Displaying 20 results from an estimated 5000 matches similar to: "Samba 4.2.11 Group Policy (GPO) sync error"
2016 Aug 03
3
Samba 4.2.14 Group Policy (GPO) sync error
Hello,
I think I really need some help on this.
Since Samba 4.2.11 upgrade my Windows 10 clients are unable to synchronize group
policies. I have asked about this already here
<https://lists.samba.org/archive/samba/2016-April/199226.html>. Now I
re-investigate the issue with Windows 10 1607 update and still face the same
issue which prevents me from rolling out this configuration in
2016 Aug 03
5
Samba 4.2.14 Group Policy (GPO) sync error
Can you run on a failing computer :
- netdom verify yourpcname
- nslookup yourpcname
All ok?
And is time in sync?
Did you install winbind after the update and also and did you change you server services line?
Like, i use bind9 dns
My smb.conf contains only this : server services = -dns
The full line is :
samba-tool testparm -vv | grep "server service"
2016 Aug 04
3
Samba 4.2.14 Group Policy (GPO) sync error
Forgot one extra.
On the win 10, check this reg key.
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Hostname
It states you hostname here, but if its not in caps change it to HOSTNAME
In that register key. (HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters)
You should see also you dnsdomain at Domain and NV Domain.
NV Hostname should be in CAPS also.
The domains not.
2016 Aug 04
2
Samba 4.2.14 Group Policy (GPO) sync error
Hello Louis,
Thanks for your reply.
> No, your output is not good.
So let's have a look.
> >C:\Temp>netdom verify cyb64w10-monster
> >The format of the specified computer name is invalid.
> Thats not good.
Well, it quite clearly states the format is invalid. If I use the the FQDN of
the AD domain it works fine. The DNS search is also including the AD domain as
2016 Apr 16
1
I can not access the DNS using dns management utility
I tried the version 4.2.11 and will not let me access the DNS via RSAT,
I changed several permissions in several ways and does not allow me
access will be a bug?
if i try to browse dns from a windows2003 dns management utility in
log.samba i got the following message:
[2016/04/16 09:39:45.296046,
2] ../source4/rpc_server/dcerpc_server.c:1275(dcesrv_request)
dcesrv_request: restrict
2016 Aug 03
0
Samba 4.2.14 Group Policy (GPO) sync error
The server expects TLS but you didnt set tls.
Read :
https://www.samba.org/samba/history/samba-4.2.10.html
basicly its now : Default: ldap server require strong auth = yes
You can try to add: ldap server require strong auth = no
But i do advice to setup the TLS parameters and make everything more secure.
Please read these links, MS change some things in GPO also.
MS16-072: Security
2016 Aug 03
0
Samba 4.2.14 Group Policy (GPO) sync error
> Can you run on a failing computer :
> - netdom verify yourpcname
It seems to work only with FQDN:
C:\Temp>netdom verify cyb64w10-monster
The format of the specified computer name is invalid.
The command failed to complete successfully.
C:\Temp>netdom verify cyb64w10-monster.ad.cyberdyne.local
The secure channel from CYB64W10-MONSTER.AD.CYBERDYNE.LOCAL to the domain
CYBERDYNE
2016 Aug 04
0
Samba 4.2.14 Group Policy (GPO) sync error
Hai,
No, your output is not good.
>C:\Temp>netdom verify cyb64w10-monster
>The format of the specified computer name is invalid.
Thats not good.
> C:\Temp>nslookup cyb64w10-monster
> Server: UnKnown
> Address: fdea:5b48:d4c1:1:1::6
Also not good.
If you resolving is setup correct both should work.
netdom verify cyb64w10-monster
and
netdom verify
2016 Aug 04
2
Samba 4.2.14 Group Policy (GPO) sync error
On Thu, 4 Aug 2016 12:02:18 +0200
rme at bluemail.ch wrote:
> > Well, I am using IPv6 mainly for all services and don't want to
> > disable it. Though I might try this temporary which will be quite a
> > bunch of reconfiguration to disable IPv6 in all services. So I will
> > come back with results on this later.
>
> I have completely disabled IPv6 on the server
2016 Apr 20
0
Samba 4.2.11 Group Policy (GPO) sync error
Hi,
You said your client can't resolve the domain controllers any more. Do you
made tests using "dig" or "nslookup" to be sure there is an issue with your
DNS system?
If you did and if there is really a DNS issue, I would start checking
rights on keytab(s) used by your Bind(s).
Checking logs would be a good option too. Bind and Samba logs.
2016-04-19 15:04 GMT+02:00
2016 Apr 06
5
GPO
Hi All,
I create a Samba domain and works it's great, the issue that I have is with the GPO's.When applying GPO's then only the computer Policy is applied and not the user GPO. I keep on receiving below error.
Has anybody else perhaps been experiencing the same issues?
C:\>gpupdate /force
Updating Policy...
User policy could not be updated successfully. The following errors were
2016 Aug 03
2
Samba 4.2.14 Group Policy (GPO) sync error
Hi Louis,
Many many thanks for your very quick and comprehensive reply.
I also found this thread here
<https://lists.samba.org/archive/samba/2016-July/201471.html>
Unfortunately none of the suggestions seem to entirely resolve the issue.
As a first work-around I have inserted
ldap server require strong auth = no
to my smb.conf and re-started Samba.
Unfortunately this didn't
2016 Jul 24
3
Samba 4.2.14 GPO issue
Hello Sébastien Le Ray,
The PC reply the following...
The processing of Group Policy failed. Windows could not resolve the user
name. This could be caused by one or more of the following:
a) Name Resolution failure on the current domain controller.
b) Active Directory Replication Latency (an account created on another
domain controller has not replicated to the current domain controller).
The
2016 Aug 04
0
Samba 4.2.14 Group Policy (GPO) sync error
>I actually also thought Windows does not care
> about
> case sensitivity and for hostnames by default it shouldn't matter.
Thats correct but if windows is buggy..
Source : https://support.microsoft.com/nl-nl/kb/2891966
It was worth a try..
https://support.microsoft.com/en-us/kb/2954031
for the status rapport error, one you can check also.
I see still something incorrect
2016 Aug 03
1
Samba 4.2.14 GPO issue
Dear Sébastien,
Sorry for the delay,
Please check on the log below.
As for the word "存取被拒。" it should translate to Access Deny...
Please help.
- <Event xmlns="*http://schemas.microsoft.com/win/2004/08/events/event
<http://schemas.microsoft.com/win/2004/08/events/event>*">
- <System>
<Provider Name="*Microsoft-Windows-GroupPolicy*"
2023 Aug 11
2
GPO not getting updated on Windows 10
Hi,
Our Domain controller environment is working for over 6 years without a
break. It started with Samba Version 4.6.5 and today running 4.18.5. We
have only Windows 10 clients across our organisation.
Off late, we have observed that GPOs are not getting updated when we
change some GPOs and link them to some specific OUs. For example,
previously, we had not allowed one specific network path
2016 Apr 07
2
GPO
Hi Louis,
See below,
C:\>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : EBEN-TEST-PC
Primary Dns Suffix . . . . . . . : domain.corp
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : domain.corp
Ethernet adapter Local Area Connection:
2016 Aug 09
2
Samba 4.2.14 Group Policy (GPO) sync error
Am 09.08.2016 um 22:18 schrieb Achim Gottinger via samba:
>
>
> Am 09.08.2016 um 21:48 schrieb Rainer Meier via samba:
>>> I think the 10.0.06 entry was created during domain creation. I'd skim
>>> thru dns records from an windows machine if possible and delete all
>>> occurences of unwanted ip adresses. I assume the gpo's still can not be
>>>
2019 Jul 26
4
GPO issues - getting SYSVOL cleaned up again
new thread, old issue
been fiddling off-list with tips from Louis over the last days, and
putting it back to the list to ask for help from others:
2 samba-4.9.11 DCs
1 samba-4.8.12 DM file server
GPOs not working cleanly anymore
tried to resync completely etc etc
-
right now I test gpupdate/gpresult on an older (not productive) W2008R2
server which I use for editing stuff via RSAT/MMC
I
2003 Mar 13
4
gpedit.msc as centralized policy for 2k/xp clients
John,
> I would like to figure out how to do this
> gpedit.msc+AD+gpc+gpt magic for
> win2k/xp with linux+samba(2.2/3.0/tng)+openldap and is it possible at
> all?
We use local (!) GPOs on our Win2k clients with great success:
- log on to "master" workstation as administrator
- create a link to the "C:\WINNT\system32\GroupPolicy" folder on your
administrator's