Displaying 20 results from an estimated 20000 matches similar to: "Problem Groups GID Mappings"
2016 Oct 21
1
Problem Groups GID Mappings
> Apart from DC2 not having this line:
>
> idmap_ldb:use rfc2307 = yes
>
> Both smb.conf files look ok.
> Can you elaborate on your problem and show a few examples.
>
> Rowland
>
>
Surely the above line is required to obtain consistent UID, SID and name
mappings on all servers?
Can the OP try adding it to their DC2, restarting services, and check again?
I was
2016 Jun 21
2
Rights issue on GPO
Am 21.06.2016 um 10:41 schrieb lists:
> Hi Achim,
>
> On 21-6-2016 0:01, Achim Gottinger wrote:
>> Hi MJ and Rowland,
>>
>> I did abit of testing last week (two debian jesie servers with sernet
>> 4.2 samba packages). Seems when rsync is run against rsyncd or involved
>> via xinet as it is described in the wiki the user and group mapping does
>> not
2017 Sep 29
3
user cannot access shares on new ad-dc
> On 29.09.2017 11:44 Rowland Penny wrote:
> Have you set up the libnss_winbind links, PAM and /etc/nsswitch.conf ?
Yes, I had modified two lines in /etc/nsswitch.conf:
passwd: files winbind
group: files winbind
No, I had not seen a pointer to libnss, but now did
ln -s /usr/local/samba/lib/libnss_winbind.so.2 /lib/i386-linux-gnu/
ln -s
2018 Jun 14
4
Admin UID changed with upgrade to 4.8.2
On Thu, 14 Jun 2018 09:39:46 +0200
"L.P.H. van Belle via samba" <samba at lists.samba.org> wrote:
> And i did read the Comment to for Rowland below,
> On debian you need :
> libnss-winbind libpam-winbind to be installed.
> I think you miss one of these.
They are the glue that connects Samba to nsswitch and allows 'getent
passwd username' to work. Without
2016 Jun 20
3
Rights issue on GPO
Hi Rowland, list,
On 20-6-2016 20:04, Rowland penny wrote:
> If you are using Sernet 4.4.4 packages, you must have a Sernet
> subscription, you may get quicker help there.
Well I'm not sure this kind of support is included, but even if it were,
then others would not benefit from the dialogue with their support. :-)
> I was wrong, if you are using 4.2.0 or later, you do not need to
2016 Jun 27
2
Rights issue on GPO
On 26/06/16 12:43, Achim Gottinger wrote:
> Created an feature request
>
> "add resolving for well known security principals"
>
> https://bugzilla.samba.org/show_bug.cgi?id=11997
>
> Am 25.06.2016 um 12:35 schrieb Achim Gottinger:
>>
>>
>> Am 25.06.2016 um 02:21 schrieb Achim Gottinger:
>>>
>>>
>>> Am 24.06.2016 um 23:16
2016 Jun 27
6
Rights issue on GPO
Hai,
After lots of testing and checking today im must concluded that achim and mathias are right.
There are "BUILDIN\" security groups which make some GPOs are going wrong.
Also, im getting errors again with sysvolcheck. .. i was in the understanding this was resolved.. but im but off with all info, very buzy at the office atm.
samba-tool ntacl sysvolcheck
ERROR(<class
2016 Jun 25
4
Rights issue on GPO
Am 25.06.2016 um 02:21 schrieb Achim Gottinger:
>
>
> Am 24.06.2016 um 23:16 schrieb Achim Gottinger:
>>
>>
>> Am 24.06.2016 um 22:57 schrieb Rowland penny:
>>> On 24/06/16 21:35, Achim Gottinger wrote:
>>>>
>>>>
>>>> Am 24.06.2016 um 21:24 schrieb Rowland penny:
>>>>> On 24/06/16 19:47, lingpanda101 at
2016 Jun 14
3
since i added second DC i have some trouble
Hi,
i provisioned a domain and all went well, until i added the second dc....
for example:
the new DC2 tells me:
getfacl /usr/local/samba/var/locks/sysvol
# file: usr/local/samba/var/locks/sysvol
# owner: root
# group: BUILTIN\134administrators
user::rwx
user:root:rwx
user:BUILTIN\134administrators:rwx
user:BUILTIN\134users:r-x
user:ELEMAY\134guest:rwx
user:ELEMAY\134domain\040guests:r-x
2018 Nov 06
3
classicupgrade
Hai,
Ok, i expected a bit different outputs.
On my DC, i use /home/samba/sysvol and /home/samba/netlogon.
This is what i expected.
getfacl /home/samba/
getfacl: Removing leading '/' from absolute path names
# file: home/samba/
# owner: root
# group: BUILTIN\134administrators
user::rwx
user:root:rwx
group::rwx
group:BUILTIN\134administrators:rwx
2016 Jun 14
3
since i added second DC i have some trouble
On 6/14/2016 1:16 PM, Rowland penny wrote:
> On 14/06/16 17:38, J. Echter wrote:
>> Hi,
>>
>> i provisioned a domain and all went well, until i added the second
>> dc....
>>
>> for example:
>>
>> the new DC2 tells me:
>>
>> getfacl /usr/local/samba/var/locks/sysvol
>>
>> # file: usr/local/samba/var/locks/sysvol
>> #
2018 Nov 06
3
classicupgrade
Hello Luis
tomorrow i'm not in office, reply to you thursday
One question : who is owner and whats rights for dir
/home
/home/samba
/home/samba/sysvol
because, from windows client, user into domain admins, when i change in
security tab, explorer always crash
bye
Il 06/11/2018 17:16, L.P.H. van Belle via samba ha scritto:
> Ok, next,
>
> From a windows pc connect to
2017 Jan 13
1
Duplicate xidNumbers
Hello Samba team,
I have 3 production samba DCs version 4.5.1 serving the same domain (2
sites) and all are having the same problems, I believe based on two
duplicate xidNumbers described below.
xidNumbers 3000002 & 3000003 have two SIDs assigned while xidNumbers
3000011 & 3000012 have no SIDs assigned. Is fixing this as simple as
moving one of the duplicates to the empty xidNumber
2016 Jun 20
4
Rights issue on GPO
Hi all,
Following this thread with interest, as we are also having some issues
with GPO (they work on and off, unpredictably)
We checked iddap.ldb on the DCs and noticed differences between DCs.
We would like to ask some questions:
On 10-6-2016 9:26, Rowland penny wrote:
> Well, it is and it isn't, yes winbindd will display the user & group
> names for sysvol, but sysvol still
2018 Nov 06
5
classicupgrade
Hai,
I suggest, start reading here, it explains all.
https://lists.samba.org/archive/samba/2018-February/213690.html
The script in that thread is not changing anything by default.
I suggest try it and post the output.
Greetz,
Louis
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces at lists.samba.org] Namens
> Rowland Penny via samba
> Verzonden:
2017 Sep 29
7
user cannot access shares on new ad-dc
Hi,
I just installed a new AD-DC as described in the wiki.
Administrator can log on and see the two default-shares.
Then I used ADUC from RSAT to create an OU and a user.
User can see the shares (and can map them to a drive letter),
but is denied to look inside.
Same for another share which I added.
Even when administrator grants permission to everybody.
I read more wiki, which made me to add a
2016 Jun 10
2
Rights issue on GPO
Thank you all for these replies.
2016-06-10 9:26 GMT+02:00 Rowland penny <rpenny at samba.org>:
> On 10/06/16 07:52, Sébastien Le Ray wrote:
>
>> Hi
>>
>>
>> Le 09/06/2016 à 20:42, Rowland penny a écrit :
>>
>>> On 08/06/16 15:34, mathias dufresne wrote:
>>>
>>>> Hi all,
>>>>
>>>> [snip]
2016 Jun 14
1
since i added second DC i have some trouble
On 6/14/2016 2:50 PM, J. Echter wrote:
> Am 14.06.2016 um 20:47 schrieb lingpanda101 at gmail.com:
>> On 6/14/2016 1:16 PM, Rowland penny wrote:
>>> On 14/06/16 17:38, J. Echter wrote:
>>>> Hi,
>>>>
>>>> i provisioned a domain and all went well, until i added the second
>>>> dc....
>>>>
>>>> for example:
2016 Oct 05
4
Failure gpupdate
Colleagues,
I come to seek help to solve this problem. I use Samba 4.4.5.
I'm getting errors when running gpupdate / force on local desktops.
I get the following error:
User policy could not be updated successfully. The following errors were encountered:
The processing of Group Policy failed. Windows could not apply the registry-based policy settings for the Group Policy object
2016 Oct 05
3
Failure gpupdate
Dear James and Lingpanda
Here I have 2 DC's running. Everything was running perfectly.
The problem started after I started to rsync to synchronize the Sysvol folder between DC's.
I believe it is a permission problem in the GPO's or Sysvol folder.
Another detail. Even accessing the gpedit Group Polic Manager via RSAT using the Administrator User, I can no longer edit any GPO. I get