[Samba] Destroyed my samba4 domain

Mario Giammarco mgiammarco at gmail.com
Thu Feb 21 15:28:46 MST 2013

I am using samba4 with zentyal distro.
I am trying to have user homes mounted as W: and I am trying to use GPO.
I have spurious permissions problems.
I have fixed most of them with "samba-tool ntacl sysvolreset"
But some users write files and cannot see them anymore to read.
The biggest problem is that I have created group policies with Microsoft tools 
but they are not applied. I have looked at sysvol share and I cannot see logon 
dirs and my scripts so I suppose it is a permission problem.

So I have given this command: "samba-tool gpo aclcheck --fix" and it has found 
around 1700 errors ( I have more than 1000 users).

But now permissions are wrong: microsoft tools do not recognize the domain 
anymore and I cannot browse it anymore with \\domainname.lan\

Help me please!!!
What can I do?

I forgot to say that I have two domain controllers based on zentyal.

Thanks in advance for any help!

Mario Giammarco

More information about the samba mailing list