[Samba] Cannot add a new GPO opject at GPMC on win7

Yaroslav Yurta yaroslav.tarasovuch at gmail.com
Thu Jan 14 09:35:59 UTC 2016

Hi, guys!
Have some trouble with adding a new GPO.
If i add a new GPO it says me "The parametr is incorrect"

I use RSAT on win7.
I have an AD DC based on samba 4.1.14 on FreeBSD 10.1
Evrything else working fine/
Here is my smb.conf
# Global parameters
workgroup = DEVCOM
realm = DEV.COM.UA
netbios name = WIZARD
server role = active directory domain controller
#server services = rpc, nbt, wrepl, ldap, cldap, kdc, drepl, winbind,
ntp_signd, kcc, dnsupdate, dns, smb
#dcerpc endpoint servers = epmapper, wkssvc, rpcecho, samr, netlogon,
lsarpc, spoolss, drsuapi, dssetup, unixinfo, browser, eventlog6, backupkey,
dnsserver, winreg, srvsvc
idmap_ldb:use rfc2307 = yes
interfaces =
dns forwarder  =
time server = yes
logon drive = P:
domain logons = yes
logon home = \\wizard\netlogon\
logon script = set_ntp.bat

available = Yes
path = /var/db/samba4/sysvol/dev.com.ua/scripts
# read only = No
comment = The domain logon service
public = no
writeable = no
browsable = yes
locking = No

path = /var/db/samba4/sysvol
read only = No
When i try to run smb-tool ntacl sysvolcheck it says me:
/usr/local/bin/samba-tool ntacl sysvolcheck
ERROR(<class 'samba.provision.ProvisioningError'>): uncaught exception -
ProvisioningError: DB ACL on GPO directory /var/db/samba4/sysvol/
does not match expected value
from GPO object
  File "/usr/local/lib/python2.7/site-packages/samba/netcmd/__init__.py",
line 175, in _run
    return self.run(*args, **kwargs)
  File "/usr/local/lib/python2.7/site-packages/samba/netcmd/ntacl.py", line
249, in run
"/usr/local/lib/python2.7/site-packages/samba/provision/__init__.py", line
1726, in checksysvolacl
"/usr/local/lib/python2.7/site-packages/samba/provision/__init__.py", line
1677, in check_gpos_acl
    domainsid, direct_db_access)
"/usr/local/lib/python2.7/site-packages/samba/provision/__init__.py", line
1624, in check_dir_acl
    raise ProvisioningError('%s ACL on GPO directory %s %s does not match
expected value %s from GPO object' % (acl_type(direct_db_access), path,
fsacl_sddl, acl))


/usr/local/bin/samba-tool gpo listall
GPO          : {31B2F340-016D-11D2-945F-00C04FB984F9}
display name : Default Domain Policy
path         : \\dev.com.ua\sysvol\dev.com.ua
dn           :
version      : 2
flags        : NONE

GPO          : {6AC1786C-016F-11D2-945F-00C04FB984F9}
display name : Default Domain Controllers Policy
path         : \\dev.com.ua\sysvol\dev.com.ua
dn           :
version      : 0
flags        : NONE

/usr/local/bin/samba-tool gpo aclcheck
ERROR(<type 'exceptions.KeyError'>): uncaught exception - 'No such element'
  File "/usr/local/lib/python2.7/site-packages/samba/netcmd/__init__.py",
line 175, in _run
    return self.run(*args, **kwargs)
  File "/usr/local/lib/python2.7/site-packages/samba/netcmd/gpo.py", line
1150, in run
    ds_sd_ndr = m['nTSecurityDescriptor'][0]

I can not understand where is an error.


*----------З повагою!Юрта Ярослав Тарасович.*

More information about the samba mailing list