz, > > Louis > > > > >> -----Oorspronkelijk bericht----- >> Van: samba [mailto:samba-bounces at
2015 Jun 17
3
samba tool and sysvol/gpo checks error/bugged? ( but it all works ok)
Hai, ? im running samba 4.2.2 sernet on debian. ? when i run : samba-tool gpo aclcheck -UAdministrator ? im getting : ERROR: Invalid GPO ACL O:DAG:DAD:PAI(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED) and it tells me it should be O:DAG:DAD:P?
2016 Nov 26
1
Everyone ACL problem
Yes, I have. But nothing change... Kevin Le 26/11/2016 à 12:08, Rowland Penny via samba a écrit : > On Sat, 26 Nov 2016 11:44:50 +0100 > Kévin GUERINEAU via samba <samba at lists.samba.org> wrote: > >> Hello list, >> >> I have problems with my PDC Samba Servers and all file servers. >> All DC Server have a compiled Samba 4.4.5. File servers have Samba
2017 May 23
3
classic upgrade, splitting servers
Am 2017-05-23 um 20:16 schrieb Rowland Penny: >> Can I reset that somehow manually? > > If you are adding GPOs, then yes, by never running sysvolreset. I only did that after sysvolcheck failed! And I still get these problems in the GPO-management. I translate via googling: "A processing error occurred collecting data using this base domain controller." this one ?
2017 Mar 07
2
Problem sysvolreset
Hi guys! I´m experiencing a problem with samba 4 policies and acl and i don´t known how it starded to do. Some problems like copy Policies, edit them, etc. It seems like permissions, but i´ve checked the list and can´t find a solution. Here are some outputs that i hope can help to understand: # Sysvol permissions: drwxrwxrwx+ 3 root DOMAIN\domain admins 4096 Mar 7 12:17 sysvol #
2020 May 19
2
sysvolcheck and sysvolreset errors
> You could try using a script Louis wrote, see here: > https://github.com/thctlo/samba4/blob/master/samba-check-set-sysvol.sh > > The 'idmap config' lines are nothing to worry about, you cannot set them on a DC, but, for some reason, testparm etc warns about > them. > > Rowland > Sorry, I should have said - I ran louis' script and set the acl's according
2020 May 19
2
sysvolcheck and sysvolreset errors
I have a samba DC based on Debian Buster running samba 4.12.2 from Louis' repo. A second DC on Raspbian buster is running samba 4.12.0. I have sysvol replication working using rsync/unison as per the WiKi. I wasn't having any issues until I tried to edit a GPO and found that all the acl settings had disappeared. This may have happened when I upgraded the DCs from 4.11.x to 4.12.x
2018 Dec 27
5
After upgrade to 4.9.4, internal DNS no longer working
On Thu, 27 Dec 2018 11:07:08 +0100 "L.P.H. van Belle via samba" <samba at lists.samba.org> wrote: > Gooood morning Rowland, :-) > > Your late ;-).. > What i also did see, so its more clear for others also. > > > Dez 22 21:08:31 dc1 systemd[1]: Starting Samba AD Daemon... > > Dez 22 21:08:31 dc1 kernel: audit: type=1131 > >
2016 Jul 24
3
Samba 4.2.14 GPO issue
Dear All, I've recently upgrade from samba 4.1.x to samba 4.2.14 and found that GPO are having issue Specifically when I'm adding new using they *never *got the gpupdate success fully. When I run samba-tool ntacl sysvolcheck or samba-tool ntacl sysvolreset But don't seem to got it fix.. Any suggestion? Thank in advance. #samba-tool ntacl sysvolcheck Processing section
2020 Oct 25
2
GPO fail and sysvol perm errors
On Sun, Oct 25, 2020 at 3:31 PM Rowland penny via samba <samba at lists.samba.org> wrote: > OK, if you look at the end of the permissions, there is a '+' sign, this > shows that extended acls set, to see these: > > getfacl /usr/local/samba/var/locks/sysvol The difference in acls is that the non-working domain includes: user:3000001:r-x user:3000002:rwx user:3000003:r-x
2020 Oct 25
2
GPO fail and sysvol perm errors
On Sun, Oct 25, 2020 at 4:24 PM Rowland penny via samba <samba at lists.samba.org> wrote: > Yes, that is what it is designed for. Yes, and yes it does! Thank you!!
2016 Jul 21
3
gpo not working with samba 4 migrated
Hi, First of all thanks for you answer, it seems that this can help, now some change made to gpo are applied and we are not receiving error in event viewer, but seem that some change are not applied, why and where I can find some information, in samba log anv event viewer any error is reported Also I have tried # samba-tool ntacl sysvolreset After this tried # samba-tool ntacl sysvolcheck
2013 Jan 10
1
ACL on GPO directory does not match expected value from GPO object. AGAIN.
Hi all, Some (then all) of our workstations were complaining about incorrect ACLs on GPOs and were unable to read the gpt.ini to apply the GPOs. So I did a sysvolcheck and sure enough I'd lost the ACLs when I moved our sysvol share to a new location on the server (whoops, mea culpa). I ran a sysvolreset which took a long time to return (some 5 minutes, please see my post on slow winbind
2016 Apr 22
3
Samba 4.4.2 "samba-tool ntacl sysvolreset" is not working correctly
Samba 4.4.2 I was doing some maintenance work and I noticed that sysvolcheck gave some error. I ran "samba-tool ntacl sysvolreset". Running sysvolcheck again still gives errors. I tried with several sysvol backups and the result is always the same. The affected policies are always "Default Domain Policy" and "Default Domain Controllers Policy". These policies
2020 Oct 28
1
GPO fail and sysvol perm errors
For completeness: The existing GPO: # samba-tool ntacl get --as-sddl \{07AF723D-5FFD-4807-B3C6-DFCE911B922A\}/ O:DAG:DAD:P(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED) The newly created GPO: # samba-tool ntacl get --as-sddl \{0C0B713E-EE65-4ACE-88AE-25125E2AAE00\}/
2013 Oct 09
2
GPO Permissions _AGAIN_
Hi all, I'm afraid I'm back to my old issue of GPO permissions. I have two ADDCs providing an AD Domain (internal.stmaryscollege.co.uk (short-name 'SMC')). Servers are called 'ad-01' and 'tainan'. ad-01 is 'Version 4.0.10' and tainan is 'Version 4.1.0rc4' (the latest version in the package repos of the respective OSs (arch and gentoo)) I have