[Samba] SYSVOL ACLs and GPOs

Andrew Bartlett abartlet at samba.org
Fri Oct 26 03:48:58 MDT 2012


On Fri, 2012-10-26 at 09:36 +0200, Olivier BILHAUT wrote:
> Hi Andrew, Hi Alex,
> 
> Pleased to see that you figured this out.
> We've got exactly the same problem from a blank provisioned domain (not 
> a migration), with a setup with 2 gpo. (Ubuntu 12.04 - S4 rc3).
> Since our instance is in a semi-production environment, we'll wait for 
> your fix. But if needed, we could give you more level 10 logs.
> 
> Note that when the sysvolreset is launched and that sysvolcheck returns 
> no errors, then the windows clients can't "gpupdate" anymore on some gpo.
> Note also that when syslvolreset isn't launched at S4 update, the 
> sysvolcheck command return the Alex's error but the client can update 
> their gpo.

This I think is the umask issue I addressed with this patch.  A
sysvolreset with this patch applied should fix that.  steve noticed that
permissions were missing from the posix ACL that was generated.

(this patch is in master)

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org

-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0002-pysmbd-Set-umask-to-0-during-smbd-operations.patch
Type: text/x-patch
Size: 3679 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba/attachments/20121026/e78a8ea7/attachment.bin>


More information about the samba mailing list