[Samba] samba-tool gpo aclcheck error

L.P.H. van Belle belle at bazuin.nl
Wed Dec 11 00:41:15 MST 2013


Hai, 

Same error here. 

samba-tool gpo aclcheck
ERROR(runtime): uncaught exception - (-1073741766, 'NT_STATUS_OBJECT_PATH_NOT_FOUND')
  File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py", line 175, in _run
    return self.run(*args, **kwargs)
  File "/usr/lib/python2.7/dist-packages/samba/netcmd/gpo.py", line 1148, in run
    fs_sd = conn.get_acl(sharepath, security.SECINFO_OWNER | security.SECINFO_GROUP | security.SECINFO_DACL, security.SEC_FLAG_MAXIMUM_ALLOWED)

samba 4.1.3 ( sernet ) 
Ubuntu 12.04 64Bit. 

also.. 

getcifsacl /home/samba/DOMAIN/sysvol/
getcifsacl: error while loading shared libraries: libwbclient.so.0: cannot open shared object file: No such file or directory 

locate libwbclient.so.0
/usr/lib/x86_64-linux-gnu/samba/libwbclient.so.0
/usr/lib/x86_64-linux-gnu/samba/libwbclient.so.0.11

but.. 
getfacl /home/samba/DOMAIN/sysvol/
getfacl: Removing leading '/' from absolute path names
# file: home/samba/DOMAIN/sysvol/
# owner: root
# group: root
user::rwx
user:root:rwx
group::---
group:root:---
group:3000000:rwx
group:3000012:r-x
group:3000018:r-x
group:3000019:rwx
mask::rwx
other::---
default:user::rwx
default:user:root:rwx
default:group::---
default:group:root:---
default:group:3000000:rwx
default:group:3000012:r-x
default:group:3000018:r-x
default:group:3000019:rwx
default:mask::rwx
default:other::---



Greetz, 

Louis
 

>-----Oorspronkelijk bericht-----
>Van: samba at marc-muehlfeld.de 
>[mailto:samba-bounces at lists.samba.org] Namens Marc Muehlfeld
>Verzonden: woensdag 11 december 2013 8:01
>Aan: David Minard; samba at lists.samba.org
>Onderwerp: Re: [Samba] samba-tool gpo aclcheck error
>
>Hello David,
>
>Am 11.12.2013 02:15, schrieb David Minard:
>> samba-tool gpo aclcheck
>>
>> ERROR(<type 'exceptions.KeyError'>): uncaught exception - 
>'No such element'
>>   File 
>"/usr/local/samba/lib64/python2.6/site-packages/samba/netcmd/__
>init__.py", line 175, in _run
>>     return self.run(*args, **kwargs)
>>   File 
>"/usr/local/samba/lib64/python2.6/site-packages/samba/netcmd/gp
>o.py", line 1150, in run
>>     ds_sd_ndr = m['nTSecurityDescriptor'][0]
>
>https://bugzilla.samba.org/show_bug.cgi?id=9922
>
>
>Do your GPOs work correct and you simply want to check the 
>ACLs? Or are 
>there any problems?
>
>
>I tried the command in my 4.1.0 test environment and 4.1.2 production. 
>There the command works (at least I don't get this error, but see an 
>invalid ACL, but it is the same on production and test environment):
># samba-tool gpo aclcheck
>ERROR: Invalid GPO ACL 
>O:DAG:DAD:(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001200a9;;;ED)(A;OI
>CI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;OICI;0x001200a9;;
>;AU)(A;OICI;0x001f01ff;;;SY)(A;OICI;;;;WD)(A;;0x001f01ff;;;DA)(
>A;OICIIO;0x001f01ff;;;CO)(A;OICIIO;;;;CG) 
>on path 
>(samdom.example.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}), 
>should be 
>O:DAG:DAD:P(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01ff;;;EA)(A;O
>ICIIO;0x001f01ff;;;CO)(A;OICI;0x001f01ff;;;DA)(A;OICI;0x001f01f
>f;;;SY)(A;OICI;0x001200a9;;;AU)(A;OICI;0x001200a9;;;ED)
>
>Can you switch to 4.1?
>
>
>Regards,
>Marc
>
>
>-- 
>To unsubscribe from this list go to the following URL and read the
>instructions:  https://lists.samba.org/mailman/options/samba
>
>



More information about the samba mailing list