[Samba] strange gpo behaviour

Ray Klassen julius_ahenobarbus at yahoo.co.uk
Wed Apr 17 18:02:58 UTC 2019

On 2019-04-17 5:49 a.m., James Atwell via samba wrote:
> On 4/16/2019 6:00 PM, Ray Klassen via samba wrote:
>> -- 3 samba 4.10.2 DC's, binaries compiled from tarballs on Debian stretch
>> -- 2 DC's are on the same (main office) LAN, one is at another 
>> location vpn'ed to the main office
>> -- randomly windows 10 pc's will not be able to complete a gpupdate 
>> (repeated tries) with no consistency as to solutions. Sometimes the 
>> pc's can't connect to the \\dc\sysvol\local.somedomain.com
>> -- we've tried (and thought we had it)
>>     -- samba-tool ntacl sysvolreset
>>     -- synchronizing time (again) between servers, and between servers 
>> and pc's
>>     -- rebooting pc's
>> sometimes any of these measures seem to suddenly work and then not.
>> any pointers?
>> Ray
> How are you synchronizing sysvol?
rsync as prescribed by the wiki.

Actually we might have found the problem. There were some stale dns 
records, especially A records that resolve the domain itself, pointing 
to a non-existent DC. also a whole slew of other records that existed 
for two of the dc's but not the third we had recently installed. so a 
major dns edit may have fixed the issue. I will update this if the 
problem is completely gone.

More information about the samba mailing list