[Samba] SYSVOL ACL errors after rsync replication

Rowland Penny rpenny at samba.org
Fri Oct 7 15:55:43 UTC 2022

On 07/10/2022 14:43, Michal Sládek via samba wrote:
> Hello!
> I am trying to setup new secondary DC in Samba domain and I face strange
> problem with SYSVOL ACL. Each time I do rsync, I got ACL errors:
> Samba is 4.9.18 on primary DC and 4.16.5 on secondary DC.

Here is what I would do:

Ensure that Sysvol on the DC running 4.16.5 is correct, also ensure that 
Samba and AD are running correctly.

Transfer any FSMO roles on the DC running 4.9.18 to the other DC.

Transfer anything else on the DC running 4.9.18 that you might need (not 

Demote the DC running 4.9.18 and, as this is a very old version of 
Samba, probably upgrade the OS. Upgrade/install Samba 4.16.5 and then 
join this to AD domain as a DC.

Sync idmap.ldb and Sysvol from the existing DC to your new one and run 
sysvolreset (do this any time you sync Sysvol).

Notice that I didn't mention primary/secondary, PDC/BDC, etc in relation 
to your DC's, all DC's are equal (or rather they should be) except for 
the FSMO roles and they can be on any DC.


More information about the samba mailing list