Re: [Samba] Can't create/update Group Policy in Samba 4.6.5
- Date: Mon, 3 Jul 2017 09:29:51 +0200
- From: "L.P.H. van Belle via samba" <samba@xxxxxxxxxxxxxxx>
- Subject: Re: [Samba] Can't create/update Group Policy in Samba 4.6.5
In reponse to the why i recommend that.
Since this is a "windows" only share, i recomment to set it up for that usage, with results in better matching for windows rights.
Resulting in better working policies.
The current POSIX rights did not match to my needs and resulted in inconsistant policies.
This is why i use these for profiles and sysvol.
And this is my setup order:
setup the sysvol share with : acl_xattr:ignore system acls = yes
Setup SeDiskOperatorPrivilege. For sysvol, setup 2 ! Groups.
net rpc rights grant "SAMDOM\Domain Admins" SeDiskOperatorPrivilege -U "SAMDOM\administrator"
net rpc rights grant "SAMDOM\Group Policy Creator Owners" SeDiskOperatorPrivilege -U "SAMDOM\administrator"
And use the default windows group for extra users: "Group Policy Creator Owners"
Setup Share rights, (you must re-apply them if you use "ignore system acls" )
Setup Security rights, but since your using, "ignore system acls" the default sysvol rights are now ok.
But check if creator group also on the security rights.
Check from with GPO manament tools, you wil get some messages about rights to fix, do that.
And dont run samba-tools sysvolreset, if you do, then you wil have to repeat above again.
Now you GPO should work as normal.
Try it out and report your result.
> -----Oorspronkelijk bericht-----
> Van: samba [mailto:samba-bounces@xxxxxxxxxxxxxxx] Namens
> Stefan G. Weichinger via samba
> Verzonden: zondag 2 juli 2017 20:41
> Aan: samba@xxxxxxxxxxxxxxx
> Onderwerp: Re: [Samba] Can't create/update Group Policy in Samba 4.6.5
> Am 2017-07-02 um 17:26 schrieb Rowland Penny via samba:
> >> [sysvol]
> >> path = /usr/local/samba/var/locks/sysvol
> >> read only = No
> >> acl_xattr:ignore system acls = yes
> > You should remove the above line, it isn't required.
> Louis recommended that one to me a few weeks ago.
> Could you explain?
> To unsubscribe from this list go to the following URL and read the
> instructions: https://lists.samba.org/mailman/options/samba
To unsubscribe from this list go to the following URL and read the