[Samba] idmap range

Stefan G. Weichinger lists at xunil.at
Thu Apr 14 09:45:47 UTC 2022

Am 14.04.22 um 09:19 schrieb Rowland Penny via samba:
> On Thu, 2022-04-14 at 07:05 +0200, Stefan G. Weichinger via samba
> wrote:
>> Am 14.04.22 um 07:00 schrieb Stefan G. Weichinger:
>>> Found this thread (without solution):
>>> https://lists.samba.org/archive/samba/2016-September/203261.html
>> Another link: https://bugzilla.samba.org/show_bug.cgi?id=12363
>> although I don't find any dir like "*/locks/sysvol"
> But you should have /var/lib/samba/sysvol

Yep. Applied these setfacl-commands there.

"samba-tool ntacl sysvolreset" fails the same way after that.

> Have you run 'samba-tool dbcheck' and 'samba-tool ldapcmp' ?

"dbcheck" shows 2 NOTEs for old string components, and "0 errors".

fixed the 2 issues with "--fix"

"ldapcmp" : got to learn which parameters to use .. ok, got it.

I get one error:

(32, 'LDAP error 32 LDAP_NO_SUCH_OBJECT -  <acl_read: Error retrieving 
instanceType for base. at 
../../source4/dsdb/samdb/ldb_modules/acl_read.c:940> <>')

What to do about that one?

> Did your problems start after adding a GPO ? If so, have you tried
> removing that GPO ?

No. No GPO edited for months. As I wanted to edit one a few weeks ago 
(at the time I started this thread) I saw these errors in RSAT and 
started to dig.

thanks, Stefan

More information about the samba mailing list