[Samba] SYSVOL ACLs and GPOs

Andrew Bartlett abartlet at samba.org
Fri Oct 26 03:48:58 MDT 2012

On Fri, 2012-10-26 at 09:36 +0200, Olivier BILHAUT wrote:
> Hi Andrew, Hi Alex,
> Pleased to see that you figured this out.
> We've got exactly the same problem from a blank provisioned domain (not 
> a migration), with a setup with 2 gpo. (Ubuntu 12.04 - S4 rc3).
> Since our instance is in a semi-production environment, we'll wait for 
> your fix. But if needed, we could give you more level 10 logs.
> Note that when the sysvolreset is launched and that sysvolcheck returns 
> no errors, then the windows clients can't "gpupdate" anymore on some gpo.
> Note also that when syslvolreset isn't launched at S4 update, the 
> sysvolcheck command return the Alex's error but the client can update 
> their gpo.

This I think is the umask issue I addressed with this patch.  A
sysvolreset with this patch applied should fix that.  steve noticed that
permissions were missing from the posix ACL that was generated.

(this patch is in master)

Andrew Bartlett

Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org

-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0002-pysmbd-Set-umask-to-0-during-smbd-operations.patch
Type: text/x-patch
Size: 3679 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba/attachments/20121026/e78a8ea7/attachment.bin>

More information about the samba mailing list