[ Date Index ]
[ Thread Index ]
[ <= Previous by date /
thread ]
[ Next by date /
thread => ]
Re: [LUG] Samba Active Directory
- To: "list@xxxxxxxxxxxxx" <list@xxxxxxxxxxxxx>
- Subject: Re: [LUG] Samba Active Directory
- From: mr meowski <mr.meowski@xxxxxxxx>
- Date: Tue, 3 Dec 2019 19:09:56 +0000
- Accept-language: en-GB, en-US
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1yH/tlKMJFMQNJenJndb8rpa3ImwwWkMF1gjSg/OJx0=; b=cZ/66Jy/Ji1sD8K4rz2qq03ka4B1vhytS+DeDwjjztMVQBODRX7kUEUjdnzKShmRvYAFohBo1Iv7Wxtj6EhpetwbIeXAhx2sKDB74Sc0blnVrKZG0JKX8cxkPArCi9+SJxWmQDv8QDzsX9DspUBGjBkd7gWYErJk1Iv4Edb50H0whULFkoiANxBEE7Ub8dky7Zqi8xeH0gIMmuc6/AfMQbsZYVVHJduEtFsc3bNY1UKMIyLlMKSOp+F+DmL6KWGjMj7Pi8FnMmUpaXA7d9adfUJi859Qg2uALxbEQVNOJKG5BXja3UInWzHazgJX0kqEAWOTFdi9u9Mqz4Y6ZddYfg==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=jccv9Z2ZYsnJakj7S20diL9Sp3D4eXsL1bUDMIcRF0JiqQ8lpxzOcHfLvw67okkwI7vOf2na9AipceArtBOcw+hMgX6/GqkzQwOSeUi0OUSnLsW/Jt5Nh/IupXvfEsrY8Ftg8my8DsOn+idq9O4vkq4KBiIswvVblqRaXXefxSDz+YrnfoYremZSpM/CNZmjjkRTLiQvPEG5ZxRzBty1mBksPlDY+CTmbS3JEAdRYFQgafcYypFEPJt8MgmTe0PzqBShd415R60dkMxix28c7XMuUwRPbqaHCpMV6fuGQ7BlQDZSxcFdUVCm1761ZO0//LLBtGitb2S22uLhTuN6iQ==
- Content-id: <C8C6886F16E9CA4DBB9B4D1A30068FD9@eurprd09.prod.outlook.com>
- Content-language: en-US
- Delivered-to: dclug@xxxxxxxxxxxxxxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=dclug.org.uk; s=1570611962; h=Sender:Content-Transfer-Encoding:Content-Type :Reply-To:List-Subscribe:List-Help:List-Post:List-Unsubscribe:List-Id:Subject :MIME-Version:Content-ID:In-Reply-To:References:Message-ID:Date:To:From:Cc: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Owner:List-Archive; bh=cPwRQ54F+ecpDY+Ot2b9wAKQU8IuC0hEqV97GWbXFBA=; b=ZWPMCqXXtpq5Z9jLMPFGPgFEBg GDjZdRrXvb1luo1AUi4CfBqyD7ACOl88fp5Z0YtzdtB7xiJzDmD7j5QIHY4umpBT/pOgkCXxkJJb7 9/6LBGPfVLr0fEPoD7MDEYndkjv6U20owuy8mNwhdcno88mdGIf8copf/dbaXW28pXG8=;
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=live.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=1yH/tlKMJFMQNJenJndb8rpa3ImwwWkMF1gjSg/OJx0=; b=Emv/v+0+HHlhKxC1KMVVNhIJ+bX4/Jm+cw/dI52aeUKFsnf+P9/z7yfsEppm7bnUSElNGuXqiVcfRnpCZu7N2ajkm6TP1KKq9K2xW0LtysmtWBegvPShCCOcW4PJw6+SOFUmKYHvbsI2i8BgWGyaRUQpG8HxjC6X8vYWgellwCSWXrVQQk03QHxDeGB1LitKi8wX6DdEyvXQTPx2YdUAsy04UjIhmW3TSaxHKiHd3NsATeamZQbvn1qj26aA0uLnXD/mmaAOzptRp+BSbTEbTCaEuwuHCUOgCDXgsf/60LrJtux3DdLQQjzjEpenBxe4FcNhF8bT7R8Y8S8UdHjhSg==
- Thread-index: AQHVqgTtTK+RR/EnmU2thvnThJ6roaeoxnSA
- Thread-topic: [LUG] Samba Active Directory
On 03/12/2019 17:57, Martin Gautier wrote:
> Hi
>
> Does anyone have any experience of using Samba as an Active Directory
> connecting Win10 clients?
>
> I seem to have everything loaded and working including drive maps and
> GPO but I'm struggling with Folder Redirection. Basically, it doesn't
> work. The client logs in Event Viewer complain with Event ID 502 Access
> Denied.
>
> I've followed the Samba docs' recommended methods of setting it up and
> double-checked with other online sources too. Everything else works and
> I get no errors in the server logs.
>
> Permissions "seem" correct and clients can CRUD files and directories on
> the drive mappings manually. Obviously the server doesn't like the
> permissions for some reason but I'm buggered if I can work out what...
>
> Any ideas? Gotchas? troubleshooting tips?
>
> Cheers
>
There's a million things that could go wrong here but you're probably
right - it's going to be permissions which will be easier to _diagnose_
from the client side but you'll have to _fix_ on the server side.
Without access to a lot more information that isn't suitable for sharing
on public mailing lists the exact issue is going to be hard for anyone
without access to the boxes themselves to dig into but have you checked
the relevant part of the GPO is actually getting applied to the clients
correctly? What if you gpupdate /force on a client with issues? Should
give you hints about security descriptors etc if you're lucky.
Good luck, this can be like descending into the seventh circle of hell!
--
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq