samba and NTconfig.pol - SMB
This is a discussion on samba and NTconfig.pol - SMB ; (reasonably off topic I think but I expect that the knowledgeable people are
just in this group :-))
A number of samba docs on the use of samba as a PDC for the windows
environment state that putting the mentioned ...
-
samba and NTconfig.pol
(reasonably off topic I think but I expect that the knowledgeable people are
just in this group :-))
A number of samba docs on the use of samba as a PDC for the windows
environment state that putting the mentioned file in the netlogon samba
share will provide adequate protection at the windows user level. (aka
roaming stuff) Did anyone ever/actualy try this out ?
I did get the poledit from W2k advanced server and was hoping it would be
able, under XP, to write the system/user policy to the samba server share ..
it even doesn't want to start complaining about missing adm files and the
standard GPO structures seem to be useless with samba (2.2.8a)
anyone ?
TIA
-
Re: samba and NTconfig.pol
On Thu, 17 Jul 2003 22:59:55 +0200, imbsysop wrote:
....
> I did get the poledit from W2k advanced server and was hoping it would
> be able, under XP, to write the system/user policy to the samba server
> share .. it even doesn't want to start complaining about missing adm
> files and the standard GPO structures seem to be useless with samba
> (2.2.8a)
>
You should place the poledit executable on a distinct share or even
netlogon, and make that share readable to all but writeable to admin only.
You can also set "hide unreadable=yes" for the share and give it a 700
perm.
Then, logon as domain admin on a sample pc with 2K as os. You will find
the adm template(s) in its windows tree - probably in the inf folder - so
you can start working on it. Save the resulting (nt)config.pol on the
netlogon share.
--
WinXXP error#4711: TCPA/NGSCB VIOLATION: Non-approved partition-id 83 (linux)
discovered. Online-recertification and reactivation of Microsoft products
required, 3 days grace period: http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html
http://moon.hipjoint.de/tcpa-palladium-faq-de.html (DE)
-
Re: samba and NTconfig.pol
"Walter Mautner" wrote in message
news
an.2003.07.19.11.00.12.441990@spamgourmet.com...
> On Thu, 17 Jul 2003 22:59:55 +0200, imbsysop wrote:
>
> ...
> > I did get the poledit from W2k advanced server and was hoping it would
> > be able, under XP, to write the system/user policy to the samba server
> > share .. it even doesn't want to start complaining about missing adm
> > files and the standard GPO structures seem to be useless with samba
> > (2.2.8a)
> >
> You should place the poledit executable on a distinct share or even
> netlogon, and make that share readable to all but writeable to admin only.
... thnx but it is not a matter of the location where the program is residing
... it does not want to start with the XP adm files it just freezes .. I got
the advice to edit the XP adm files and to remove all stuff that reads "GP
only .." or something along those lines or even better just compare XP & W2K
adm files for collating syntax ..
-
Re: samba and NTconfig.pol
On Sat, 19 Jul 2003 18:53:46 +0200, imbsysop wrote:
....
> .. thnx but it is not a matter of the location where the program is residing
> .. it does not want to start with the XP adm files it just freezes .. I got
> the advice to edit the XP adm files and to remove all stuff that reads "GP
> only .." or something along those lines or even better just compare XP & W2K
> adm files for collating syntax ..
Hmm ... now since it's a rather long time ago, I don't exactly remember if
I used the w2k adm templates or some from XP. However - w2k templates will
work for XP also, so get a 2K.
But then, there are some different versions of poledit - did you really
get yours from a 2K server cd? That version should be able to load 2 or 3
templates at once and merge them.
Also, loading the templates sometimes takes a long time, during which the
program appears to be frozen. Take patience ...
--
WinXXP error#4711: TCPA/NGSCB VIOLATION: Non-approved partition-id 83 (linux)
discovered. Online-recertification and reactivation of Microsoft products
required, 3 days grace period: http://www.cl.cam.ac.uk/~rja14/tcpa-faq.html
http://moon.hipjoint.de/tcpa-palladium-faq-de.html (DE)