Re: Access denied on GPO after "ntacl sysvolreset"
Rowland Penny via samba <[email protected]> Mon, 13 Apr 2026 17:35:32 +0100
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 13 Apr 2026 17:35:11 +0200 Klaas TJEBBES via samba <[email protected]> wrote: > Hello. > > I come back on the subject because the problem is still present. > > For information : > Ubuntu 24.04.4 LTS > samba 2:4.19.5+dfsg-4ubuntu9.4 > > /etc/samba/smb.conf > > [global] > realm = DOMSCRIBE.AC-TEST.FR > workgroup = DOMSCRIBE > netbios name = ADDC > disable netbios = yes > smb ports = 445 > map acl inherit = Yes > store dos attributes = Yes > winbind separator = / > server role = active directory domain controller > server services = -dns > tls enabled = yes > tls keyfile = /var/lib/samba/private/tls/key.pem > tls certfile = /var/lib/samba/private/tls/cert.pem > tls cafile = > usershare max shares = 0 > restrict anonymous = 2 > interfaces = 192.168.0.30 > log level = 3 > > [netlogon] > comment = Network Logon Service > path = /home/sysvol/domscribe.ac-test.fr/scripts > read only = No > guest ok = yes > > [sysvol] > comment = Sysvol Service > #path = /home/sysvol > path = /var/lib/samba/sysvol > read only = No > guest ok = yes > inherit acls = yes > > > The user I'm doing all the action with on the Windows side is : > root@addc:~# id admin > uid=3000026(DOMSCRIBE/admin) gid=100(users) > groupes=100(users),3000026(DOMSCRIBE/admin),3000027(DOMSCRIBE/professeurs),3000004(DOMSCRIBE/domain > admins),3000005(DOMSCRIBE/denied rodc password replication > group),3000009(BUILTIN/users),3000000(BUILTIN/administrators) > > > Sympoms : > * create a GPO on Windows 11 RSAT > * run 'samba-tool ntacl sysvolreset' > * trying to modify GPO in RSAT returns an "Access Denied" error. > > It has to deal with sub-directory created with faulty ACLs. For > example, after creating an empty GPO, I have : > > root@addc:~# tree > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ > ├── GPT.INI > ├── Machine > └── User > > root@addc:~# getfacl > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/ > getfacl : suppression du premier « / » des noms de chemins absolus > # file: > var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/ > # owner: BUILTIN/administrators > # group: users > user::rwx > user:NT\040Authority/system:rwx > user:NT\040Authority/authenticated\040users:r-x > user:DOMSCRIBE/domain\040admins:rwx > user:DOMSCRIBE/enterprise\040admins:rwx > user:NT\040Authority/enterprise\040domain\040controllers:r-x > group::--- > group:users:--- > group:BUILTIN/administrators:rwx > group:NT\040Authority/system:rwx > group:NT\040Authority/authenticated\040users:r-x > group:DOMSCRIBE/domain\040admins:rwx > group:DOMSCRIBE/enterprise\040admins:rwx > group:NT\040Authority/enterprise\040domain\040controllers:r-x > mask::rwx > other::--- > default:user::rwx > default:user:BUILTIN/administrators:rwx > default:user:NT\040Authority/system:rwx > default:user:NT\040Authority/authenticated\040users:r-x > default:user:DOMSCRIBE/domain\040admins:rwx > default:user:DOMSCRIBE/enterprise\040admins:rwx > default:user:NT\040Authority/enterprise\040domain\040controllers:r-x > default:group::--- > default:group:users:--- > default:group:NT\040Authority/system:rwx > default:group:NT\040Authority/authenticated\040users:r-x > default:group:DOMSCRIBE/domain\040admins:rwx > default:group:DOMSCRIBE/enterprise\040admins:rwx > default:group:NT\040Authority/enterprise\040domain\040controllers:r-x > default:mask::rwx > default:other::--- > > > Then I run 'samba-tool ntacl sysvolreset' and I get : > > root@addc:~# getfacl > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/ > getfacl : suppression du premier « / » des noms de chemins absolus > # file: > var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/ > # owner: DOMSCRIBE/domain\040admins > # group: DOMSCRIBE/domain\040admins > user::rwx > user:root:rwx > user:BUILTIN/administrators:rwx > user:BUILTIN/server\040operators:r-x > user:NT\040Authority/system:rwx > user:NT\040Authority/authenticated\040users:r-x > group::rwx > group:BUILTIN/administrators:rwx > group:BUILTIN/server\040operators:r-x > group:NT\040Authority/system:rwx > group:NT\040Authority/authenticated\040users:r-x > mask::rwx > other::--- > default:user::rwx > default:user:root:rwx > default:user:BUILTIN/administrators:rwx > default:user:BUILTIN/server\040operators:r-x > default:user:NT\040Authority/system:rwx > default:user:NT\040Authority/authenticated\040users:r-x > default:group::--- > default:group:BUILTIN/administrators:rwx > default:group:BUILTIN/server\040operators:r-x > default:group:NT\040Authority/system:rwx > default:group:NT\040Authority/authenticated\040users:r-x > default:mask::rwx > default:other::--- > > Then in RSAT I do : > Computer => Preferences => Windows Parameters => .ini files => > C:\test.ini (section a, key b, value c) => Click OK > > It returns the error "Access denied", and indeed, this INI File > creation action in RSAT, creates a sub-directory named "Preferences" > and its ACLs are faulty : > > root@addc:~# getfacl > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/ > getfacl : suppression du premier « / » des noms de chemins absolus > # file: > var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/ > # owner: BUILTIN/administrators > # group: users > user::rwx > user:root:rwx #effective:r-x > user:BUILTIN/administrators:rwx #effective:r-x > user:BUILTIN/server\040operators:r-x > user:NT\040Authority/system:rwx #effective:r-x > user:NT\040Authority/authenticated\040users:r-x > group::--- > group:BUILTIN/administrators:rwx #effective:r-x > group:BUILTIN/server\040operators:r-x > group:NT\040Authority/system:rwx #effective:r-x > group:NT\040Authority/authenticated\040users:r-x > mask::r-x > other::--- > default:user::rwx > default:user:root:rwx > default:user:BUILTIN/administrators:rwx > default:user:BUILTIN/server\040operators:r-x > default:user:NT\040Authority/system:rwx > default:user:NT\040Authority/authenticated\040users:r-x > default:group::--- > default:group:BUILTIN/administrators:rwx > default:group:BUILTIN/server\040operators:r-x > default:group:NT\040Authority/system:rwx > default:group:NT\040Authority/authenticated\040users:r-x > default:mask::rwx > default:other::--- > > and : > > root@addc:~# tree > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ > ├── GPT.INI > ├── Machine > │ ├── Preferences > │ └── Scripts > └── User > > > So I re-run 'samba-tool ntacl sysvolreset', and retry create INI file > in RSAT, again an "Access denied" error, but this time a new > sub-directory has been created : > > root@addc:~# tree > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ > ├── GPT.INI > ├── Machine > │ ├── Preferences > │ │ └── IniFiles > │ └── Scripts > └── User > > But, again, it has faulty ACLs : > > root@addc:~# getfacl > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/ > getfacl : suppression du premier « / » des noms de chemins absolus > # file: > var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/ > # owner: DOMSCRIBE/domain\040admins > # group: DOMSCRIBE/domain\040admins > user::rwx > user:root:rwx > user:BUILTIN/administrators:rwx > user:BUILTIN/server\040operators:r-x > user:NT\040Authority/system:rwx > user:NT\040Authority/authenticated\040users:r-x > group::rwx > group:BUILTIN/administrators:rwx > group:BUILTIN/server\040operators:r-x > group:NT\040Authority/system:rwx > group:NT\040Authority/authenticated\040users:r-x > mask::rwx > other::--- > default:user::rwx > default:user:root:rwx > default:user:BUILTIN/administrators:rwx > default:user:BUILTIN/server\040operators:r-x > default:user:NT\040Authority/system:rwx > default:user:NT\040Authority/authenticated\040users:r-x > default:group::--- > default:group:BUILTIN/administrators:rwx > default:group:BUILTIN/server\040operators:r-x > default:group:NT\040Authority/system:rwx > default:group:NT\040Authority/authenticated\040users:r-x > default:mask::rwx > default:other::--- > > root@addc:~# getfacl > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/IniFiles/ > getfacl : suppression du premier « / » des noms de chemins absolus > # file: > var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/IniFiles/ > # owner: BUILTIN/administrators > # group: users > user::rwx > user:root:rwx #effective:r-x > user:BUILTIN/administrators:rwx #effective:r-x > user:BUILTIN/server\040operators:r-x > user:NT\040Authority/system:rwx #effective:r-x > user:NT\040Authority/authenticated\040users:r-x > group::--- > group:BUILTIN/administrators:rwx #effective:r-x > group:BUILTIN/server\040operators:r-x > group:NT\040Authority/system:rwx #effective:r-x > group:NT\040Authority/authenticated\040users:r-x > mask::r-x > other::--- > default:user::rwx > default:user:root:rwx > default:user:BUILTIN/administrators:rwx > default:user:BUILTIN/server\040operators:r-x > default:user:NT\040Authority/system:rwx > default:user:NT\040Authority/authenticated\040users:r-x > default:group::--- > default:group:BUILTIN/administrators:rwx > default:group:BUILTIN/server\040operators:r-x > default:group:NT\040Authority/system:rwx > default:group:NT\040Authority/authenticated\040users:r-x > default:mask::rwx > default:other::--- > > If I re-re-run 'samba-tool ntacl sysvolreset', then this time, it's > OK, RSAT is happy and I have this : > > root@addc:~# tree > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ > /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ > ├── GPT.INI > ├── Machine > │ ├── Preferences > │ │ └── IniFiles > │ │ └── IniFiles.xml > │ └── Scripts > └── User > > > As you can see, the problem is the "mask::r-x" that is put on the > newly created directory. Each time "sysvolreset" puts it back to > "mask::rwx" but the it's the new sub-directory that gets a wrong > "mask". And so on until the last directory needed to store the file > containing the GPO parameter. > > It's as if, in one way or the other, default ACLs are not correctly > inherited. > > > What am I missing ? or is there really a bug in "sysvolreset" ? > > Thank you. > > > Le 17/04/2025 à 15:54, Klaas TJEBBES via samba a écrit : > > We https://pcll.ac-dijon.fr/pcll/ are editor of servers from the > > French Ministry of Education. We provide Samba servers, Firewalls, > > VPN aggregators and monitoring servers since more that 20 years. > > These servers are for schools, administrations, etc. We have 18000 > > servers in production, that means approximately 6 million users. > > > > Historically we have always stored users data in /home. Since the > > path of [sysvol] is configurable, we have put it in /home as well. > > > > For example, on the file server, the one that hosts people > > homedirs, those dirs are stored in /home/adhomes/<username>, group > > dirs are stored in /home/workgroups/<groupname>, recycle bin in > > /home/recycle, etc. > > > > This simplifies a lot server partitioning and backups. For example > > /home can be put on a faster device than /, or one can decide to > > put /home on a SAN with persistent data while / is a VM image, etc. > > > > > > But I doubt putting [sysvol] in /home has something to do with the > > problem we are facing : > > * 'samba-tool ntacl sysvolcheck' does not detect that ACLs are wrong > > * 'samba-tool ntacl sysvolreset' does not place the same ACLs as > > Windows does and this leads to prevent importing GPO parameters in > > RSAT. > > > > Also I don't understand your sentence "Why are sysvol and netlogon > > in / home instead of being in /var/lib/samba where it belongs ?". > > > > Can you explain what the technical problem is to put [sysvol] > > elsewhere ? I've taken a look to samba source code and could find > > any answer to this question. > > > > > > > > Also can you confirm that on your setup, which you told has the > > same ACLs than the one that are problematic for me, you can import > > parameters from a previously backuped GPO in RSAT ? see image > > https://ibb.co/QvFkV8nW > > > > > > > > Le 16/04/2025 à 18:07, Rowland Penny via samba a écrit : > >> On Wed, 16 Apr 2025 17:03:10 +0200 > >> Klaas TJEBBES via samba <[email protected]> wrote: > >> > >>> > >>> I don't understand how import parameters from a previously > >>> backuped GPO in RSAT can work on your setup as it clearly does > >>> not on ours. > >>> > >>> > >>> To summarize : > >>> > >>> root@addc:~# cat /etc/lsb-release > >>> DISTRIB_ID=Ubuntu > >>> DISTRIB_RELEASE=24.04 > >>> DISTRIB_CODENAME=noble > >>> DISTRIB_DESCRIPTION="Ubuntu 24.04.2 LTS" > >>> > >>> root@addc:~# cat /etc/samba/smb.conf > >>> [global] > >>> realm = DOMSCRIBE.AC-TEST.FR > >>> workgroup = DOMSCRIBE > >>> netbios name = ADDC > >>> disable netbios = yes > >>> smb ports = 445 > >>> map acl inherit = Yes > >>> store dos attributes = Yes > >>> winbind separator = / > >>> server role = active directory domain controller > >>> server services = -dns > >>> tls enabled = yes > >>> tls keyfile = /var/lib/samba/private/tls/key.pem > >>> tls certfile = /var/lib/samba/private/tls/cert.pem > >>> tls cafile = > >>> usershare max shares = 0 > >>> restrict anonymous = 2 > >>> interfaces = 192.168.0.30 > >>> > >>> [netlogon] > >>> comment = Network Logon Service > >>> path = /home/sysvol/domscribe.ac-test.fr/scripts > >>> read only = No > >>> guest ok = yes > >>> > >>> [sysvol] > >>> comment = Sysvol Service > >>> path = /home/sysvol > >>> read only = No > >>> guest ok = yes > >>> > >> > >> I asked this once, but you didn't answer, lets try again: Lets try again, why is netlogon not where it supposed to be ? I notice you have put sysvol back to where it should be. Why have you added things to netlogon & sysvol even though the Samba wiki tells you not to ? Finally, why are you ignoring the EA that stores the Windows ACEs that are set by creating the GPOs, try running: sudo samba-tool ntacl get /var/lib/samba/sysvol --as-sddl The output of the above command is the permissions that count, not the standard Unix permissions or the output of getfacl, though they will affect the permissions, as will adding things to the netlogon & sysvol shares. Rowland -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba