Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Ok I have setup 2 spanking new 2008 64 bit servers on our existing 2003 domain, old servers which are 32 bit. Eventually I want to transfer all of the roles and user date and apps to the new servers. Problem I am having is software deployment. I create a folder on the new servers and put an MSI into it, give it the same perms as is on the 2003 servers but the software does not install in any format on the client i.e assigned published machine or user. The error is the file cannot be found. I have checked the UNC path and permissions but nothing is amiss there.

 

Can you deploy 32 bit apps from a 64 bit server is probably the most direct question?

Posted
I have checked the UNC path and permissions but nothing is amiss there.

 

How's about on the share itself, what permissions are granted to that?

 

--

David Hicks

Posted (edited)

Has the policy been given the correct security assignment?

Has the machine been given permission to read and apply the policy?

Can the servers holding the policy see the client? Ping by IP and Netbios Name?

 

A common mistake when assigning msi installation policies is failing to add authenticated computers.

Also make sure that machine has rights to the UNC path.

rDNS is vital to group policies, if you use rDNS then ensure that the database is upto date and consistent if you have multiple entries in your reverse lookups policies can fail as the server can't find the right machine!

Edited by m25man
Posted
Has the policy been given the correct security assignment?

Has the machine been given permission to read and apply the policy?

Can the servers holding the policy see the client? Ping by IP and Netbios Name?

 

If I assign publish the app from a windows 2003 server and folder it works fine. Its only when the share is on windows 2008 x64 I get the error.

Posted
For testing purposes everyone has full cotrol at NTFS and share level so it definatley is not a permissions thing or not in relation to a 2003 server anyway.
Posted
I don't think that the everyone group actually covers everyone anymore so it may be worth adding domain computers as this is the group that will be required for the deployment and it will fully rule out permissions.
Posted (edited)

Ok I will try that, but what happens when I want to try and get rid of the 2003 servers. Do I then have to raise the functional levels of the forest and domain controller?

 

Ah - on which machine are you running the AD tool?

 

Yes it worked thanks jinnandtonnix, but what about when I want to get rid of the 2003 DC's?

Edited by jsnetman

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...