[Samba] DC2 denies ac­cess­ whe­n sa­ving throu­gh th­e Gro­up Po­licy M

?icro MEGAS micromegas at mail333.com
Sat Nov 1 14:06:15 MDT 2014


> OK, make sure that the two idmap.ldb files match and then run 
> 'samba-tool ntacl sysvolreset' on both machines and see if this cured 
> this problem.

I did:

root at dc1:~$ service sernet-samba-ad stop
root at dc2:~$ service sernet-samba-ad stop
root at dc2:~$ mv /var/lib/samba/private/idmap.ldb /root/idmap.ldb.bak
root at dc1:~$ scp /var/lib/samba/private/idmap.ldb dc2:/var/lib/samba/private/

then I ensured that /var/lib/samba/private/idmap.ldb is exactly the same on dc1 and dc2. then...

root at dc1:~$ samba-tool ntacl sysvolreset
root at dc2:~$ samba-tool ntacl sysvolreset
root at dc1:~$ service sernet-samba-ad start
root at dc2:~$ service sernet-samba-ad start

to be sure again I execute the sysvolreset command...

root at dc1:~$ samba-tool ntacl sysvolreset
root at dc2:~$ samba-tool ntacl sysvolreset

but when I execute "samba-tool ntacl sysvolcheck" I still get the uncaught exception error on dc1 and dc2 :(


More information about the samba mailing list