Univention Bugzilla – Bug 46741
GPO application fails after moving windows machine account to other OU via UMC
Last modified: 2018-12-17 21:43:32 CET
Ticket# 2018030821000649: Situation: Windows client joined, machine account created beneath some OU1 (via redircmp). GPO with machine affecting policy attached to OU2. Now move machine account to OU2 and reboot: 1. When done from a Windows client via ADUC GUI: GPO is applied correctly. 2. When done via UMC: GPO is not applied => Bug This is before the move: root@master10:~# univention-s4search cn=win7pro230 # record 1 dn: CN=WIN7PRO230,OU=OU1,DC=ar41i1,DC=qa This is after: root@master10:~# univention-s4search cn=win7pro230 # record 1 dn: CN=win7pro230,OU=OU2,DC=ar41i1,DC=qa Restoring the original uppercase spelling fixes the issue (took two reboots in my case): root@master10:~# ldbrename -H /var/lib/samba/private/sam.ldb \ CN=win7pro230,OU=OU2,DC=ar41i1,DC=qa \ CN=WIN7PRO230,OU=OU2,DC=ar41i1,DC=qa
Created attachment 9487 [details] preserve_case_in_sync_from_ucs_move.patch This patch should fix it and improve a debugging message.
ucs-test - 7f3c49c06c63f0ce59ea8fece8e0e06ba21a7ba2 added 403rename_computer_object_ad_and_check_case univention-s4-connector - 0478a563dc5ee43d67f9f95f662446523f372bc9 applied patch yaml - 22272aff7c858bcf3913a17c6fc06ca7db1b010e
Ok, works, test case too and the advisory looks good.
<http://errata.software-univention.de/ucs/4.3/14.html>