LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-24-2018, 05:24 PM   #1
atomiccomp
Member
 
Registered: Dec 2008
Location: UK
Distribution: Debian/Ubuntu
Posts: 41

Rep: Reputation: 0
Zentyal 5 ad samba problem with Win 10 and group policy.


I have three Zentyal 5.0.1 servers with Samba 4.6.7 in the field all functioning as DC's. I use the default domain policy with roaming profiles (the roaming profiles were set in the zentyal admin webpage) and a couple of drive maps.

All the PC's are 'joined to the domain'

On windows 7 PC's when regular users log in the roaming profiles and drive maps work perfectly.

However on windows 10 PC's unless the users are administrators (members of the admin and schema admin group) neither the roaming profiles or drive maps work and often it logs in with a temp profile.
A check of the system events shows the following error;
The processing of Group Policy failed. Windows attempted to read the file \\test.local\sysvol\test.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:
a) Name Resolution/Network Connectivity to the current domain controller.
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller).
c) The Distributed File System (DFS) client has been disabled.

Things I have tried;
I can browse to and open the gpt.ini with no problems as a standard user.

If I then add the user to the admin group the issue goes away.
This issue affects all the zentyal 5 setups I have in exactly the same way including a test one. The windows 10 version is the latest creators edition.

I am certain anyone else using the win 10 creators version and zentyal 5/samba 4.6.7 will be hitting the same issue!

Has anyone solved it?
 
Old 02-25-2018, 06:02 AM   #2
atomiccomp
Member
 
Registered: Dec 2008
Location: UK
Distribution: Debian/Ubuntu
Posts: 41

Original Poster
Rep: Reputation: 0
Many thanks for all the replies and pointers chaps!

Hopefully this may help another newbie like me.

Just a quick update;

The issue was caused by UNC hardening which by default is off on win 7 and 8/8.1 but enabled by default on Windows 10.
Once disabled on my win 10 clients the fault went away- However this raises two questions in my mind;

1, It looks like UNC hardening is a security feature so disabling it may not be the best idea.

2, I run quite a few MS domain controllers (Server 2008/sbs2011/server2012) and Win 10 clients with the UNC hardening enabled and have no group policy issues at all. I'm thinking this is maybe a bug in Samba?


Main thing for now is its working.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
group policy with samba utdom Linux - Server 4 11-15-2007 09:29 AM
somebody test samba group policy? kstan Linux - General 1 07-19-2007 03:05 PM
Group Policy & Samba 3.0 matarodi Linux - Software 2 02-21-2006 06:57 AM
Samba User / Group Access Permissions Different Between Linux and Win jeyroz Linux - Software 8 01-29-2006 11:26 AM
samba and group policy egyptian Linux - Networking 3 10-20-2004 05:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 10:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration