Displaying 20 results from an estimated 20000 matches similar to: "Domain Admin can't create GPO"
2016 Feb 17
3
Gpo issue
Hi everybody!
I have two samba AD server ( 4.2.7-SerNet-Debian-8.wheezy ). I try to
make gpo working but I'm facing some problems...
My Samba4 comes from an old windows AD so I have launch these command :
samba-tool dbcheck --cross-ncs --reset-well-known-acls --fix
samba-tool ntacl sysvolreset ( that take about 10 minutes to complete )
samba-tool dbcheck --cross-ncs --fix
But the
2018 Mar 14
3
sysvolreset - open: error=40 (Too many levels of symbolic links)
hi folks,
After run *samba-tool ntacl sysvolreset *the below error occurs. I not
remember of make any modification directly on the server. I only manager
via rsat.
root at dc3:/etc/samba# samba-tool ntacl sysvolreset
*open: error=40 (Too many levels of symbolic links)*
ERROR(runtime): uncaught exception - (-1073741823, '{Operation Failed} The
requested operation was unsuccessful.')
2018 Mar 14
2
sysvolreset - open: error=40 (Too many levels of symbolic links)
Hello Louis,
I use your apt for samba. Great works btw!! :D
root at dc3:/etc/samba# samba -V
Version 4.7.3-Debian
root at dc3:/etc/samba# lsb_release -a
No LSB modules are available.
Distributor ID: Debian
Description: Debian GNU/Linux 9.2 (stretch)
Release: 9.2
Codename: stretch
Did you upgrade, if so, from .. To ... Samba version ?
No upgrades.
And why was running : samba-tool ntacl
2019 Apr 16
5
strange gpo behaviour
-- 3 samba 4.10.2 DC's, binaries compiled from tarballs on Debian stretch
-- 2 DC's are on the same (main office) LAN, one is at another location
vpn'ed to the main office
-- randomly windows 10 pc's will not be able to complete a gpupdate
(repeated tries) with no consistency as to solutions. Sometimes the pc's
can't connect to the \\dc\sysvol\local.somedomain.com
--
2018 Jul 30
4
gpupdate /force not applied
The principle was not made any changes to occur this problem.
We infra have dc3 and dc4 ADDC.
root at dc3:/etc/samba# samba -V
Version 4.7.7-Debian (van-blle apt)
Result of gpupdate /force in a joined computer client:
C:\>gpupdate /force
> Updating Policy...
> User policy could not be updated successfully. The following errors were
> encountered:
> The processing of Group Policy
2014 May 23
1
Cannot edit GPO's anymore via RSAT
Hello all,
I have recently discovered that my user cannot edit GPO's anymore. Every
GPO I try to open, gets me the famous window "*The permissions for this GPO
in the SYSVOL folder are inconsistent with those in Active Directory" * and
then I get another window saying "Access is denied".
I believe that this happened when I upgraded to 4.1.7 from 4.1.3, about 3
weeks ago,
2015 Nov 16
6
Win Clients and DNS
On 16.11.2015 14:44, Rowland Penny wrote:
> On 16/11/15 13:25, Ole Traupe wrote:
>>
>>
>> Am 16.11.2015 um 14:06 schrieb Viktor Trojanovic:
>>>
>>>
>>> On 16.11.2015 13:48, Viktor Trojanovic wrote:
>>>> See replies below
>>>>
>>>> On 16.11.2015 12:39, Rowland Penny wrote:
>>>>> On 16/11/15 11:19,
2017 Feb 06
3
gpupdate use wrong url
When I do an gpupdate /force a wrong url is used.
\\foo\SysVol\foo\Policies\{89E....}\gpt.ini
ON my dc the path (in explorer) is
\\dc1\sysol\foo\Policies\{89E....}\gpt.ini
or
\\dc1.foo\sysol\foo\Policies\{89E....}\gpt.ini
whats wrong?
2018 Dec 27
5
After upgrade to 4.9.4, internal DNS no longer working
On Thu, 27 Dec 2018 11:07:08 +0100
"L.P.H. van Belle via samba" <samba at lists.samba.org> wrote:
> Gooood morning Rowland, :-)
>
> Your late ;-)..
> What i also did see, so its more clear for others also.
>
> > Dez 22 21:08:31 dc1 systemd[1]: Starting Samba AD Daemon...
> > Dez 22 21:08:31 dc1 kernel: audit: type=1131
> >
2018 Mar 29
2
Failed to find DC in keytab, gpupdate fails
Hi,
I suggest you post this to samba at list.samba.org that more for these questions.
Try this setting in resolv.conf
search domain.net.pl
nameserver 10.1.10.11 # IP of DC itself.
#nameserver # and extra nameserver that has access to the DC dns info. (a second dc maybe)
nameserver 8.8.8.8 # IP of forwarder in SMB.conf as backup for internet access.
# and max 3 nameservers in
2016 Nov 26
2
Everyone ACL problem
Hello list,
I have problems with my PDC Samba Servers and all file servers.
All DC Server have a compiled Samba 4.4.5. File servers have Samba
Debian packages.
In all shared folders, the ACL has the group "Everyone" and I can't
remove it.
The biggest problem concern SYSVOL, I can't modify GPO, I have an error
in MMC.
I have tried to resolv the problem with the
2017 Sep 04
2
BUILTIN\Administrators - failed to call wbcSidToUid: WBC_ERR_DOMAIN_NOT_FOUND
Hello everyone.
I'm trying to fix sysvol rights, because i see errors in output of
/usr/bin/samba-tool ntacl sysvolcheck
ERROR(<class 'samba.provision.ProvisioningError'>): uncaught exception
- ProvisioningError: DB ACL on GPO directory
/var/lib/samba/sysvol/samdom.svmetal.cz/Policies/{6AC1786C-016F-11D2-945F-00C04FB984F9}
2013 Feb 14
1
Should I run dbcheck and sysvolreset when upgrading 4.0.0 to 4.0.3?
Hello,
Is it necessary or recommended to run 'samba-tool dbcheck --cross-ncs
--fix' and 'samba-tool ntacl sysvolreset' when upgrading from 4.0.0 to
4.0.3?
2018 Nov 25
3
No good way to migrate 4.1 on Server A to 4.7.6 on New Server B
Hi Rowland,
The old server is Debian 3.2.101-1 running a compiled-from-source Samba 4.1.0. The new server I'm trying to migrate to is Ubuntu Server 18.04LTS, running a package-installed (apt) Samba 4.7.7.
Old server name: isofs 10.4.0.2
New server name: isofs2 10.4.0.3
Domain: ISO.PRIVATE
smb.conf:
[global]
netbios name = ISOFS2
realm = ISO.PRIVATE
server role = active directory domain
2025 Apr 08
1
Access denied on GPO after "ntacl sysvolreset"
Hello.
samba --version
Version 4.19.5-Ubuntu
Samba as Active Directory controller.
2 scenarios.
# First scenario :
* On a Windows client, from RSAT, I create a new GPO named "firstgpo".
* Still in RSAT, I then create a second GPO "scndgpo" with some
parameters that I backup (right clic on the GPO => Backup...).
* Then I right clic on "firstgpo" and select
2018 Jul 23
4
sysvolreset error '{Operation Failed} The requested operation was unsuccessful.'
When I run samba-tool ntacl sysvolreset on my "secondary" Samba AD DC I
get the error:
---
ERROR(runtime): uncaught exception - (-1073741823, '{Operation Failed}
The requested operation was unsuccessful.')
File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py",
line 176, in _run
return self.run(*args, **kwargs)
File
2016 Nov 26
1
Everyone ACL problem
Yes, I have. But nothing change...
Kevin
Le 26/11/2016 à 12:08, Rowland Penny via samba a écrit :
> On Sat, 26 Nov 2016 11:44:50 +0100
> Kévin GUERINEAU via samba <samba at lists.samba.org> wrote:
>
>> Hello list,
>>
>> I have problems with my PDC Samba Servers and all file servers.
>> All DC Server have a compiled Samba 4.4.5. File servers have Samba
2024 Oct 13
1
samba-tool domain backup offline fails.
Try this maintenance procedures and report back:
http://samba.bigbird.es/doku.php?id=samba:dc-maintenance
?? ?Find and delete ?tombstone? items
samba-tool domain tombstones expunge --tombstone-lifetime=0
?? ?Check domain databases and automatically fix things.
samba-tool dbcheck --cross-ncs --fix --yes
On 12 Oct 2024 at 18:53 +0100, Carlos Jesus via samba <samba at lists.samba.org>,
2018 Mar 29
2
Failed to find DC in keytab, gpupdate fails
what is the output of "kvno dc.domain.net.pl"? There seems to be
mismatch kvno of the secrets keytab, and what is client expecting (kvno
2). Kvno increments by 1 for every password change. Was there by any
chance password change for the dc$ account and keytab was not recreated?
If You made some upgrades, maybe during process You for example rejoined
the domain (that would set new
2016 Jul 24
3
Samba 4.2.14 GPO issue
Dear All,
I've recently upgrade from samba 4.1.x to samba 4.2.14 and found that GPO
are having issue
Specifically when I'm adding new using they *never *got the gpupdate
success fully.
When I run samba-tool ntacl sysvolcheck or samba-tool ntacl sysvolreset
But don't seem to got it fix..
Any suggestion?
Thank in advance.
#samba-tool ntacl sysvolcheck
Processing section