Re: Access denied on GPO after "ntacl sysvolreset"
Klaas TJEBBES via samba <[email protected]> Tue, 14 Apr 2026 11:51:27 +0200
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <aad956a6-ad58-42b4-abac-3df7ab6c79c1@region-academique-bourgogne-franche-comte.fr> |
Le 13/04/2026 à 18:35, Rowland Penny via samba a écrit : > On Mon, 13 Apr 2026 17:35:11 +0200 > Klaas TJEBBES via samba <[email protected]> wrote: > >> Hello. >> >> I come back on the subject because the problem is still present. >> >> For information : >> Ubuntu 24.04.4 LTS >> samba 2:4.19.5+dfsg-4ubuntu9.4 >> >> /etc/samba/smb.conf >> >> [global] >> realm = DOMSCRIBE.AC-TEST.FR >> workgroup = DOMSCRIBE >> netbios name = ADDC >> disable netbios = yes >> smb ports = 445 >> map acl inherit = Yes >> store dos attributes = Yes >> winbind separator = / >> server role = active directory domain controller >> server services = -dns >> tls enabled = yes >> tls keyfile = /var/lib/samba/private/tls/key.pem >> tls certfile = /var/lib/samba/private/tls/cert.pem >> tls cafile = >> usershare max shares = 0 >> restrict anonymous = 2 >> interfaces = 192.168.0.30 >> log level = 3 >> >> [netlogon] >> comment = Network Logon Service >> path = /home/sysvol/domscribe.ac-test.fr/scripts >> read only = No >> guest ok = yes >> >> [sysvol] >> comment = Sysvol Service >> #path = /home/sysvol >> path = /var/lib/samba/sysvol >> read only = No >> guest ok = yes >> inherit acls = yes >> >> >> The user I'm doing all the action with on the Windows side is : >> root@addc:~# id admin >> uid=3000026(DOMSCRIBE/admin) gid=100(users) >> groupes=100(users),3000026(DOMSCRIBE/admin),3000027(DOMSCRIBE/professeurs),3000004(DOMSCRIBE/domain >> admins),3000005(DOMSCRIBE/denied rodc password replication >> group),3000009(BUILTIN/users),3000000(BUILTIN/administrators) >> >> >> Sympoms : >> * create a GPO on Windows 11 RSAT >> * run 'samba-tool ntacl sysvolreset' >> * trying to modify GPO in RSAT returns an "Access Denied" error. >> >> It has to deal with sub-directory created with faulty ACLs. For >> example, after creating an empty GPO, I have : >> >> root@addc:~# tree >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ >> ├── GPT.INI >> ├── Machine >> └── User >> >> root@addc:~# getfacl >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/ >> getfacl : suppression du premier « / » des noms de chemins absolus >> # file: >> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/ >> # owner: BUILTIN/administrators >> # group: users >> user::rwx >> user:NT\040Authority/system:rwx >> user:NT\040Authority/authenticated\040users:r-x >> user:DOMSCRIBE/domain\040admins:rwx >> user:DOMSCRIBE/enterprise\040admins:rwx >> user:NT\040Authority/enterprise\040domain\040controllers:r-x >> group::--- >> group:users:--- >> group:BUILTIN/administrators:rwx >> group:NT\040Authority/system:rwx >> group:NT\040Authority/authenticated\040users:r-x >> group:DOMSCRIBE/domain\040admins:rwx >> group:DOMSCRIBE/enterprise\040admins:rwx >> group:NT\040Authority/enterprise\040domain\040controllers:r-x >> mask::rwx >> other::--- >> default:user::rwx >> default:user:BUILTIN/administrators:rwx >> default:user:NT\040Authority/system:rwx >> default:user:NT\040Authority/authenticated\040users:r-x >> default:user:DOMSCRIBE/domain\040admins:rwx >> default:user:DOMSCRIBE/enterprise\040admins:rwx >> default:user:NT\040Authority/enterprise\040domain\040controllers:r-x >> default:group::--- >> default:group:users:--- >> default:group:NT\040Authority/system:rwx >> default:group:NT\040Authority/authenticated\040users:r-x >> default:group:DOMSCRIBE/domain\040admins:rwx >> default:group:DOMSCRIBE/enterprise\040admins:rwx >> default:group:NT\040Authority/enterprise\040domain\040controllers:r-x >> default:mask::rwx >> default:other::--- >> >> >> Then I run 'samba-tool ntacl sysvolreset' and I get : >> >> root@addc:~# getfacl >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/ >> getfacl : suppression du premier « / » des noms de chemins absolus >> # file: >> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/ >> # owner: DOMSCRIBE/domain\040admins >> # group: DOMSCRIBE/domain\040admins >> user::rwx >> user:root:rwx >> user:BUILTIN/administrators:rwx >> user:BUILTIN/server\040operators:r-x >> user:NT\040Authority/system:rwx >> user:NT\040Authority/authenticated\040users:r-x >> group::rwx >> group:BUILTIN/administrators:rwx >> group:BUILTIN/server\040operators:r-x >> group:NT\040Authority/system:rwx >> group:NT\040Authority/authenticated\040users:r-x >> mask::rwx >> other::--- >> default:user::rwx >> default:user:root:rwx >> default:user:BUILTIN/administrators:rwx >> default:user:BUILTIN/server\040operators:r-x >> default:user:NT\040Authority/system:rwx >> default:user:NT\040Authority/authenticated\040users:r-x >> default:group::--- >> default:group:BUILTIN/administrators:rwx >> default:group:BUILTIN/server\040operators:r-x >> default:group:NT\040Authority/system:rwx >> default:group:NT\040Authority/authenticated\040users:r-x >> default:mask::rwx >> default:other::--- >> >> Then in RSAT I do : >> Computer => Preferences => Windows Parameters => .ini files => >> C:\test.ini (section a, key b, value c) => Click OK >> >> It returns the error "Access denied", and indeed, this INI File >> creation action in RSAT, creates a sub-directory named "Preferences" >> and its ACLs are faulty : >> >> root@addc:~# getfacl >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/ >> getfacl : suppression du premier « / » des noms de chemins absolus >> # file: >> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/ >> # owner: BUILTIN/administrators >> # group: users >> user::rwx >> user:root:rwx #effective:r-x >> user:BUILTIN/administrators:rwx #effective:r-x >> user:BUILTIN/server\040operators:r-x >> user:NT\040Authority/system:rwx #effective:r-x >> user:NT\040Authority/authenticated\040users:r-x >> group::--- >> group:BUILTIN/administrators:rwx #effective:r-x >> group:BUILTIN/server\040operators:r-x >> group:NT\040Authority/system:rwx #effective:r-x >> group:NT\040Authority/authenticated\040users:r-x >> mask::r-x >> other::--- >> default:user::rwx >> default:user:root:rwx >> default:user:BUILTIN/administrators:rwx >> default:user:BUILTIN/server\040operators:r-x >> default:user:NT\040Authority/system:rwx >> default:user:NT\040Authority/authenticated\040users:r-x >> default:group::--- >> default:group:BUILTIN/administrators:rwx >> default:group:BUILTIN/server\040operators:r-x >> default:group:NT\040Authority/system:rwx >> default:group:NT\040Authority/authenticated\040users:r-x >> default:mask::rwx >> default:other::--- >> >> and : >> >> root@addc:~# tree >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ >> ├── GPT.INI >> ├── Machine >> │ ├── Preferences >> │ └── Scripts >> └── User >> >> >> So I re-run 'samba-tool ntacl sysvolreset', and retry create INI file >> in RSAT, again an "Access denied" error, but this time a new >> sub-directory has been created : >> >> root@addc:~# tree >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ >> ├── GPT.INI >> ├── Machine >> │ ├── Preferences >> │ │ └── IniFiles >> │ └── Scripts >> └── User >> >> But, again, it has faulty ACLs : >> >> root@addc:~# getfacl >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/ >> getfacl : suppression du premier « / » des noms de chemins absolus >> # file: >> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/ >> # owner: DOMSCRIBE/domain\040admins >> # group: DOMSCRIBE/domain\040admins >> user::rwx >> user:root:rwx >> user:BUILTIN/administrators:rwx >> user:BUILTIN/server\040operators:r-x >> user:NT\040Authority/system:rwx >> user:NT\040Authority/authenticated\040users:r-x >> group::rwx >> group:BUILTIN/administrators:rwx >> group:BUILTIN/server\040operators:r-x >> group:NT\040Authority/system:rwx >> group:NT\040Authority/authenticated\040users:r-x >> mask::rwx >> other::--- >> default:user::rwx >> default:user:root:rwx >> default:user:BUILTIN/administrators:rwx >> default:user:BUILTIN/server\040operators:r-x >> default:user:NT\040Authority/system:rwx >> default:user:NT\040Authority/authenticated\040users:r-x >> default:group::--- >> default:group:BUILTIN/administrators:rwx >> default:group:BUILTIN/server\040operators:r-x >> default:group:NT\040Authority/system:rwx >> default:group:NT\040Authority/authenticated\040users:r-x >> default:mask::rwx >> default:other::--- >> >> root@addc:~# getfacl >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/Machine/Preferences/IniFiles/ >> getfacl : suppression du premier « / » des noms de chemins absolus >> # file: >> var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/Machine/Preferences/IniFiles/ >> # owner: BUILTIN/administrators >> # group: users >> user::rwx >> user:root:rwx #effective:r-x >> user:BUILTIN/administrators:rwx #effective:r-x >> user:BUILTIN/server\040operators:r-x >> user:NT\040Authority/system:rwx #effective:r-x >> user:NT\040Authority/authenticated\040users:r-x >> group::--- >> group:BUILTIN/administrators:rwx #effective:r-x >> group:BUILTIN/server\040operators:r-x >> group:NT\040Authority/system:rwx #effective:r-x >> group:NT\040Authority/authenticated\040users:r-x >> mask::r-x >> other::--- >> default:user::rwx >> default:user:root:rwx >> default:user:BUILTIN/administrators:rwx >> default:user:BUILTIN/server\040operators:r-x >> default:user:NT\040Authority/system:rwx >> default:user:NT\040Authority/authenticated\040users:r-x >> default:group::--- >> default:group:BUILTIN/administrators:rwx >> default:group:BUILTIN/server\040operators:r-x >> default:group:NT\040Authority/system:rwx >> default:group:NT\040Authority/authenticated\040users:r-x >> default:mask::rwx >> default:other::--- >> >> If I re-re-run 'samba-tool ntacl sysvolreset', then this time, it's >> OK, RSAT is happy and I have this : >> >> root@addc:~# tree >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/\{2060950E-B0BF-421E-B62D-E2D0C9532B08\}/ >> /var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{2060950E-B0BF-421E-B62D-E2D0C9532B08}/ >> ├── GPT.INI >> ├── Machine >> │ ├── Preferences >> │ │ └── IniFiles >> │ │ └── IniFiles.xml >> │ └── Scripts >> └── User >> >> >> As you can see, the problem is the "mask::r-x" that is put on the >> newly created directory. Each time "sysvolreset" puts it back to >> "mask::rwx" but the it's the new sub-directory that gets a wrong >> "mask". And so on until the last directory needed to store the file >> containing the GPO parameter. >> >> It's as if, in one way or the other, default ACLs are not correctly >> inherited. >> >> >> What am I missing ? or is there really a bug in "sysvolreset" ? >> >> Thank you. >> >> >> Le 17/04/2025 à 15:54, Klaas TJEBBES via samba a écrit : >>> We https://pcll.ac-dijon.fr/pcll/ are editor of servers from the >>> French Ministry of Education. We provide Samba servers, Firewalls, >>> VPN aggregators and monitoring servers since more that 20 years. >>> These servers are for schools, administrations, etc. We have 18000 >>> servers in production, that means approximately 6 million users. >>> >>> Historically we have always stored users data in /home. Since the >>> path of [sysvol] is configurable, we have put it in /home as well. >>> >>> For example, on the file server, the one that hosts people >>> homedirs, those dirs are stored in /home/adhomes/<username>, group >>> dirs are stored in /home/workgroups/<groupname>, recycle bin in >>> /home/recycle, etc. >>> >>> This simplifies a lot server partitioning and backups. For example >>> /home can be put on a faster device than /, or one can decide to >>> put /home on a SAN with persistent data while / is a VM image, etc. >>> >>> >>> But I doubt putting [sysvol] in /home has something to do with the >>> problem we are facing : >>> * 'samba-tool ntacl sysvolcheck' does not detect that ACLs are wrong >>> * 'samba-tool ntacl sysvolreset' does not place the same ACLs as >>> Windows does and this leads to prevent importing GPO parameters in >>> RSAT. >>> >>> Also I don't understand your sentence "Why are sysvol and netlogon >>> in / home instead of being in /var/lib/samba where it belongs ?". >>> >>> Can you explain what the technical problem is to put [sysvol] >>> elsewhere ? I've taken a look to samba source code and could find >>> any answer to this question. >>> >>> >>> >>> Also can you confirm that on your setup, which you told has the >>> same ACLs than the one that are problematic for me, you can import >>> parameters from a previously backuped GPO in RSAT ? see image >>> https://ibb.co/QvFkV8nW >>> >>> >>> >>> Le 16/04/2025 à 18:07, Rowland Penny via samba a écrit : >>>> On Wed, 16 Apr 2025 17:03:10 +0200 >>>> Klaas TJEBBES via samba <[email protected]> wrote: >>>> >>>>> >>>>> I don't understand how import parameters from a previously >>>>> backuped GPO in RSAT can work on your setup as it clearly does >>>>> not on ours. >>>>> >>>>> >>>>> To summarize : >>>>> >>>>> root@addc:~# cat /etc/lsb-release >>>>> DISTRIB_ID=Ubuntu >>>>> DISTRIB_RELEASE=24.04 >>>>> DISTRIB_CODENAME=noble >>>>> DISTRIB_DESCRIPTION="Ubuntu 24.04.2 LTS" >>>>> >>>>> root@addc:~# cat /etc/samba/smb.conf >>>>> [global] >>>>> realm = DOMSCRIBE.AC-TEST.FR >>>>> workgroup = DOMSCRIBE >>>>> netbios name = ADDC >>>>> disable netbios = yes >>>>> smb ports = 445 >>>>> map acl inherit = Yes >>>>> store dos attributes = Yes >>>>> winbind separator = / >>>>> server role = active directory domain controller >>>>> server services = -dns >>>>> tls enabled = yes >>>>> tls keyfile = /var/lib/samba/private/tls/key.pem >>>>> tls certfile = /var/lib/samba/private/tls/cert.pem >>>>> tls cafile = >>>>> usershare max shares = 0 >>>>> restrict anonymous = 2 >>>>> interfaces = 192.168.0.30 >>>>> >>>>> [netlogon] >>>>> comment = Network Logon Service >>>>> path = /home/sysvol/domscribe.ac-test.fr/scripts >>>>> read only = No >>>>> guest ok = yes >>>>> >>>>> [sysvol] >>>>> comment = Sysvol Service >>>>> path = /home/sysvol >>>>> read only = No >>>>> guest ok = yes >>>>> >>>> >>>> I asked this once, but you didn't answer, lets try again: > > Lets try again, why is netlogon not where it supposed to be ? > I notice you have put sysvol back to where it should be. > > Why have you added things to netlogon & sysvol even though the Samba > wiki tells you not to ? > > Finally, why are you ignoring the EA that stores the Windows ACEs that > are set by creating the GPOs, try running: > > sudo samba-tool ntacl get /var/lib/samba/sysvol --as-sddl > > The output of the above command is the permissions that count, not > the standard Unix permissions or the output of getfacl, though they will > affect the permissions, as will adding things to the netlogon & sysvol > shares. > > Rowland > > Sorry, "netlogon" was an error. I've fixed it. [global] realm = DOMSCRIBE.AC-TEST.FR workgroup = DOMSCRIBE netbios name = ADDC disable netbios = yes smb ports = 445 map acl inherit = Yes store dos attributes = Yes winbind separator = / server role = active directory domain controller server services = -dns tls enabled = yes tls keyfile = /var/lib/samba/private/tls/key.pem tls certfile = /var/lib/samba/private/tls/cert.pem tls cafile = usershare max shares = 0 restrict anonymous = 2 interfaces = 192.168.0.30 log level = 3 [netlogon] comment = Network Logon Service path = /var/lib/samba/sysvol/domscribe.ac-test.fr/scripts read only = No guest ok = yes [sysvol] comment = Sysvol Service #path = /home/sysvol path = /var/lib/samba/sysvol read only = No guest ok = yes inherit acls = yes inherit owner = yes root@addc:~# samba-tool ntacl get /var/lib/samba/sysvol --as-sddl O:LAG:BAD:P(A;OICI;FA;;;BA)(A;OICI;0x1200a9;;;SO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU) New GPO created with RSAT has : root@addc:~# samba-tool ntacl get "/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}" --as-sddl O:DAG:DAD:P(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;DA)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(A;OICI;0x1200a9;;;ED) New GPO after "sysvolreset" : root@addc:~# samba-tool ntacl get "/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}" --as-sddl O:DAG:DAD:P(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;DA)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;edacfd8f-ffb3-11d1-b41d-00a0c968f939;;AU)(A;OICI;0x1200a9;;;ED) And after trying to add a .INI File preference in RSAT (which failed with "Access Denied" error) : root@addc:~# samba-tool ntacl get "/var/lib/samba/sysvol/domscribe.ac-test.fr/Policies/{168E5E09-529C-4947-84BE-DD3410700CBE}/Machine/Preferences" --as-sddl O:DAG:DAD:(A;OICI;FA;;;DA)(A;OICI;FA;;;EA)(A;;FA;;;DA)(A;OICIIO;FA;;;CO)(A;OICI;FA;;;SY)(A;OICI;0x1200a9;;;AU)(OA;OICI;;;;AU)(A;OICI;0x1200a9;;;ED) -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba