[Samba] Missing Policies folder after failure; how to recreate

Marcel de Reuver marcel at de.reuver.org
Wed Jan 14 10:06:10 MST 2015


Quick solution can be copy the contents of the attached zipfile to:  /usr
/local/samba/var/locks/sysvol/domain.of/
Run the command: samba-tool ntacl sysvolreset

You will end up without any GPO's and look at https://wiki.samba.org/index.
php/Backup_and_Recovery to get backups of your Samba installation!!

Regards, Marcel


2015-01-13 21:09 GMT+01:00 "Gergely, Kaszás" <cheese at caesar.elte.hu>:

> Dear Samba List!
>
> Long story short and please just don't ask; if it were up to me this would
> have not happened:
>
> I need to recreate the default GPO-s (as in the
> \SysVol\domain.of\Policies\ folder and subfolders) of my domain.
> Trying to delete the old GPO-s I run into errors, both in the windows mmc
> and on the dc with runing samba-tools as root.
> ERROR(ldb): uncaught exception - LDAP error 50 LDAP_INSUFFICIENT_ACCESS_RIGHTS
> -  <dsdb_access: Access check failed on CN={97A64DB0-B51D-4A70-80A3-
> 7F47483B0EB2},CN=Policies,CN=System,DC=domain,DC=of > <>
>   File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py", line
> 175, in _run
>
> Reprovisioning is not an option; since this is an active, "in use" system
> with lots of accounts.
> The moment this is solved I swear to make a second DC with sysvol
> replication.
>
> Thank you!
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>


More information about the samba mailing list