Bug 35619 - SYSVOL GPOs are back-replicated from DC Master to Slave after deletion
Summary: SYSVOL GPOs are back-replicated from DC Master to Slave after deletion
Status: RESOLVED WONTFIX
Alias: None
Product: UCS@school
Classification: Unclassified
Component: Samba 4 - Slave PDC
Version: UCS@school 3.2 R2
Hardware: Other Linux
: P5 normal
Target Milestone: UCS@school 3.2.x
Assignee: Samba maintainers
QA Contact:
URL:
Keywords:
Depends on: 38265
Blocks:
  Show dependency treegraph
 
Reported: 2014-08-15 15:23 CEST by Dmitry Galkin
Modified: 2019-02-05 21:26 CET (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dmitry Galkin univentionstaff 2014-08-15 15:23:15 CEST
The SYSVOL GPOs are replicated back from Master after their deletion on Slave.

For instance:

1. Create a GPO on DC Slave: 
samba-tool gpo create TEST_GPO_BUG --username=Administrator --password=univention
GPO 'TEST_GPO_BUG' created as {5FEDA627-965E-4391-A10C-863ABB995148}

2. Run sync or just wait for cron job on Slave:
root@slave2032:/usr/share/univention-samba4/scripts# ./sysvol-sync.sh

3. Run sync or just wait for cron job on Master:
root@master203:/root/# /usr/share/univention-samba4/scripts/sysvol-sync.sh

4. Make sure that GPO was replicated to Master:
root@master203:/var/lib/samba/sysvol/autotest203.local/Policies# ls | grep {5FEDA627-965E-4391-A10C-863ABB995148}

{5FEDA627-965E-4391-A10C-863ABB995148}

5. Remove the GPO on Slave:
root@slave2032:/usr/share/univention-samba4/scripts# samba-tool gpo del {5FEDA627-965E-4391-A10C-863ABB995148} --username=Administrator --password=univention

GPO {5FEDA627-965E-4391-A10C-863ABB995148} deleted.

6. Make sure that GPO was deleted:
root@slave2032:/var/lib/samba/sysvol/autotest203.local/Policies# ls | grep {5FEDA627-965E-4391-A10C-863ABB995148}

7. Run sync or just wait for cron job:
root@slave2032:/usr/share/univention-samba4/scripts# ./sysvol-sync.sh

8. Deleted GPO is back-replicated:
root@slave2032:/var/lib/samba/sysvol/autotest203.local/Policies# ls | grep {5FEDA627-965E-4391-A10C-863ABB995148}

{5FEDA627-965E-4391-A10C-863ABB995148}

9. Thus, with every clean-up script run -> it is deleted; With every sync-up script run it is back-replicated again.
Comment 1 Sönke Schwardt-Krummrich univentionstaff 2019-02-05 21:26:18 CET
This issue has been filled against UCS@school 3.2. The maintenance with
bug and security fixes for UCS@school 3.2 has ended on Dec 31, 2016.

Customers still on UCS 3.x are encouraged to update to UCS 4.3 (or later). 
Please contact your partner or Univention for any questions.

If this issue still occurs in newer UCS versions, please use "Clone this bug"
or simply reopen the issue. In this case please provide detailed information on
how this issue is affecting you.