[Samba] Error when removing client from domain

von Obernitz, Daniel daniel.vonobernitz at uni-greifswald.de
Wed Apr 22 12:05:17 UTC 2020


when I remove a Windows client from the domain I get the following error message in log.samba:

[2020/04/21 13:06:11.453483,  1] ../../source4/rpc_server/samr/dcesrv_samr.c:4071(dcesrv_samr_SetUserInfo)
  Failed to modify record CN=DESKTOP-C9L2OUQ,CN=Computers,DC=ad,DC=example,DC=net: Object CN=DESKTOP-C9L2OUQ,CN=Computers,DC=ad,DC=example,DC=net has no write property access

The computer can still be listed via samba-tool after the client removal (I can delete it via samba-tool without problem).

We are still testing, so I'm still using the administrator account for adding and removing Windows clients to the domain.
The error message itself makes sense, the computer object does not have write access to the ldap (and I think should never have), but the administrator should have them.

We are currently using Samba version 4.12.1-SerNet-Debian-5.buster.

Do you have any idea?

Best regards
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 6098 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba/attachments/20200422/3d955b5b/smime.bin>

More information about the samba mailing list