[Samba] Samba and Winbind Group Policy

Robert Marcano robert at marcanoonline.com
Thu Oct 7 13:19:14 UTC 2021


On 10/4/21 5:01 PM, David Mulder via samba wrote:
> After some discussion about this on the mailing list, I decided to 
> update the outdated wiki page and mention it here. There is a great deal 
> that has changed since the last time I updated the 
> https://wiki.samba.org/index.php/Group_Policy page.
> There are currently 13 distinct policies, including smb.conf, addc 
> password/kerberos, scripts, files, symlinks, sudoers, messages 
> (motd/issue), pam access, certificate auto enrollment, firefox, 
> chrome/chromium, GNOME, and OpenSSH. And I'm not finished. I will try to 
> keep this page up-to-date in the future to avoid confusion.
> 
> FYI, the samba-gpupdate command *does* work when joined via either 
> winbind or sssd, so you can choose.
> 

This is great to know, amazing work. Do anyone know of someone working 
on a console based GPO editor. I remotely manage some small networks and 
it is becoming really painful to have to use remote desktop to fix some 
GPO some local sysadmin needs help, specially on small business Internet 
connections that tend to be saturated, and our country bad ISPs with 2MB 
"super mega fast" internet service.

Now that I see this kind of work, is there some documentation on the GPO 
file formats? Is the samba code base to parse them reusable enough to 
experiment building a console based GPO editor? I am starting to think I 
should invest some time on this.



More information about the samba mailing list