Roaming profiles in ns7 Active Directory

Isn’t it possible to use the user-home-folder ?

1 Like

That quickly becomes a mess with storage requirements or profile issues. If users can easily find it, they can easily break it :wink:

1 Like

Maybe we can/should use a more modern way like UE-V ?
User Experience Virtualization overview

Afaik that needs to store settings in the user profile, so gets me nothing … ?

So, what we´ re planning during christmas holidays is a setting, where we´ ll try to put all “My Documents” of Windows and all “Home” Folder to the standard Nethserver share of the specified user.
The approach will be, that on Windows clients we probably use the netlogon.bat and on Linux clients (SUSE- Gnome) I don´ t have a clue yet (e.g. something like https://serverfault.com/questions/504759/heterogeneous-environment-roaming-profiles ).
I´ ll report…and I´ m open for ideas…and will there be ever a out of the box solution by NS?

I’d like to expand the AD GPO support for both Linux (sssd) and Windows (native) clients.

As said during the NethServer Conference, we could develop some esmith templates for GPOs, covering basic use cases. For instance,

  • home dirs (windows, linux)
  • roaming profiles (windows)
  • host based shell access (Linux)
5 Likes

And would that be implementable with a switch in the NS GUI?

1 Like

I have correct my post:

I created a directory /var/lib/nethserver/profiles and then assigned it the following permissions: chmod 1757 /var/lib/nethserver/profiles The ‘everyone’ permissions of 7 is what allows the user account to create their own profiles directory upon first login. The sticky bit means that they can delete files/directories in their own profiles directory, but nobody else can, since they are not the owner.
TEST and work !

1 Like

My 2 cent’s:
Would it be possible to setup this scenario:
Two locations with two NS7 servers.
Location no #1: NS7 as SambaAD
Location no #2: NS7 joined to Loc#1 as a “secondary” sambaAD server.
connection with IPsec so servers can see each other.

Users from Location #1 has Roaming profiles setup at main SambaAD server
Users from Location #2 has Roaming profiles setup at server located at secondary NS7 server joined to SambaAD?

Would it be possible to setup ?

so far that is nowhere implemented in NS, right?

Not yet, unfortunately

For SUSE Linux Clients we found a solution- Mounting the home directory directly at the users home on NS- which is absolutly great- all files and settings are directly stored at the Server and also therefore backuped with the normal backup prozedure- only the network connection must be garanteed. Done on every cllent makes roaming unnecessary.

6 Likes

Hi everybody,

I am trying to set up roaming profiles and it works now but … with manual configuration. I think I miss something.

I don’t quite understand uliversal’s approach further up here. Too much command line for me, til now. I created then a share “profiles” via the nethserver web interface and changed the path there via RSAT tools just as uliversal did. Upon login in a folder for the user is created, then ‘access denied’ follows and the roaming profil cannot be loaded. I changed the ownership of the newly created folder to the respective user and now roaming profiles work. Before every folder on that share has as owner ‘root’

I would like that to work automatically.

Why is the owner ‘root’ in the first place? Shouldn’t that be the creater or the owner I set in the web interface of the server?

Do I miss something else to get roaming profiles?

I have nethserver 7.4 and Windows 7 Professional, if that’s important.

Thanks for your help!

edit: Is there is difference between ‘server based’ and ‘roaming’ profiles? I understand them to be the same thing.

Did you try to change this setting in Windows file server page? (Applies to new dirs only)

3 Likes

That was missing. Roaming profiles are operatinal now!

Thank you for the great support here! and great product!

1 Like

Would be great if NS7 had embedded tools for enabling roaming profiles and mounting of share.

4 Likes

It’s still in roadmap, with other improvements to the local AD accounts provider!

7 Likes

An inquiry about the current state of affairs…
With 7.9, is it still necessary to create the user profile folders manually, or is this now done by default with the AD service provider?

Best regards, Marko

Yes, nothing changed in the last year!

2 Likes

Well, neither did Windows…

It’s still Windows 10, just more bloated… :slight_smile:

1 Like