[Samba] GPO not applied (folder share and printer)

Elias Pereira empbilly at gmail.com
Fri Oct 22 13:05:43 UTC 2021


Hello Louis, thanks for your reply!!

Searching through the information you requested, I think I have found the
problem.

In the system events showed "access problems" for the GPO, then I
remembered that
I have a script that adds automatic uidNumber and I noticed that there was
a very high
number in some users, such number exceeded the 999999 that I had configured
in the
idmap of my fileserver.

idmap config CAMPUS:range = 10000-999999

I will do some more tests, but I believe that's it.

On Fri, Oct 22, 2021 at 3:55 AM L.P.H. van Belle via samba <
samba at lists.samba.org> wrote:

> Whats windows showing in the event logs.. ?
> Event id, description, thats what we also need.
>
>
>
> > -----Oorspronkelijk bericht-----
> > Van: samba [mailto:samba-bounces at lists.samba.org] Namens
> > Elias Pereira via samba
> > Verzonden: vrijdag 22 oktober 2021 3:33
> > Aan: samba
> > Onderwerp: [Samba] GPO not applied (folder share and printer)
> >
> > hi,
> >
> > We have some users that the GPOs do not apply at all.
> >
> > Looking at my profile and one of these accounts,
> > there is apparently no difference from the standard AD confs.
> >
> > It occurs on any computer. With my login the shared folder
> > and the printer
> > are mapped, but with the login of this particular user, these
> > two options
> > are not mapped.
> >
> > I even deleted one of these accounts and remade it,
> > but it still does not apply.
> >
> > ------------------------------------------------------------
> >
> > Client: Windows 10 Pro 20H2
> >
> > --------------------------------------------------------------
> >
> > DC3: Debian 10 with 4.14.6 from Louis's repo.
> > DC4: Debian 10 with 4.14.6 from Louis's repo.
> >
> > --------------------------------------------------------------
> >
> > root at dc3:~/test_scripts# cat default-rights-sysvol.acl
> > # file: /var/lib/samba/sysvol
> > # owner: root
> > # group: root
> > user::rwx
> > user:root:rwx
> > user:3000000:rwx
> > user:3000021:r-x
> > user:3000022:rwx
> > user:3000019:r-x
> > group::rwx
> > group:3000000:rwx
> > group:3000021:r-x
> > group:3000022:rwx
> > group:3000019:r-x
> > mask::rwx
> > other::---
> > default:user::rwx
> > default:user:root:rwx
> > default:user:3000000:rwx
> > default:user:3000021:r-x
> > default:user:3000022:rwx
> > default:user:3000019:r-x
> > default:group::---
> > default:group:3000000:rwx
> > default:group:3000021:r-x
> > default:group:3000022:rwx
> > default:group:3000019:r-x
> > default:mask::rwx
> > default:other::---
> >
> > ------------------------------------------------------------
> >
> > samba-tool ldapcmp --filter="whenChanged,dc,DC,cn,CN"
> > ldap://dc3 ldap://dc4
> > Please wait.. this can take a while..
> >
> > * Comparing [DOMAIN] context...
> >
> > * Objects to be compared: 8448
> >
> > * Result for [DOMAIN]: SUCCESS
> >
> > * Comparing [CONFIGURATION] context...
> >
> > * Objects to be compared: 1728
> >
> > * Result for [CONFIGURATION]: SUCCESS
> >
> > * Comparing [SCHEMA] context...
> >
> > * Objects to be compared: 1740
> >
> > * Result for [SCHEMA]: SUCCESS
> >
> > * Comparing [DNSDOMAIN] context...
> >
> > * Objects to be compared: 780
> >
> > * Result for [DNSDOMAIN]: SUCCESS
> >
> > * Comparing [DNSFOREST] context...
> >
> > * Objects to be compared: 29
> >
> > * Result for [DNSFOREST]: SUCCESS
> >
> > ---------------------------------------------------------------------
> >
> > samba-tool ntacl sysvolreset NO PROBLEM
> >
> > --------------------------------------------------------------------
> >
> > Any other info, please, let me know!!
> >
> > --
> > Elias Pereira
> > --
> > To unsubscribe from this list go to the following URL and read the
> > instructions:  https://lists.samba.org/mailman/options/samba
> >
> >
>
>
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>


-- 
Elias Pereira


More information about the samba mailing list