samba-technical@lists.samba.org
[Top] [All Lists]

Re: [Samba4] Duplicate ntSecurityDescriptor during provisioning

Subject: Re: [Samba4] Duplicate ntSecurityDescriptor during provisioning
From: Matthias Dieter WallnÃfer
Date: Thu, 17 Sep 2009 23:57:11 +0200
Hi all together,

yeah, this problem needs tracking. I also suffer from it (I think you all too): consider the group policy objects under "CN=Policies,CN=System,<domain-DN>". One is the security descriptor added by the "provision_group_policy.ldif" file, therefore this should be the right one, and the other seems to be added (I don't exactly know - but I imagine) by the new module.

Matthias

Nadezhda Ivanova schrieb:
Hi,
Are you using alpha8 or the current master? It could be related to a patch 
regarding security descriptors that we pushed Monday evening.

Regards,
Nadya
----- Original Message -----
From: samba-technical-bounces@xxxxxxxxxxxxxxx 
<samba-technical-bounces@xxxxxxxxxxxxxxx>
To: Andrew Bartlett <abartlet@xxxxxxxxx>, Endi Sukma Dewata <edewata@xxxxxxxxxx>
Cc: Dmitri Pal <dpal@xxxxxxxxxx>, samba-technical@xxxxxxxxxxxxxxx 
<samba-technical@xxxxxxxxxxxxxxx>
Sent: Wednesday, September 16, 2009 3:38:59 PM GMT-0800 America;Los_Angeles
Subject: [Samba4] Duplicate ntSecurityDescriptor during provisioning

Andrew,
I'm trying to run the test against OpenLDAP to verify my environment before testing FDS again. I found that the provisioning script failed to load the first entry in provision_group_policy.ldif. Here is the error message:

_ldb.LdbError: (19, 'LDAP error 19 LDAP_CONSTRAINT_VIOLATION - <nTSecurityDescriptor: multiple values provided> <>')

In the LDIF file the entry only has 1 nTSecurityDescriptor value, but when I check the attribute in ildap_add() it actually has 2 values.

Do you have any idea? Thanks.

--
Endi S. Dewata



<Prev in Thread] Current Thread [Next in Thread>