Displaying 20 results from an estimated 1000 matches similar to: "Problem sysvolreset"
2017 Mar 07
2
Problem sysvolreset
Hi Rowland.
But, samba automaticaly do this mapping.
root at server:/usr/local/src/samba-4.4.10# id 'domain admins'
uid=3000008(DOMAIN\domain admins) gid=3000008(DOMAIN\domain admins)
groups=3000008(DOMAIN\domain admins)
Because of this options in smb.conf:
winbind enum users = yes
winbind enum groups = yes
Can i remove this mapping only for domain admin group?
Thanks
2017-03-07
2020 May 19
2
sysvolcheck and sysvolreset errors
I have a samba DC based on Debian Buster running samba 4.12.2 from Louis' repo. A second DC on Raspbian buster is running samba
4.12.0. I have sysvol replication working using rsync/unison as per the WiKi. I wasn't having any issues until I tried to edit
a GPO and found that all the acl settings had disappeared. This may have happened when I upgraded the DCs from 4.11.x to 4.12.x
2016 Apr 22
3
Samba 4.4.2 "samba-tool ntacl sysvolreset" is not working correctly
Samba 4.4.2
I was doing some maintenance work and I noticed that sysvolcheck gave
some error. I ran "samba-tool ntacl sysvolreset". Running sysvolcheck
again still gives errors. I tried with several sysvol backups and the
result is always the same. The affected policies are always "Default
Domain Policy" and "Default Domain Controllers Policy". These policies
2020 May 19
0
sysvolcheck and sysvolreset errors
On 19/05/2020 17:09, Roy Eastwood via samba wrote:
> I have a samba DC based on Debian Buster running samba 4.12.2 from Louis' repo. A second DC on Raspbian buster is running samba
> 4.12.0. I have sysvol replication working using rsync/unison as per the WiKi. I wasn't having any issues until I tried to edit
> a GPO and found that all the acl settings had disappeared. This
2020 May 19
2
sysvolcheck and sysvolreset errors
> You could try using a script Louis wrote, see here:
> https://github.com/thctlo/samba4/blob/master/samba-check-set-sysvol.sh
>
> The 'idmap config' lines are nothing to worry about, you cannot set them on a DC, but, for some reason, testparm etc warns about
> them.
>
> Rowland
>
Sorry, I should have said - I ran louis' script and set the acl's according
2020 Oct 25
3
GPO fail and sysvol perm errors
On 25/10/2020 20:37, Sonic wrote:
> The reset allowed the current GPO to take effect, but right after
> adding a new GPO (just named it, no editing, or linking) the
> sysvolcheck fails:
> # samba-tool ntacl sysvolcheck
> ERROR(<class 'samba.provision.ProvisioningError'>): uncaught exception
> - ProvisioningError: DB ACL on GPO directory
>
2017 Aug 24
4
sysvolreset doesn't reset all ACLs
> root at graz-dc-1b:~# samba --version
> Version 4.5.8-Debian
> root at graz-dc-1b:~# samba-tool ntacl sysvolreset && echo "no error"
> no error
> root at graz-dc-1b:~# samba-tool ntacl sysvolcheck
> ERROR(<class 'samba.provision.ProvisioningError'>): uncaught exception - ProvisioningError: DB ACL on GPO directory
2016 Oct 03
0
Failure permission in Sysvol and GPO
Dear,
I'm having trouble handling GPO's my DC.
Environment:
Samba 4.4.5, primary and secondary DC.
I am not allowed to edit the GPO's.
The problem occurred after I edit the Default GPO in the primary DC, and then run the rsync to synchronize between the DC's.
The following errors arise when squeegee commands:
Note: I hid the actual domain name.
# samba-tool gpo aclcheck
2017 Aug 24
3
sysvolreset doesn't reset all ACLs
On 2017-08-24 12:27, Rowland Penny via samba wrote:
> On Thu, 24 Aug 2017 12:03:42 +0200
> Sven Schwedas via samba <samba at lists.samba.org> wrote:
>
>>> root at graz-dc-1b:~# samba --version
>>> Version 4.5.8-Debian
>>> root at graz-dc-1b:~# samba-tool ntacl sysvolreset && echo "no error"
>>> no error
>>> root at
2023 Oct 19
1
Error in samba-tool ntacl sysvolcheck
Hi!
I executed the command "samba-tool ntacl sysvolcheck" on a DC and I got the following I pasted below. The first DC was provisioned migrating from a samba NT4 PDC with an LDAP backend using the classic upgrade procedure. I haven't detected any problem but I wanted to make sure there isn't any problem I might not be seeing yet.
ERROR(<class
2020 Oct 25
2
GPO fail and sysvol perm errors
On Sun, Oct 25, 2020 at 3:31 PM Rowland penny via samba
<samba at lists.samba.org> wrote:
> OK, if you look at the end of the permissions, there is a '+' sign, this
> shows that extended acls set, to see these:
>
> getfacl /usr/local/samba/var/locks/sysvol
The difference in acls is that the non-working domain includes:
user:3000001:r-x
user:3000002:rwx
user:3000003:r-x
2013 Jan 10
1
ACL on GPO directory does not match expected value from GPO object. AGAIN.
Hi all,
Some (then all) of our workstations were complaining about incorrect
ACLs on GPOs and were unable to read the gpt.ini to apply the GPOs.
So I did a sysvolcheck and sure enough I'd lost the ACLs when I moved
our sysvol share to a new location on the server (whoops, mea culpa).
I ran a sysvolreset which took a long time to return (some 5 minutes,
please see my post on slow winbind
2015 Jun 17
3
samba tool and sysvol/gpo checks error/bugged? ( but it all works ok)
Hai,
?
im running samba 4.2.2 sernet on debian.
?
when i run :
samba-tool gpo aclcheck -UAdministrator
?
im getting :
ERROR: Invalid GPO ACL
O:DAG:DAD:PAI(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED)
and it tells me it should be
O:DAG:DAD:P?
2020 Oct 28
1
GPO fail and sysvol perm errors
For completeness:
The existing GPO:
# samba-tool ntacl get --as-sddl \{07AF723D-5FFD-4807-B3C6-DFCE911B922A\}/
O:DAG:DAD:P(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED)
The newly created GPO:
# samba-tool ntacl get --as-sddl \{0C0B713E-EE65-4ACE-88AE-25125E2AAE00\}/
2016 Jul 24
3
Samba 4.2.14 GPO issue
Dear All,
I've recently upgrade from samba 4.1.x to samba 4.2.14 and found that GPO
are having issue
Specifically when I'm adding new using they *never *got the gpupdate
success fully.
When I run samba-tool ntacl sysvolcheck or samba-tool ntacl sysvolreset
But don't seem to got it fix..
Any suggestion?
Thank in advance.
#samba-tool ntacl sysvolcheck
Processing section
2020 Oct 25
2
GPO fail and sysvol perm errors
On Sun, Oct 25, 2020 at 4:02 PM Rowland penny via samba
<samba at lists.samba.org> wrote:
> What do you mean by 'working domain' and 'non-working domain' ?
> Do you have two domains ?
Different sites, different companies, not related. The working one was
also a classic upgrade but earlier on, pre 4.6.x. Just using it to
compare.
> I am also trying to understand why
2014 Apr 08
1
Samba4 policies acl corruption
Hi everybody.
One month ago me migrated from samba 3.6 classic domain to samba4.
After solving some minor problems, we have found ourselves with a ACL
corruption and we don't know how to deal with this.
When accesing to our sysvol shared (for example, \\domain.local\sysvol)
from both Samba or Windows clients, we are refused to connect.
Domain=[VECTORSF] OS=[Unix] Server=[Samba 4.1.4]
2016 Jul 21
3
gpo not working with samba 4 migrated
Hi,
First of all thanks for you answer, it seems that this can help, now some
change made to gpo are applied and we are not receiving error in event
viewer, but seem that some change are not applied, why and where I can find
some information, in samba log anv event viewer any error is reported
Also I have tried
# samba-tool ntacl sysvolreset
After this tried
# samba-tool ntacl sysvolcheck
2014 May 13
1
GPO problems on a 4.1.6 AD, classicupgraded, uncaught exception
Hi all,
We'er running a classicupgraded samba4 AD 4.1.6 sernet for a month or
two now, and all is very well. :-) It has been classicupgraded using the
same 4.1.6.
Today I wanted to try GPO's and they are not applied. GPUpdate /force
tells me:
"Windows attempted to read the file blahblah\gpt.ini
from a domain controller and was not successful".
Taken from the mailinglist, I
2013 Oct 09
2
GPO Permissions _AGAIN_
Hi all,
I'm afraid I'm back to my old issue of GPO permissions.
I have two ADDCs providing an AD Domain (internal.stmaryscollege.co.uk
(short-name 'SMC')). Servers are called 'ad-01' and 'tainan'. ad-01 is
'Version 4.0.10' and tainan is 'Version 4.1.0rc4' (the latest version in
the package repos of the respective OSs (arch and gentoo))
I have