[Samba] Samba4 Trusts and GPO

Vladimir Eltsov samba at veltsov.ru
Thu Apr 13 12:28:16 UTC 2017

Any news about trust relationships or plans?

I have set up DC on CentOS 7 and samba 4.6.2, and another DC (with
another domain) on Windows server 2012 R2.

Then I have established trust relationships between two domains, and
just after that I see Event ID 1110 in Windows 7 (which is member of
samba domain) event log:

"The processing of Group Policy failed. Windows could not determine if
the user and computer accounts are in the same forest. Ensure the user
domain name matches the name of a trusted domain that resides in the
same forest as the computer account."

When I delete trust relationships on samba domain side, Group Policy
immediately starts working.

Does anybody use samba 4 AD DC with trust relationships and Group Policies?

Vladimir Eltsov

25.10.2016 22:44, lingpanda101 via samba пишет:
> Trust support is still considered experimental per the wiki.
> https://wiki.samba.org/index.php/FAQ#Trust_Support
> One of the limitations is "You cannot add users and groups of a
> trusted domain into domain groups." This may be applicable to your issue.
> On 10/24/2016 9:59 PM, Владимир Ельцов via samba wrote:
>> Really nobody uses Samba 4 AD with trust relationships and GPOs?

More information about the samba mailing list