[prev in list] [next in list] [prev in thread] [next in thread] 

List:       samba
Subject:    Re: [Samba] "failed access check on" on gpo
From:       Stefan Kania <stefan () kania-online ! de>
Date:       2015-11-27 12:57:13
Message-ID: 56585329.3080507 () kania-online ! de
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I think I fond the problem. We have one Win 10 System with RSAT and
all teh gpo's where created with win7 RSAT as soon as we access the
gpos with win10 rsat the permissions are getting changed. samba-tool
ntacl sysvolcheck will give an error about wrong permission. As soon
as we let samba-tool ntacl sysvolrest run, everything is fine.


Am 27.11.15 um 12:59 schrieb mathias dufresne:
> You shoudl check ACLs on your GPO, to whom you applied them.
> 
> failed access check with some standard user + access granted to 
> administrator sounds like a right (acl) issue on your files. Check
> them, you can run GPMC.msc on Windows to check and apply new
> rights.
> 
> 2015-11-27 12:48 GMT+01:00 Stefan Kania <stefan@kania-online.de>:
> 
> Hallo,
> 
> when I do an "samba-tool gpo list username" I get an "faild access 
> check on OU=name,......". But not if I do a "samba-tool gpo
> listall" then everything is ok. Is this normal? If I take
> "administrator" as username I didn't get this message.
> 
> Stefan
> 
>> 
>> -- To unsubscribe from this list go to the following URL and read
>> the instructions:  https://lists.samba.org/mailman/options/samba
>> 


-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.16 (Darwin)

iEYEARECAAYFAlZYUykACgkQ2JOGcNAHDTYvegCg3Bhjcc3t6fdFjf9URSmrC+lX
8msAnR0kOKDz0bOES8DlDbo/sRGutKID
=fzeR
-----END PGP SIGNATURE-----

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic