нет доступа к редактрованию GptTmpl.inf

Обсуждение сетевых операционных систем и их применения (Windows, Linux, FreeBSD, Novell и т.д.)

Модератор: Модераторы

Новый участник
Сообщения: 1
Зарегистрирован: 19 дек 2007, 09:29

Сообщение berezikov » 19 дек 2007, 09:34

есть 2 контроллера домена: adserver (был изначально контроллером) и fileserv (поднят недавно для повышения надежности). Проблема - при изменении групповой политики вылазит ошибка

Отказано в доступе
не удалось сохранить \\adrem.local\SYSVOL\Adrem.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf. Убедитесь в том что вы имеете достаточные права на этот объект.

Так же невозможно отредактировать этот файл если попасть к нему по пути \\adrem.local\SYSVOL\Adrem.local\... - так же нет прав на изменение
Зато если зайти в этот файлик на любом из серверов c:\windows\sysvol... все прекрасно редактируется.
Т.е. нет прав на редактирование встроенной dfs шары sysvol
Размер папок SYSVOL на обоих серверах одинаковый.
на обоих серверах папка sysvol расшарена с правами:
все - чтение
прошедшие проверку и админы - полный доступ

к тому же если зайти не на \\adrem.local\... , а на \\fileserv\... или \\adserver\... то редактировать возможно

И еще: создать файл/папку получается в любой директории: \\adrem.local\SYSVOL и глубже, причем так же возможно удаление GptTmpl.inf файла, его копирование и вообще что угодно кроме редактирования.

ADSERVER

C:\Documents and Settings\Администратор>dcdiag

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site\ADSERVER
Starting test: Connectivity
......................... ADSERVER passed test Connectivity

Doing primary tests

Testing server: Default-First-Site\ADSERVER
Starting test: Replications
......................... ADSERVER passed test Replications
Starting test: NCSecDesc
......................... ADSERVER passed test NCSecDesc
Starting test: NetLogons
......................... ADSERVER passed test NetLogons
Starting test: Advertising
......................... ADSERVER passed test Advertising
Starting test: KnowsOfRoleHolders
......................... ADSERVER passed test KnowsOfRoleHolders
Starting test: RidManager
......................... ADSERVER passed test RidManager
Starting test: MachineAccount
......................... ADSERVER passed test MachineAccount
Starting test: Services
......................... ADSERVER passed test Services
Starting test: ObjectsReplicated
......................... ADSERVER passed test ObjectsReplicated
Starting test: frssysvol
......................... ADSERVER passed test frssysvol
Starting test: frsevent
......................... ADSERVER passed test frsevent
Starting test: kccevent
......................... ADSERVER passed test kccevent
Starting test: systemlog
......................... ADSERVER passed test systemlog
Starting test: VerifyReferences
......................... ADSERVER passed test VerifyReferences

Running partition tests on : TAPI3Directory
Starting test: CrossRefValidation
......................... TAPI3Directory passed test CrossRefValidation

Starting test: CheckSDRefDom
......................... TAPI3Directory passed test CheckSDRefDom

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation

Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation

Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running partition tests on : Adrem
Starting test: CrossRefValidation
......................... Adrem passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Adrem passed test CheckSDRefDom

Running enterprise tests on : Adrem.local
Starting test: Intersite
......................... Adrem.local passed test Intersite
Starting test: FsmoCheck
......................... Adrem.local passed test FsmoCheck



C:\Documents and Settings\Администратор>netdiag

.........................................

Computer Name: ADSERVER
DNS Host Name: adserver.Adrem.local
System info : Windows 2000 Server (Build 3790)
Processor : x86 Family 15 Model 2 Stepping 5, GenuineIntel
List of installed hotfixes :
KB833407
KB890046
KB893756
KB896358
KB896424
KB896428
KB898715
KB899587
KB899588
KB899589
KB899591
KB900725
KB901017
KB901214
KB902400
KB904706
KB905414
KB908519
KB908531
KB910437
KB911280
KB911562
KB911564
KB911567
KB911897
KB911927
KB912919
KB914388
KB914389
KB917159
KB917344
KB917422
KB917537
KB917734
KB917953
KB918439
KB918899
KB920213
KB920214
KB920670
KB920683
KB920685
KB921398
KB921883
KB922582
KB922616
KB922819
KB923191
KB923414
KB923689
KB923694
KB923980
KB924191
KB924496
KB925398_WMP64
KB925454
KB925486
KB929969
Q147222


Netcard queries test . . . . . . . : Passed
[WARNING] The net card 'Kerio VPN adapter' may not be working because it has
not received any packets.



Per interface results:

Adapter : ╧юфъы■ўхэшх яю ыюъры№эющ ёхЄш 3

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : adserver
IP Address . . . . . . . . : 192.168.0.1
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.0.23
Primary WINS Server. . . . : 127.0.0.1
Dns Servers. . . . . . . . : 127.0.0.1


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Failed
The test failed. We were unable to query the WINS servers.

Adapter : Kerio VPN

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : adserver
IP Address . . . . . . . . : 172.26.48.4
Subnet Mask. . . . . . . . : 255.255.255.0
IP Address . . . . . . . . : 169.254.1.247
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . :
NetBIOS over Tcpip . . . . : Disabled
Dns Servers. . . . . . . . : 172.26.48.1

IpConfig results . . . . . : Failed
Pinging DHCP server - not reachable
WARNING: DHCP server may be down.

AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.

NetBT name test. . . . . . : Skipped
NetBT is disabled on this interface. [Test skipped]

WINS service test. . . . . : Skipped
NetBT is disable on this interface. [Test skipped].


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{2EA245C1-04AA-43A4-927A-3C84840D959F}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '127.0.0.1' a
nd other DCs also have some of the names registered.
[WARNING] The DNS entries for this DC are not registered correctly on DNS se
rver '172.26.48.1'. Please wait for 30 minutes for DNS server replication.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{2EA245C1-04AA-43A4-927A-3C84840D959F}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{2EA245C1-04AA-43A4-927A-3C84840D959F}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully





FILESERV


C:\Documents and Settings\Администратор.ADREM>dcdiag

Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site\FILESERV
Starting test: Connectivity
......................... FILESERV passed test Connectivity

Doing primary tests

Testing server: Default-First-Site\FILESERV
Starting test: Replications
......................... FILESERV passed test Replications
Starting test: NCSecDesc
......................... FILESERV passed test NCSecDesc
Starting test: NetLogons
......................... FILESERV passed test NetLogons
Starting test: Advertising
......................... FILESERV passed test Advertising
Starting test: KnowsOfRoleHolders
......................... FILESERV passed test KnowsOfRoleHolders
Starting test: RidManager
......................... FILESERV passed test RidManager
Starting test: MachineAccount
......................... FILESERV passed test MachineAccount
Starting test: Services
......................... FILESERV passed test Services
Starting test: ObjectsReplicated
......................... FILESERV passed test ObjectsReplicated
Starting test: frssysvol
......................... FILESERV passed test frssysvol
Starting test: frsevent
......................... FILESERV passed test frsevent
Starting test: kccevent
......................... FILESERV passed test kccevent
Starting test: systemlog
......................... FILESERV passed test systemlog
Starting test: VerifyReferences
......................... FILESERV passed test VerifyReferences

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation

Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation

Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running partition tests on : Adrem
Starting test: CrossRefValidation
......................... Adrem passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Adrem passed test CheckSDRefDom

Running enterprise tests on : Adrem.local
Starting test: Intersite
......................... Adrem.local passed test Intersite
Starting test: FsmoCheck
......................... Adrem.local passed test FsmoCheck

C:\Documents and Settings\Администратор.ADREM>netdiag

......................................

Computer Name: FILESERV
DNS Host Name: fileserv.Adrem.local
System info : Microsoft Windows Server 2003 (Build 3790)
Processor : x86 Family 15 Model 6 Stepping 4, GenuineIntel
List of installed hotfixes :
KB901105
Q147222


Netcard queries test . . . . . . . : Passed
GetStats failed for '╧Ё ьющ ярЁрыыхы№э√щ яюЁЄ'. [ERROR_NOT_SUPPORTED]
[WARNING] The net card '╠шэшяюЁЄ WAN (PPTP)' may not be working because it h
as not received any packets.
[WARNING] The net card '╠шэшяюЁЄ WAN (PPPoE)' may not be working because it
has not received any packets.
[WARNING] The net card '╠шэшяюЁЄ WAN (IP)' may not be working because it has
not received any packets.
GetStats failed for '╠шэшяюЁЄ WAN (L2TP)'. [ERROR_NOT_SUPPORTED]



Per interface results:

Adapter : ╧юфъы■ўхэшх яю ыюъры№эющ ёхЄш

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : fileserv
IP Address . . . . . . . . : 192.168.0.3
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.0.23
Primary WINS Server. . . . : 192.168.0.1
Dns Servers. . . . . . . . : 192.168.0.1


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Passed


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{B78F3A7A-C84D-42E3-B97E-6312892B2D3B}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '192.168.0.1'
and other DCs also have some of the names registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{B78F3A7A-C84D-42E3-B97E-6312892B2D3B}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{B78F3A7A-C84D-42E3-B97E-6312892B2D3B}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Passed
Secure channel for domain 'ADREM' is to '\\adserver.Adrem.local'.


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully

C:\Documents and Settings\Администратор.ADREM>ipconfig /?




Судя по выводам dcdiag и netdiag всё в порядке.
В чем может быть проблема ?

Вернуться в Сетевые операционные системы

Кто сейчас на конференции

Сейчас этот форум просматривают: нет зарегистрированных пользователей и гости: 16