[Samba] More AD DC Questions - GPO Issues

Nick Couchman Nick.Couchman at seakr.com
Wed Nov 13 11:54:51 MST 2013

Another question related to Samba 4 as an Active Directory DC (with other Windows DCs present).  I'll mention that I am using rsync to synchornize the sysvol share between the Windows-based DCs and the Linux-based DCs, so the GPO objects should be consistent across all of the DCs.  When I try to do a "gpupdate" on my Windows 7 Pro/Enterprise clients, I am frequently receiving the following message:

"The processing of Group Policy failed.  Windows could not determine if the user and computer accounts are in the same forest.  Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account."

Anyone know why this is happening, or where I should start debugging?  I'm not sure why it's having trouble matching computer and user domains, since the computer is in the domain, I can successfully authenticate to the domain, and can attach to other computers in the domain.  Any pointers/help in tracking down the problem would be greatly appreciated.


This e-mail may contain SEAKR Engineering (SEAKR) Confidential and Proprietary Information.  If this message is not intended for you, you are strictly prohibited from using this message, its contents or attachments in any way.  If you have received this message in error, please delete the message from your mailbox.  This e-mail may contain export-controlled material and should be handled accordingly.

More information about the samba mailing list