[Samba] Domain trust and GPO

Karel Lang AFD lang at afd.cz
Tue Oct 14 12:55:52 MDT 2014

i can not speak for samba4, i'm not there yet, but i had similar message 
after migration in Samba3 when users SID (RID) were changed and were not 
in accord with RIDs still contained in the NTUSER.DAT files that held 
their old SID-RIDs...

not sure if this helps, but anyway :]

On 10/14/2014 03:39 PM, Владимир Ельцов wrote:
> Hi all.
> I am testing samba4 AD for my organisation.
> Almost all is ok, except trusts.
> When I setup trust on Samba4 domain side, at once GPO stops working.
> In windows event log on the domain members I see error with event id 1110:
> "The processing of Group Policy failed. Windows could not determine if
> the user and computer accounts are in the same forest. Ensure the user
> domain name matches the name of a trusted domain that resides in the
> same forest as the computer account."
> When I delete trust - GPO starts working.
> Can anyone help me with this issue?
> Thanks in advance

*Karel Lang*

More information about the samba mailing list