Displaying 20 results from an estimated 7000 matches similar to: "Verification on different issues"
2015 Jan 22
2
Windows users can't change password 4.1.6
Hello,
When PDC was installed I remember that everybody could change thair passwords after first 24h after password reset via admin console.
(I remamber that I was searching for this and even if GPO was min 0 days for changing password you had to wait)
Anyway... Now noone is able to change password.
When GPO tells you to change password after 30days, or you want to change it; typing old
2015 Jan 15
0
Verification on different issues
Hello Tim,
Am 15.01.2015 um 20:33 schrieb Tim:
> I'd like to know if the following issues happen to you too.
>
> 1. Sysvol permissions
> After I edited a GPO with a user which is member of domain Admins, sysvolcheck runs on an error due to security settings of thisvedited GPO. Running sysvolreset makes it all for he again
What version of Samba are you running?
I have 4.1.12 in
2015 Dec 08
4
Confusion about account locking policy (Samba AD/Windows 7 client)
Hi,
here on the wiki
https://wiki.samba.org/index.php/FAQ#Is_it_possible_to_set_user_specific_password_policies_in_Samba4_.28e._g._on_a_OU-base.29.3F
I read this:
"Is it possible to set user specific password policies in Samba4 (e.
g. on a OU-base)?
Samba can't handle GPO restrictions. You have to use 'samba-tool domain
passwordsettings' to change password policies.
2016 Jun 04
3
"Samba cannot handle GPO restrictions"
Hi list,
Today, I spent most of the day figuring out why my password policies set
via GPO are not applied on a domain level, just to find out that this is
not one of the many occasions where Windows is the problem but it's really
Samba, for a change. Apparently, password policies can only be changed
using samba-tool and not via GPO.
IMO, the FAQ is not very clear here.
2014 Sep 06
2
samba4 GPO passw
Hi list, well, i create a new gpo (rsat tools) and try to find password
policies to define all stuff like time, complexity, etc but dont here
where normaly are!..cant find from any gpo create password policies!...i
personalize a search into gpo but nothing appears...normaly in windows
ad this policies are in security settings....
any suggestion?
2015 Dec 08
2
Confusion about account locking policy (Samba AD/Windows 7 client)
As far as I understand Samba and the wiki in this regard, the Samba4
DC's password policy is no typical domain policy (no GPO). It can't be
inherited by Windows clients. So I suspect the full story to be:
- on the Unix side (DC and member server) the Samba password rules apply
- on the Windows client side the inherited Windows POLICIES apply (as
far as possible)
In effect, if e.g.
2013 Jun 13
1
Problems adding domain policies in debian 7 with samba4.0.6
Hi once again my greetings I rewrite because I'm in the same situation
but this time in debian 7 using samba4.0.6. The account lockout policy
does not work, got help from some colleagues but nothing I fail to solve
the problem, I have recommended using Zentyal 3.0 but it's my favorite
distro is debian and do not feel right changing. This time I used a
Windows 7 client and I
2014 Sep 04
4
can't turn off password complexity requirements
Hello,
I'm unsing Ubuntu 14.4 Server and samba 4.1.6-Ubuntu. Everything
works great but I somehow fail to switch off the password complexity
requirements. It is not unlikely that this is because I'm very
unexperienced with Windows. I've heard that the password-settings are
always a bit tricky and I did exactly what the windows-tutorials say.
I've tried gpresult for
2014 Oct 01
2
Domain Functionality Level and GPO password policies
Hi guys,
I've been trying to work out how to set a GPO that allows certain
Groups (Domain Users) a password expiry of 60 days and another group
(Domain admins) an expiry of 30 days, but when looking through the
Group Policy Manager I don't see how to achieve this.
After looking around online I stumbled across the domain Functionality
Level which if I understand means that I have to
2015 Feb 11
1
Samba 4 GPO - Account Policy
Hello,
I installed samba4 on an debian server with dc provisioning.
If I create an default policy that is linked to the domain and set the
Account Lockout Policy to e.g. 5 thresholds, it does not work.
My question: I this Policy supported by samba and if it is supported how can
I apply these.
I also tried on other systems like openSUSE 13.2 and Ubuntu 14.04.
And I also tried an
2018 Feb 06
2
GPOs not Working!
On Tue, 6 Feb 2018 15:03:16 -0400
Robert Marcano via samba <samba at lists.samba.org> wrote:
> Thanks for the information, to use a default GPO was a simple way to
> try to encourage someone to reproduce the problem.
>
> I already created new GPOs (this is a test domain) Using the default
> filter for a new GPO, "Authenticated users", creating a new group for
2017 Aug 24
4
sysvolreset doesn't reset all ACLs
> root at graz-dc-1b:~# samba --version
> Version 4.5.8-Debian
> root at graz-dc-1b:~# samba-tool ntacl sysvolreset && echo "no error"
> no error
> root at graz-dc-1b:~# samba-tool ntacl sysvolcheck
> ERROR(<class 'samba.provision.ProvisioningError'>): uncaught exception - ProvisioningError: DB ACL on GPO directory
2017 Aug 24
3
sysvolreset doesn't reset all ACLs
On 2017-08-24 12:27, Rowland Penny via samba wrote:
> On Thu, 24 Aug 2017 12:03:42 +0200
> Sven Schwedas via samba <samba at lists.samba.org> wrote:
>
>>> root at graz-dc-1b:~# samba --version
>>> Version 4.5.8-Debian
>>> root at graz-dc-1b:~# samba-tool ntacl sysvolreset && echo "no error"
>>> no error
>>> root at
2020 May 20
2
sysvolcheck and sysvolreset errors
> >
> Yes, There are three places where permissions are stored on sysvol (4 if you count in AD), the standard Linux permissions 'ugo',
POSIX
> ACLs as shown by getfacl and an EA (this is where the ACLs are stored when set from Windows).
>
> Try running 'samba-tool ntacl get /var/lib/samba/sysvol --as-sddl', this should produce something similar to this:
>
2018 May 25
4
syscolcheck error / Could not convert sid S-1-5-32-544 to uid
On Fri, 25 May 2018 15:07:57 +0100
Rowland Penny via samba <samba at lists.samba.org> wrote:
> > running "samba-tool ntacl sysvolcheck" doesn't fix this.
>
> Well it wouldn't, they are both borked.
>
> Just do administration from Windows
OK, maybe this is something which should be mentioned in the wiki. The
reason I got to this was that I wanted to
2017 Jun 16
2
Erro sysvolcheck/sysvolreset
I run the sysvolreset by without it when I duplicate the gpo (rsync)
problems occurs later on windows machines perform the same on the DC
that received the copy ....
Regards....
Em 16-06-2017 15:08, Rowland Penny via samba escreveu:
> Mine looks similar, but I am/was trying to get samba-tool to work
> correctly so there are some differences. Did you know that 'Domain
>
2017 Jul 06
4
Can't create/update Group Policy in Samba 4.6.5
Hi,
My DC doesn't know domains users and groups by name, only by uid/gid.
Ex: chmod mike:'EMPRESA\unix_admins' test
chown: invalid group mike:EMPRESA\\unix_admins
if run with GID work properly
chmod mike:30059 test
drwxr-xr-x 2 root 30059 4096 Jul 6 00:17 test
There is unix_admins group
wbinfo --gid-info 30059
EMPRESA\unix_admins:x:30059:
In File Server Domain Member
2016 Jul 21
3
gpo not working with samba 4 migrated
Hi,
First of all thanks for you answer, it seems that this can help, now some
change made to gpo are applied and we are not receiving error in event
viewer, but seem that some change are not applied, why and where I can find
some information, in samba log anv event viewer any error is reported
Also I have tried
# samba-tool ntacl sysvolreset
After this tried
# samba-tool ntacl sysvolcheck
2016 Jul 22
2
gpo not working with samba 4 migrated
On 21/07/16 22:18, Trenta sis wrote:
> I'm not sure what are you deatiling, is a bug in progress taht can cause
> this random problems with some gpos or this error can be ignored?
>
> 2016-07-21 20:37 GMT+02:00 Trenta sis <trenta.sis at gmail.com>:
>
>> Hi,
>>
>> First of all thanks for you answer, it seems that this can help, now some
>> change
2017 May 23
2
classic upgrade, splitting servers
Am 2017-05-23 um 19:38 schrieb Rowland Penny:
>> So it sounds like I should raise that level?
>>
>
> You shouldn't need to, lets start with your new DCs smb.conf
set a VM snapshot and raised it already :-P
-
Right now I think I screwed up the default policies somehow
ntacl sysvolreset works
ntacl sysvolcheck ... throws error (hard to paste right now as the
test-LAN is