Displaying 20 results from an estimated 1000 matches similar to: "Error with "samba-tool ntacl get --as-sddl""
2016 May 18
1
Error with "samba-tool ntacl get --as-sddl"
> Hi, this is because when you use '--as-sddl', the python code does this:
>
> if as_sddl:
> try:
> domain_sid = security.dom_sid(samdb.domain_sid)
> except:
> raise CommandError("Unable to read domain SID from
> configuration files")
>
2003 Mar 06
1
ACL bug FIXes for get_nt_acl()
Two attached patches for samba 2.2.7a and 3.0-alfa22,
that I've made today, fix 3 bugs mentioned in my previous e-mail.
1) For each file in addition to ALLOW ACE
proper DENY ACE is created.
2) "Take ownership" is shown DENIED for all except root ACEs
3) Read Permissions and read attributes are always shown as allowed,
as they are actually allowed.
--
Zhitomirsky
2018 Aug 22
1
samba-tool dsacl set fails with "Unknown flag"
Hi,
i was not able to find anything about my issue in the bug-tracker,
the mailinglist or the release notes. We see the following issue
using samba-tool dsacl:
samba-tool dsacl set --objectdn "cn=srv-client-99,cn=CoreBizClients,cn=Netzwerk,ou=muc,DC=coreboso,DC=de" --sddl='(A;CI;GA;;;DD)'
new descriptor for
2012 Sep 24
4
samba4: samba-tool and (unix) uids
Hello,
at my universities CS computer pools we're trying to migrate our
samba3 based NT domain to AD with samba4-rc1.
In the past we had a little script which our users could run on their
own from their linux account which created a samba user with
their own uid/gid and set their password (via smbpasswd).
We're trying to recreate this behaviour with "samba-tool user create"
2014 May 27
1
ERROR in samba-tool ntacls get
Hi,
the command "samba-tool ntacl get --as-sddl" always returns
"ERROR: Unable to read domain SID from configuration files"
Does this command only work in AD-DC mode?
Is there another way to transfer the complete ntacl info in Linux from
one file to others?
I'm using Samba 4.1.6 of Ubuntu 14.04 with
server role = classic primary domain controller
vfs objects = acl_xattr
2020 Oct 28
1
GPO fail and sysvol perm errors
For completeness:
The existing GPO:
# samba-tool ntacl get --as-sddl \{07AF723D-5FFD-4807-B3C6-DFCE911B922A\}/
O:DAG:DAD:P(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED)
The newly created GPO:
# samba-tool ntacl get --as-sddl \{0C0B713E-EE65-4ACE-88AE-25125E2AAE00\}/
2023 Nov 29
1
Setting up Profiles share... 777?!
Mandi! Rowland Penny via samba
In chel di` si favelave...
>> acl_xattr:default acl style = windows
>> acl_xattr:ignore system acls = yes
> Why have you added those two last lines ?
Ahem, really you need an answer?! ;-)
I don't remember... ;-(((
>> What i'm missing?! Thanks.
> Well, because you have added this line:
> acl_xattr:ignore system
2020 Oct 28
2
GPO fail and sysvol perm errors
>
> However the acls via getfacl for the two GPO's are identical.
Your sure?
> I don't know if that will be problematic down the road or not.
No, thats fine.
But run on the 2 folders :
samba-tool ntacl get --as-sddl FOLDERHERE
Compair the 2 outputs.
There must be a difference.
Well, at least it works now for you..
Greetz,
Louis
2019 Jul 15
3
SAMBA AD DC - Windows explorer.exe crashes on security tab access
I experienced a Windows Explorer crash in https://lists.samba.org/archive/samba/2019-July/224346.html as well...
Try samba-tool ntacl sysvolreset (or check first).
Joachim Lindenberg
-----Urspr?ngliche Nachricht-----
Von: Rowland penny <rpenny at samba.org>
Gesendet: Monday, 15 July 2019 10:24
An: samba at lists.samba.org
Cc: Jeremy Allison <jra at samba.org>
Betreff: Re: [Samba]
2023 Apr 02
1
Inconsistent SYSVOL ACLs
On 02/04/2023 09:21, Michael Tokarev via samba wrote:
> Neither of the 3 should be a problem. Especially the ones which
> are already set by default.? --enable-fhs uses slightly different
> layout within $prefix, that's all. The build-time configuration
> looks entirely okay.
You may be correct Michael, but I still wouldn't use '--enable-fhs' by
itself.
>
>
2017 Mar 21
3
Problem sysvolreset
Hai,
Here you go my output of the R2008R2. (64bit)
1) original GPO from the install ( the domain controller policy )
Path : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SYSVOL\domain\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}
Owner : BUILTIN\Administrators
Group : NT AUTHORITY\SYSTEM
Access : CREATOR OWNER Allow 268435456
NT AUTHORITY\Authenticated Users
2023 Mar 28
1
windows acls
On 28/03/2023 19:47, Peter Carlson via samba wrote:
>
> On 3/28/23 11:22, Rowland Penny via samba wrote:
>>
>>
>> On 28/03/2023 18:43, Peter Carlson via samba wrote:
>>> bumping the log to 5, there are a few more lines right before
>>> NT_STATUS_ACCESS_DENIED, could the EA error be a clue?
>>
>> I do not think so, that is what you are trying
2023 Nov 28
1
Setting up Profiles share... 777?!
On Tue, 28 Nov 2023 16:00:22 +0100
Marco Gaiarin via samba <samba at lists.samba.org> wrote:
>
> In a fresh samba AD domain i'm setting up the 'Profiles' share for
> roaming profiles, following the wiki:
>
> https://wiki.samba.org/index.php/Roaming_Windows_User_Profiles
> https://wiki.samba.org/index.php/Setting_up_a_Share_Using_Windows_ACLs
>
>
2020 Jul 01
4
Users, home directories and profiles
> root at localhost:~# getfacl /home/samba/users/
> getfacl: Removing leading '/' from absolute path names
> # file: home/samba/users/
> # owner: root
> # group: root
> user::rwx
> group::rwx
> other::rwx
> root at localhost:~# samba-tool ntacl get /home/samba/users --as-sddl
>
2023 Apr 02
2
Inconsistent SYSVOL ACLs
First of all thank you all for the answers and for trying to help me.
I agree with you michael regarding the parameters passed in the ./configure
command, the location is not part of the problem.
The file system used is XFS. and the strace command logs are in the
attached link
https://drive.google.com/file/d/1R_b6TzeJVmNIpnlkPfRk0CtkpeU4dgcg/view?usp=share_link
Rowland, the result of the
2018 Aug 24
3
Samba fileserver member corrupt smb.ldb after joining 4.8.4 Samba DC
Hello,
I'm trying to join a samba-fileserver to a 4.8.4 Domain Controller. Both
are installed from the Debian Unstable Sources.
I've setup some scripts that allows me to provision the latest
samba-version for testing purposes on two VMs. The following configs where
working absolutly fine when provisioning a Samba-DC version 4.7.3 and I was
able to do profile roaming, but since the DC is
2020 Jul 01
3
Users, home directories and profiles
On 01.07.2020 13:35, Rowland penny via samba wrote:
> On 01/07/2020 12:15, Robi. T. Wagner via samba wrote:
>>> root at localhost:~# getfacl /home/samba/users/
>>> getfacl: Removing leading '/' from absolute path names
>>> # file: home/samba/users/
>>> # owner: root
>>> # group: root
>>> user::rwx
>>> group::rwx
>>>
2013 Jan 10
2
Samba 4 "Services for UNIX"? [SOLVED]
To get the automount schema to work with the git checkout of samba 4 I had
to modify the automount schema files and separate the attributes from the
classes. I also discovered that it's required to have the
ntSecurityDescriptor , instanceType, and objectCategory attributes. Without
these it will crash whenever you try to browse... I did alot of stopping
samba, tarring of /usr/local/samba and
2020 Jul 01
3
Users, home directories and profiles
On 01/07/2020 09:03, Enrico Morelli wrote:
> On Wed, 1 Jul 2020 08:43:37 +0100
> Rowland penny via samba <samba at lists.samba.org> wrote:
>
>> On 01/07/2020 08:36, Enrico Morelli via samba wrote:
>>> On Tue, 30 Jun 2020 10:28:41 -0700
>>> Jeremy Allison via samba <samba at lists.samba.org> wrote:
>>>
>>>> On Tue, Jun 30, 2020 at
2019 Aug 27
3
Permissions at the top of a Samba share
Am 2019-08-26 um 16:35 schrieb Rowland penny via samba:
> On 26/08/2019 15:20, ? Peter Rindfuss via samba wrote:
>> Hi,
>>
>> I have a question regarding permissions at the top of a share as seen
>> from a Windows 10 client.
>>
>> We are using Samba 4.10.6-Debian (van Belle) on Debian 10 (Buster) with
>> one AD controller and one file server.
>>