# Remote file Copy from Windows Share

**URL:** <https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695>\
**Category:** Chef Infra (archive)\
**Created:** [August 6, 2014, 2:28pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695 "2014-08-06T14:28:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ChristopherHall](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@ChristopherHall](https://discourse.chef.io/u/ChristopherHall)\
**Post date:** [August 6, 2014, 2:28pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695/1 "2014-08-06T14:28:10Z")

</div>

Hi Chefs  
I’m having trouble again 🙂

I’m trying to copy a file from a share on a windows server from a target node via chef. The purpose for it to copy dll drop files from a share and dumped into d:\installs so it can later be unzipped. At the moment I am having issues trying to connect to the share.  
I’ve tried running the chef run as a local admin on the target node (which used to work), using AD creds and also a different local account to no avail.  
The linux server was recently added to our domain, but this was failing before that happened.  
I’ve tried a batch file mapping a drive then copy, a powershell script doing the same, native ruby and now this remote file resource. Same error everytime, it looks like a permissions error on Windows, but the file share is currently set full permission to everyone on both Share permissions and filesystem permissions.  
I’m seeing NULL\_SID event log entries where the auth fails, but this is on the target node, not the one that hosts the share.

Can any offer anything to look at?

Chef server is Ubuntu 14.04 using PBIS to auth via AD (might I need Samba installing now AD is in use for Auth?)  
Windows nodes are running Server 2008R2 patched up-to-date. All are VM’s. All one the same AD and DNS domain.

“myserver  
DEBUG: :relay\_output\_from\_backend =\> [“[ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)”, “================================================================================\r\nError executing action `create` on resource ‘remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]’\r\n================================================================================\r\n\r\nErrno::EACCES\r\n-------------\r\nPermission denied - //targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n\r\nResource Declaration:\r\n---------------------\r\n# In c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb\r\n\r\n 27: remote\_file “d:\\installs\\#{fname}” do \r\n 28: source “file:////#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)”\r\n 29: end\r\n 30: \r\n\r\nCompiled Resource:\r\n------------------\r\n# Declared in c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb:27:in `from\_file’\r\n\r\nremote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”) do\r\n provider Chef::Provider::RemoteFile\r\n action “create”\r\n retries 0\r\n retry\_delay 2\r\n guard\_interpreter :default\r\n path “d:\\installs\\7.1\_HF05\_Overlay\_SAML\_fix.zip”\r\n backup 5\r\n atomic\_update true\r\n source [“file:////targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip”]\r\n use\_etag true\r\n use\_last\_modified true\r\n cookbook\_name “AW\_DLLDrop”\r\n recipe\_name “default”\r\nend\r\n\r\n”]”

Thanks  
Chris

---

<div class="post-metadata">

**Author:** ![Adam\_Edwards1](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/adam_edwards1/32/27_2.png) [@Adam\_Edwards1](https://discourse.chef.io/u/Adam_Edwards1)\
**Post date:** [August 6, 2014, 4:08pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695/2 "2014-08-06T16:08:36Z")

</div>

Christopher, to clarify a few things here:

1. 

```
  Are you copying from a windows machine to a windows machine? Or is

```

one of the systems a Linux system

1. 

```
  You’re saying that even without any Chef / Ruby involved you can’t

```

access the share?

If those things are true, I’d try the following:

1. 

```
  Turn off the firewall

```

2. 

```
  Try using credentials for a local account as well as a domain

```

credentials

1. 

```
  Check the security log to see if you get an audit event for a

```

failed logon

-Adam

_From:_ [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]

_Sent:_ Wednesday, August 6, 2014 7:28 AM  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] Remote file Copy from Windows Share

Hi Chefs

I’m having trouble again J

I’m trying to copy a file from a share on a windows server from a target  
node via chef. The purpose for it to copy dll drop files from a share and  
dumped into d:\installs so it can later be unzipped. At the moment I am  
having issues trying to connect to the share.

I’ve tried running the chef run as a local admin on the target node (which  
used to work), using AD creds and also a different local account to no  
avail.

The linux server was recently added to our domain, but this was failing  
before that happened.

I’ve tried a batch file mapping a drive then copy, a powershell script  
doing the same, native ruby and now this remote file resource. Same error  
everytime, it looks like a permissions error on Windows, but the file share  
is currently set full permission to everyone on both Share permissions and  
filesystem permissions.

I’m seeing NULL\_SID event log entries where the auth fails, but this is on  
the target node, not the one that hosts the share.

Can any offer anything to look at?

Chef server is Ubuntu 14.04 using PBIS to auth via AD (might I need Samba  
installing now AD is in use for Auth?)

Windows nodes are running Server 2008R2 patched up-to-date. All are VM’s.  
All one the same AD and DNS domain.

“myserver

DEBUG: :relay\_output\_from\_backend =\> [“[ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)”,  
"================================================================================\r\nError  
executing action `create` on resource  
’remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]’\r\n================================================================================\r\n\r\nErrno::EACCES\r\n-------------\r\nPermission  
denied -  
//targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n\r\nResource  
Declaration:\r\n---------------------\r\n# In  
c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb\r\n\r\n 27:  
remote\_file “d:\\installs\\#{fname}” do \r\n 28: source “  
file:////#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)  
\<file:///\#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\>”\r\n  
29: end\r\n 30: \r\n\r\nCompiled Resource:\r\n------------------\r\n#  
Declared in c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb:27:in  
`from\_file’\r\n\r\nremote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”)  
do\r\n provider Chef::Provider::RemoteFile\r\n action “create”\r\n  
retries 0\r\n retry\_delay 2\r\n guard\_interpreter :default\r\n path  
"d:\\installs\\7.1\_HF05\_Overlay\_SAML\_fix.zip"\r\n backup 5\r\n  
atomic\_update true\r\n source [“  
file:////targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip  
\<file:///\targetserver\server.installs\dll.drops\7.1\_HF05\_Overlay\_SAML\_fix.zip\>”]\r\n  
use\_etag true\r\n use\_last\_modified true\r\n cookbook\_name  
"AW\_DLLDrop"\r\n recipe\_name “default”\r\nend\r\n\r\n"]”

_Thanks_

_Chris_

---

<div class="post-metadata">

**Author:** ![ChristopherHall](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@ChristopherHall](https://discourse.chef.io/u/ChristopherHall)\
**Post date:** [August 6, 2014, 4:38pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695/3 "2014-08-06T16:38:11Z")

</div>

Hi Adam,  
It’s windows to windows. Only the Chef server is Linux but that has little to do with anything (I think/hope).  
Without Chef involvement the shares are perfectly accessible, even using the user account that chef client is run as.

Firewall is off completely and I’m using AD creds and local creds. When Chef run is performed against the two windows nodes, one will complete successfully (it is the node hosting the share) and the other node will fail with ‘authentication failed – password incorrect’ (which I think is a catch-all error).  
The security log of the second node shows authentication error with a null sid.  
The first node (hosting the share) shows no errors.  
The security of the D:\installs folder also show effective permissions as full control for both ad login and local account.

I’m wondering if it’s something to do with the user that the chef client is run as on each node? Maybe machine localsystem? Does chef-client run with the creds that winrm provides to it or do those creds simply auth against WinRM and then localsystem takes over? Chef-Client is being run on-demand, it is not installed as a service due to the way we will be using Chef.

Thanks  
Chris

From: Adam Edwards [[mailto:adamed@getchef.com](mailto:adamed@getchef.com)]  
Sent: 06 August 2014 17:09  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] RE: Remote file Copy from Windows Share

Christopher, to clarify a few things here:

1. 

```
  Are you copying from a windows machine to a windows machine? Or is one of the systems a Linux system

```

2. 

```
  You’re saying that even without any Chef / Ruby involved you can’t access the share?

```

If those things are true, I’d try the following:

1. 

```
  Turn off the firewall

```

2. 

```
  Try using credentials for a local account as well as a domain credentials

```

3. 

```
  Check the security log to see if you get an audit event for a failed logon

```

-Adam

From: [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]  
Sent: Wednesday, August 6, 2014 7:28 AM  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)[mailto:chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] Remote file Copy from Windows Share

Hi Chefs  
I’m having trouble again 🙂

I’m trying to copy a file from a share on a windows server from a target node via chef. The purpose for it to copy dll drop files from a share and dumped into d:\installs so it can later be unzipped. At the moment I am having issues trying to connect to the share.  
I’ve tried running the chef run as a local admin on the target node (which used to work), using AD creds and also a different local account to no avail.  
The linux server was recently added to our domain, but this was failing before that happened.  
I’ve tried a batch file mapping a drive then copy, a powershell script doing the same, native ruby and now this remote file resource. Same error everytime, it looks like a permissions error on Windows, but the file share is currently set full permission to everyone on both Share permissions and filesystem permissions.  
I’m seeing NULL\_SID event log entries where the auth fails, but this is on the target node, not the one that hosts the share.

Can any offer anything to look at?

Chef server is Ubuntu 14.04 using PBIS to auth via AD (might I need Samba installing now AD is in use for Auth?)  
Windows nodes are running Server 2008R2 patched up-to-date. All are VM’s. All one the same AD and DNS domain.

“myserver  
DEBUG: :relay\_output\_from\_backend =\> [“[ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)[http://ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)”, “================================================================================\r\nError executing action `create` on resource ‘remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]’\r\n================================================================================\r\n\r\nErrno::EACCES\r\n-------------\r\nPermission denied - //targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n\r\nResource Declaration:\r\n---------------------\r\n# In c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb\r\n\r\n 27: remote\_file “d:\\installs\\#{fname}” do \r\n 28: source “file:////#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\<file:///\#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\>”\r\n 29: end\r\n 30: \r\n\r\nCompiled Resource:\r\n------------------\r\n# Declared in c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb:27:in `from\_file’\r\n\r\nremote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”) do\r\n provider Chef::Provider::RemoteFile\r\n action “create”\r\n retries 0\r\n retry\_delay 2\r\n guard\_interpreter :default\r\n path “d:\\installs\\7.1\_HF05\_Overlay\_SAML\_fix.zip”\r\n backup 5\r\n atomic\_update true\r\n source [“file:////targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\<file:///\targetserver\server.installs\dll.drops\7.1\_HF05\_Overlay\_SAML\_fix.zip\>”]\r\n use\_etag true\r\n use\_last\_modified true\r\n cookbook\_name “AW\_DLLDrop”\r\n recipe\_name “default”\r\nend\r\n\r\n”]”

Thanks  
Chris

---

<div class="post-metadata">

**Author:** ![Adam\_Edwards1](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/adam_edwards1/32/27_2.png) [@Adam\_Edwards1](https://discourse.chef.io/u/Adam_Edwards1)\
**Post date:** [August 6, 2014, 4:43pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695/4 "2014-08-06T16:43:24Z")

</div>

Hmm – so you are running Chef remotely via WinRM? If that’s the case, you  
should add credssp to your winrm listener. You can do that with powershell  
by setting the value below to true:

ls WSMan:\localhost\Service\Auth\CredSSP

# if that shows false, you can set it to true:

si WSMan:\localhost\Service\Auth\CredSSP $true

That should allow your credentials to do one extra hop off the machine.

_From:_ [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]

_Sent:_ Wednesday, August 6, 2014 9:38 AM  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] RE: RE: Remote file Copy from Windows Share

Hi Adam,

It’s windows to windows. Only the Chef server is Linux but that has  
little to do with anything (I think/hope).

Without Chef involvement the shares are perfectly accessible, even using  
the user account that chef client is run as.

Firewall is off completely and I’m using AD creds and local creds. When  
Chef run is performed against the two windows nodes, one will complete  
successfully (it is the node hosting the share) and the other node will  
fail with ‘authentication failed – password incorrect’ (which I think is a  
catch-all error).

The security log of the second node shows authentication error with a null  
sid.

The first node (hosting the share) shows no errors.

The security of the D:\installs folder also show effective permissions as  
full control for both ad login and local account.

I’m wondering if it’s something to do with the user that the chef client is  
run as on each node? Maybe machine localsystem? Does chef-client run with  
the creds that winrm provides to it or do those creds simply auth against  
WinRM and then localsystem takes over? Chef-Client is being run on-demand,  
it is not installed as a service due to the way we will be using Chef.

Thanks

Chris

_From:_ Adam Edwards [[mailto:adamed@getchef.com](mailto:adamed@getchef.com) [adamed@getchef.com](mailto:adamed@getchef.com)]  
_Sent:_ 06 August 2014 17:09  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] RE: Remote file Copy from Windows Share

Christopher, to clarify a few things here:

1. 

```
  Are you copying from a windows machine to a windows machine? Or is

```

one of the systems a Linux system

1. 

```
  You’re saying that even without any Chef / Ruby involved you can’t

```

access the share?

If those things are true, I’d try the following:

1. 

```
  Turn off the firewall

```

2. 

```
  Try using credentials for a local account as well as a domain

```

credentials

1. 

```
  Check the security log to see if you get an audit event for a

```

failed logon

-Adam

_From:_ [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]

_Sent:_ Wednesday, August 6, 2014 7:28 AM  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] Remote file Copy from Windows Share

Hi Chefs

I’m having trouble again J

I’m trying to copy a file from a share on a windows server from a target  
node via chef. The purpose for it to copy dll drop files from a share and  
dumped into d:\installs so it can later be unzipped. At the moment I am  
having issues trying to connect to the share.

I’ve tried running the chef run as a local admin on the target node (which  
used to work), using AD creds and also a different local account to no  
avail.

The linux server was recently added to our domain, but this was failing  
before that happened.

I’ve tried a batch file mapping a drive then copy, a powershell script  
doing the same, native ruby and now this remote file resource. Same error  
everytime, it looks like a permissions error on Windows, but the file share  
is currently set full permission to everyone on both Share permissions and  
filesystem permissions.

I’m seeing NULL\_SID event log entries where the auth fails, but this is on  
the target node, not the one that hosts the share.

Can any offer anything to look at?

Chef server is Ubuntu 14.04 using PBIS to auth via AD (might I need Samba  
installing now AD is in use for Auth?)

Windows nodes are running Server 2008R2 patched up-to-date. All are VM’s.  
All one the same AD and DNS domain.

“myserver

DEBUG: :relay\_output\_from\_backend =\> [“[ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)”,  
"================================================================================\r\nError  
executing action `create` on resource  
’remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]’\r\n================================================================================\r\n\r\nErrno::EACCES\r\n-------------\r\nPermission  
denied -  
//targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n\r\nResource  
Declaration:\r\n---------------------\r\n# In  
c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb\r\n\r\n 27:  
remote\_file “d:\\installs\\#{fname}” do \r\n 28: source “  
file:////#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)  
\<file:///\#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\>”\r\n  
29: end\r\n 30: \r\n\r\nCompiled Resource:\r\n------------------\r\n#  
Declared in c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb:27:in  
`from\_file’\r\n\r\nremote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”)  
do\r\n provider Chef::Provider::RemoteFile\r\n action “create”\r\n  
retries 0\r\n retry\_delay 2\r\n guard\_interpreter :default\r\n path  
"d:\\installs\\7.1\_HF05\_Overlay\_SAML\_fix.zip"\r\n backup 5\r\n  
atomic\_update true\r\n source [“  
file:////targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip  
\<file:///\targetserver\server.installs\dll.drops\7.1\_HF05\_Overlay\_SAML\_fix.zip\>”]\r\n  
use\_etag true\r\n use\_last\_modified true\r\n cookbook\_name  
"AW\_DLLDrop"\r\n recipe\_name “default”\r\nend\r\n\r\n"]”

_Thanks_

_Chris_

---

<div class="post-metadata">

**Author:** ![ChristopherHall](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@ChristopherHall](https://discourse.chef.io/u/ChristopherHall)\
**Post date:** [August 6, 2014, 5:48pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695/5 "2014-08-06T17:48:12Z")

</div>

Hi Adam,  
Thanks for that, it seems to have helped. Authenticating via AD seems to be working ok.  
I’m now getting an error saying the dir isn’t there (which is clearly is – I have checked the paths).  
I think it’s looking for the path on the local system rather that the remote one. I suspect this is me messing up some syntax 🙂  
Here is the section out of the recipe:  
“

# Dll drop filename (in full, no path)

# ie fname = “7.1\_HF05\_Overlay\_SAML\_fix.zip”

fname = "7.1\_HF05\_Overlay\_SAML\_fix.zip"  
path = “file://#{managementServer}/server.installs/dll.drops/#{fname}”

remote\_file “d:\installs\#{fname}” do  
source path  
end  
”

Here is the error:  
“  
remote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”) do  
Win-Node2 provider Chef::Provider::RemoteFile  
Win-Node2 action "create"  
Win-Node2 retries 0  
Win-Node2 retry\_delay 2  
Win-Node2 guard\_interpreter :default  
Win-Node2 path "d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip"  
Win-Node2 backup 5  
Win-Node2 atomic\_update true  
Win-Node2 source [“file://ATLQ-CHEF01.airwatch.qa/server.installs/dll.drops/7.1\_HF05\_Overlay\_SAML\_fix.zip”]  
Win-Node2 use\_etag true  
Win-Node2 use\_last\_modified true  
Win-Node2 cookbook\_name "AW\_DLLDrop"  
Win-Node2 recipe\_name "default"  
Win-Node2 end

Win-Node2 [2014-08-06T13:41:36-04:00] FATAL: Stacktrace dumped to c:/chef/cache/chef-stacktrace.out  
DEBUG: :relay\_output\_from\_backend =\> [“Win-Node2”, “[2014-08-06T13:41:36-04:00] FATAL: Errno::ENOENT: remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip] (AW\_DLLDrop::default line 28) had an error: Errno::ENOENT: No such file or directory - /server.installs/dll.drops/7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n”]  
”

From: Adam Edwards [[mailto:adamed@getchef.com](mailto:adamed@getchef.com)]  
Sent: 06 August 2014 17:43  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] RE: RE: RE: Remote file Copy from Windows Share

Hmm – so you are running Chef remotely via WinRM? If that’s the case, you should add credssp to your winrm listener. You can do that with powershell by setting the value below to true:

ls WSMan:\localhost\Service\Auth\CredSSP

# if that shows false, you can set it to true:

si WSMan:\localhost\Service\Auth\CredSSP $true

That should allow your credentials to do one extra hop off the machine.

From: [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]  
Sent: Wednesday, August 6, 2014 9:38 AM  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)[mailto:chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] RE: RE: Remote file Copy from Windows Share

Hi Adam,  
It’s windows to windows. Only the Chef server is Linux but that has little to do with anything (I think/hope).  
Without Chef involvement the shares are perfectly accessible, even using the user account that chef client is run as.

Firewall is off completely and I’m using AD creds and local creds. When Chef run is performed against the two windows nodes, one will complete successfully (it is the node hosting the share) and the other node will fail with ‘authentication failed – password incorrect’ (which I think is a catch-all error).  
The security log of the second node shows authentication error with a null sid.  
The first node (hosting the share) shows no errors.  
The security of the D:\installs folder also show effective permissions as full control for both ad login and local account.

I’m wondering if it’s something to do with the user that the chef client is run as on each node? Maybe machine localsystem? Does chef-client run with the creds that winrm provides to it or do those creds simply auth against WinRM and then localsystem takes over? Chef-Client is being run on-demand, it is not installed as a service due to the way we will be using Chef.

Thanks  
Chris

From: Adam Edwards [[mailto:adamed@getchef.com](mailto:adamed@getchef.com)]  
Sent: 06 August 2014 17:09  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)[mailto:chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] RE: Remote file Copy from Windows Share

Christopher, to clarify a few things here:

1. 

```
  Are you copying from a windows machine to a windows machine? Or is one of the systems a Linux system

```

2. 

```
  You’re saying that even without any Chef / Ruby involved you can’t access the share?

```

If those things are true, I’d try the following:

1. 

```
  Turn off the firewall

```

2. 

```
  Try using credentials for a local account as well as a domain credentials

```

3. 

```
  Check the security log to see if you get an audit event for a failed logon

```

-Adam

From: [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]  
Sent: Wednesday, August 6, 2014 7:28 AM  
To: [chef@lists.opscode.com](mailto:chef@lists.opscode.com)[mailto:chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
Subject: [chef] Remote file Copy from Windows Share

Hi Chefs  
I’m having trouble again 🙂

I’m trying to copy a file from a share on a windows server from a target node via chef. The purpose for it to copy dll drop files from a share and dumped into d:\installs so it can later be unzipped. At the moment I am having issues trying to connect to the share.  
I’ve tried running the chef run as a local admin on the target node (which used to work), using AD creds and also a different local account to no avail.  
The linux server was recently added to our domain, but this was failing before that happened.  
I’ve tried a batch file mapping a drive then copy, a powershell script doing the same, native ruby and now this remote file resource. Same error everytime, it looks like a permissions error on Windows, but the file share is currently set full permission to everyone on both Share permissions and filesystem permissions.  
I’m seeing NULL\_SID event log entries where the auth fails, but this is on the target node, not the one that hosts the share.

Can any offer anything to look at?

Chef server is Ubuntu 14.04 using PBIS to auth via AD (might I need Samba installing now AD is in use for Auth?)  
Windows nodes are running Server 2008R2 patched up-to-date. All are VM’s. All one the same AD and DNS domain.

“myserver  
DEBUG: :relay\_output\_from\_backend =\> [“Win-Node2[http://ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)”, “================================================================================\r\nError executing action `create` on resource ‘remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]’\r\n================================================================================\r\n\r\nErrno::EACCES\r\n-------------\r\nPermission denied - //targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n\r\nResource Declaration:\r\n---------------------\r\n# In c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb\r\n\r\n 27: remote\_file “d:\\installs\\#{fname}” do \r\n 28: source “file:////#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\<file:///\#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\>”\r\n 29: end\r\n 30: \r\n\r\nCompiled Resource:\r\n------------------\r\n# Declared in c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb:27:in `from\_file’\r\n\r\nremote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”) do\r\n provider Chef::Provider::RemoteFile\r\n action “create”\r\n retries 0\r\n retry\_delay 2\r\n guard\_interpreter :default\r\n path “d:\\installs\\7.1\_HF05\_Overlay\_SAML\_fix.zip”\r\n backup 5\r\n atomic\_update true\r\n source [“file:////targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\<file:///\targetserver\server.installs\dll.drops\7.1\_HF05\_Overlay\_SAML\_fix.zip\>”]\r\n use\_etag true\r\n use\_last\_modified true\r\n cookbook\_name “AW\_DLLDrop”\r\n recipe\_name “default”\r\nend\r\n\r\n”]”

Thanks  
Chris

---

<div class="post-metadata">

**Author:** ![Adam\_Edwards1](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/adam_edwards1/32/27_2.png) [@Adam\_Edwards1](https://discourse.chef.io/u/Adam_Edwards1)\
**Post date:** [August 6, 2014, 6:04pm UTC](https://discourse.chef.io/t/remote-file-copy-from-windows-share/5695/6 "2014-08-06T18:04:27Z")

</div>

So here’s an example of what I did to make remote\_file work – I also added  
the ‘atomic\_update’ attribute because at one point this was required (not  
sure that’s needed in latest versions of chef-client):

remote\_file “c:/users/myuser/myfile.txt” do

atomic\_update false

source ‘file:////server/share/file.txt’

end

Basically you need two additional ‘/’ chars in your url. We should probably  
add a path\_syntax attribute to automate this…

-Adam

_From:_ [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]

_Sent:_ Wednesday, August 6, 2014 10:48 AM  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] RE: RE: RE: RE: Remote file Copy from Windows Share

Hi Adam,

Thanks for that, it seems to have helped. Authenticating via AD seems to  
be working ok.

I’m now getting an error saying the dir isn’t there (which is clearly is –  
I have checked the paths).

I think it’s looking for the path on the local system rather that the  
remote one. I suspect this is me messing up some syntax J

Here is the section out of the recipe:

“

# Dll drop filename (in full, no path)

# ie fname = “7.1\_HF05\_Overlay\_SAML\_fix.zip”

fname = “7.1\_HF05\_Overlay\_SAML\_fix.zip”

path = “file://#{managementServer}/server.installs/dll.drops/#{fname}  
\<file:///\#{managementServer}/server.installs/dll.drops/#{fname}\>”

remote\_file “d:\installs\#{fname}” do

source path

end

”

Here is the error:

“

remote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”) do

Win-Node2 provider Chef::Provider::RemoteFile

Win-Node2 action “create”

Win-Node2 retries 0

Win-Node2 retry\_delay 2

Win-Node2 guard\_interpreter :default

Win-Node2 path “d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”

Win-Node2 backup 5

Win-Node2 atomic\_update true

Win-Node2 source [“  
file://ATLQ-CHEF01.airwatch.qa/server.installs/dll.drops/7.1\_HF05\_Overlay\_SAML\_fix.zip  
\<file:///\[ATLQ-CHEF01.airwatch.qa](http://ATLQ-CHEF01.airwatch.qa)\server.installs\dll.drops\7.1\_HF05\_Overlay\_SAML\_fix.zip\>  
”]

Win-Node2 use\_etag true

Win-Node2 use\_last\_modified true

Win-Node2 cookbook\_name “AW\_DLLDrop”

Win-Node2 recipe\_name “default”

Win-Node2 end

Win-Node2 [2014-08-06T13:41:36-04:00] FATAL: Stacktrace dumped to  
c:/chef/cache/chef-stacktrace.out

DEBUG: :relay\_output\_from\_backend =\> [“Win-Node2”,  
"[2014-08-06T13:41:36-04:00] FATAL: Errno::ENOENT:  
remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]  
(AW\_DLLDrop::default line 28) had an error: Errno::ENOENT: No such file or  
directory - /server.installs/dll.drops/7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n"]

”

_From:_ Adam Edwards [[mailto:adamed@getchef.com](mailto:adamed@getchef.com) [adamed@getchef.com](mailto:adamed@getchef.com)]  
_Sent:_ 06 August 2014 17:43  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] RE: RE: RE: Remote file Copy from Windows Share

Hmm – so you are running Chef remotely via WinRM? If that’s the case, you  
should add credssp to your winrm listener. You can do that with powershell  
by setting the value below to true:

ls WSMan:\localhost\Service\Auth\CredSSP

# if that shows false, you can set it to true:

si WSMan:\localhost\Service\Auth\CredSSP $true

That should allow your credentials to do one extra hop off the machine.

_From:_ [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]

_Sent:_ Wednesday, August 6, 2014 9:38 AM  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] RE: RE: Remote file Copy from Windows Share

Hi Adam,

It’s windows to windows. Only the Chef server is Linux but that has  
little to do with anything (I think/hope).

Without Chef involvement the shares are perfectly accessible, even using  
the user account that chef client is run as.

Firewall is off completely and I’m using AD creds and local creds. When  
Chef run is performed against the two windows nodes, one will complete  
successfully (it is the node hosting the share) and the other node will  
fail with ‘authentication failed – password incorrect’ (which I think is a  
catch-all error).

The security log of the second node shows authentication error with a null  
sid.

The first node (hosting the share) shows no errors.

The security of the D:\installs folder also show effective permissions as  
full control for both ad login and local account.

I’m wondering if it’s something to do with the user that the chef client is  
run as on each node? Maybe machine localsystem? Does chef-client run with  
the creds that winrm provides to it or do those creds simply auth against  
WinRM and then localsystem takes over? Chef-Client is being run on-demand,  
it is not installed as a service due to the way we will be using Chef.

Thanks

Chris

_From:_ Adam Edwards [[mailto:adamed@getchef.com](mailto:adamed@getchef.com) [adamed@getchef.com](mailto:adamed@getchef.com)]  
_Sent:_ 06 August 2014 17:09  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] RE: Remote file Copy from Windows Share

Christopher, to clarify a few things here:

1. 

```
  Are you copying from a windows machine to a windows machine? Or is

```

one of the systems a Linux system

1. 

```
  You’re saying that even without any Chef / Ruby involved you can’t

```

access the share?

If those things are true, I’d try the following:

1. 

```
  Turn off the firewall

```

2. 

```
  Try using credentials for a local account as well as a domain

```

credentials

1. 

```
  Check the security log to see if you get an audit event for a

```

failed logon

-Adam

_From:_ [ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com) [[mailto:ChristopherHall@air-watch.com](mailto:ChristopherHall@air-watch.com)]

_Sent:_ Wednesday, August 6, 2014 7:28 AM  
_To:_ [chef@lists.opscode.com](mailto:chef@lists.opscode.com)  
_Subject:_ [chef] Remote file Copy from Windows Share

Hi Chefs

I’m having trouble again J

I’m trying to copy a file from a share on a windows server from a target  
node via chef. The purpose for it to copy dll drop files from a share and  
dumped into d:\installs so it can later be unzipped. At the moment I am  
having issues trying to connect to the share.

I’ve tried running the chef run as a local admin on the target node (which  
used to work), using AD creds and also a different local account to no  
avail.

The linux server was recently added to our domain, but this was failing  
before that happened.

I’ve tried a batch file mapping a drive then copy, a powershell script  
doing the same, native ruby and now this remote file resource. Same error  
everytime, it looks like a permissions error on Windows, but the file share  
is currently set full permission to everyone on both Share permissions and  
filesystem permissions.

I’m seeing NULL\_SID event log entries where the auth fails, but this is on  
the target node, not the one that hosts the share.

Can any offer anything to look at?

Chef server is Ubuntu 14.04 using PBIS to auth via AD (might I need Samba  
installing now AD is in use for Auth?)

Windows nodes are running Server 2008R2 patched up-to-date. All are VM’s.  
All one the same AD and DNS domain.

“myserver

DEBUG: :relay\_output\_from\_backend =\> [“Win-Node2  
[http://ATLQ-CHEF04.airwatch.qa](http://ATLQ-CHEF04.airwatch.qa)”,  
"================================================================================\r\nError  
executing action `create` on resource  
’remote\_file[d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip]’\r\n================================================================================\r\n\r\nErrno::EACCES\r\n-------------\r\nPermission  
denied -  
//targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip\r\n\r\nResource  
Declaration:\r\n---------------------\r\n# In  
c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb\r\n\r\n 27:  
remote\_file “d:\\installs\\#{fname}” do \r\n 28: source “  
file:////#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)  
\<file:///\#{managementServer}[//server.installs//dll.drops//#{fname}](https://server.installs//dll.drops//#%7Bfname%7D)\>”\r\n  
29: end\r\n 30: \r\n\r\nCompiled Resource:\r\n------------------\r\n#  
Declared in c:/chef/cache/cookbooks/AW\_DLLDrop/recipes/default.rb:27:in  
`from\_file’\r\n\r\nremote\_file(“d:\installs\7.1\_HF05\_Overlay\_SAML\_fix.zip”)  
do\r\n provider Chef::Provider::RemoteFile\r\n action “create”\r\n  
retries 0\r\n retry\_delay 2\r\n guard\_interpreter :default\r\n path  
"d:\\installs\\7.1\_HF05\_Overlay\_SAML\_fix.zip"\r\n backup 5\r\n  
atomic\_update true\r\n source [“  
file:////targetserver//server.installs//dll.drops//7.1\_HF05\_Overlay\_SAML\_fix.zip  
\<file:///\targetserver\server.installs\dll.drops\7.1\_HF05\_Overlay\_SAML\_fix.zip\>”]\r\n  
use\_etag true\r\n use\_last\_modified true\r\n cookbook\_name  
"AW\_DLLDrop"\r\n recipe\_name “default”\r\nend\r\n\r\n"]”

_Thanks_

_Chris_
