[Samba] Samba 4.5.3 AD DC - issues with sysvol when setting up Group Policies

Rowland Penny rpenny at samba.org
Sun Jan 15 19:05:14 UTC 2017

On Sun, 15 Jan 2017 20:30:25 +0200
Richard via samba <samba at lists.samba.org> wrote:

> I remain baffled as to why richard.h cannot access the sysvol share. 
> Permissions all seem ok from what I can see and I'm not sure why this
> should be any different from normal AD share behaviour (our other
> shares are working fine for domain users)
> I would really appreciate it if someone could let me know whether the
> sysvol has become corrupt in some way and  I am wasting my time even
> trying to sort this out.
> thanks

I have thought about this and notice that you gave 'Domain Admins' a
gidNumber (which you have now removed), but 'getfacl' only showed the
number not the group name. This makes me wonder if you have set up the
libnss_winbind links etc. If you haven't, or don't know what I mean,
see here:



More information about the samba mailing list