Bug 31438 - Make sysvol readable for members of the group "Enterprise Domain Controllers"
Make sysvol readable for members of the group "Enterprise Domain Controllers"
Status: CLOSED FIXED
Product: UCS@school
Classification: Unclassified
Component: Samba 4 - Slave PDC
UCS@school 3.1
Other Linux
: P5 normal (vote)
: UCS@school 3.1 R2
Assigned To: Arvid Requate
Alexander Kläser
: interim-2
Depends on: 31437
Blocks:
  Show dependency treegraph
 
Reported: 2013-05-23 23:25 CEST by Arvid Requate
Modified: 2013-06-07 21:39 CEST (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2013-05-23 23:25:08 CEST
In two special cases one of the UCS@School Samba4 Slave PDCs will have to create the group "Enterprise Domain Controllers":

  * if no S4 Connector is running in the central school epartement
  * if the errata update for Bug 31437 was not installed on the Master/Backup yet


+++ This bug was initially created as a clone of Bug #31437 +++

The changes of Bug 31271 demand that a different way for sysvol synchronization
is created:

The group "Enterprise Domain Controllers" needs to be created with its propper
builtin SID (S-1-5-9) and all currently registered samba4 DC need to be added.
After waiting for samba4-idmap to write the updated mapping to idmap.ldb,
samba-tool ntacl sysvolreset should be called to re-create the fACLs from the
directory-NTACLs.
Comment 1 Arvid Requate univentionstaff 2013-05-23 23:45:03 CEST
The current solution reuses univention-samba4 shell library code and thus declares a versioned dependency on unviention-samba4.

The helper joinscript 98univention-samba4slavepdc-dns.inst was used for this purpose, because administrative credentials are required. The joinscript version needed to be increased.

Changelog adjusted.
Comment 2 Alexander Kläser univentionstaff 2013-05-29 12:47:35 CEST
After the installation of UCS@school on a master and a slave, the group "Enterprise Domain Controllers" exists and the slave is member of the group.

Changes → OK

Changelog → OK

→ VERIFIED
Comment 3 Sönke Schwardt-Krummrich univentionstaff 2013-06-07 21:39:34 CEST
UCS@school 3.1 R2 has been released:
http://download.univention.de/doc/release-notes-ucsschool-3.1-rev2.pdf

If this error occurs again, please use "Clone This Bug".