Univention Bugzilla – Bug 40300
provide printers via gpo doesn't work when gpo is created at dc master central location
Last modified: 2016-01-19 15:54:23 CET
+++ This bug was initially created as a clone of Bug #32041 +++ Please see ticket #2013071721001785 for more detail: You have the possibility to provide printers per user via gpo. This is working when the gpo's are created at school locations, but does not fully work when they are created at the master location. The master itself uses samba 4 within its school-environment and is intended to be used for a central gpo management.
ucs-school-ldap-acls-master: changed 65ucsschool ldap acl's. slaves are allowed to write objectClass=msPrintConnectionPolicy objects "cn=policies,cn=system,@%@ldap/base@%@" subtree ucs-school-metapackage: Set connector/s4/mapping/msprintconnectionpolicy?yes as default for all roles. I did NOT update the ucs@school app yet. Dependency: https://forge.univention.org/bugzilla/show_bug.cgi?id=40299 Changelog: ucs-school-ldap-acls-master: The LDAP ACL's have been modified to allow school slave's to update printConnectionPolicy objects (to provide printers via Group Policies). ucs-school-metapackage: The synchronization of printConnectionPolicy objects (to provide printers via Group Policies) has been enabled for all server roles. The synchronization can be disabled by setting the UCR variable connector/s4/mapping/msprintconnectionpolicy to false.
Added code to resync the objectClass=msPrint-ConnectionPolicy objects from s4 to udm to ucs-school-master.postinst, ucs-school-slave.postinst and ucs-school-nonedu-slave.postinst in ucs-school-metapackage.
Basically it works but there is one corner case: Standard setup as discussed: *before* updating the UCS@school packages on a UCS 4.0-4 e381 Master and Slave I created two printers and assigned them in different ways via msPrint-ConnectionPolicy: Two Windows clients: * client 1 joined to master110 in the central school department * client 2 joined to slave112 at school2 1. On the Master UMC I created printer1 and printer2 on slave112@school2 and uploaded+assigned a printer driver for both via Printmanagement.msc on client 1 2. Via GPMC on client 1 I created GPO1 and GPO2 on Master and assigned both to OU=school2 3.1 On a client 1 I used Printmanagement.msc to attach a msPrint-ConnectionPolicy for printer1 to GPO1 (user+machine) 3.2 On a client 2 I used Printmanagement.msc to attach a msPrint-ConnectionPolicy for printer2 to GPO2 (user+machine) Then I updated first on the Master and then on slave112 and tested login at client 2 with a student account. Problem: printer2 was connected but printer1 not. I checked and the udm settings/msprintconnectionpolicy listed all 4 objects on the slave, but univention-s4search '(objectClass=msPrint-ConnectionPolicy)' dn only showed the two that had been created on the slave. I think this is needed too: /usr/share/univention-s4-connector/ resync_object_from_ucs.py --filter '(objectClass=msPrintConnectionPolicy)' I'll attach a patch proposal.
Created attachment 7404 [details] sync_msprinterpolicy_from_ucs.patch
(In reply to Arvid Requate from comment #4) > Created attachment 7404 [details] > sync_msprinterpolicy_from_ucs.patch yes, by the time the master re-synced its PushedPrinterConnections from s4 to udm the connector on the slave wasn't updated yet and the connector did not know how to handle PushedPrinterConnections objects fixed
Ok, works.
As discussed with Felix: UCS@school supports the possibility to convert a single master environment into a multi server environment. This is why 62ucs-school-singlemaster.inst should also sync the msPrintConnectionPolicy objects → REOPEN
(In reply to Sönke Schwardt-Krummrich from comment #7) > As discussed with Felix: UCS@school supports the possibility to convert a > single master environment into a multi server environment. This is why > 62ucs-school-singlemaster.inst should also sync the msPrintConnectionPolicy > objects → REOPEN added msPrintConnectionPolicy resync to ucs-school-singlemaster.postinst for this update
Ok, also works on Singlemaster.
UCS@school 4.0 R2 v6 has been released. If this error occurs again, please use "Clone This Bug".