[Samba] Join Samba to Windows with error DsReplicaSync

Miguel Angel Coa M. miguelcoam at gmail.com
Thu Feb 29 20:41:21 UTC 2024


Hello samba team,

Ive Samba 4.19.1 join to Windows 2022 AD the replication works only from
Windowd DC to Samba DC but not in the other direction.


DC1: windows server 2022 , schema version 69

DC2: Samba version 4.19.1, schema version 69

Domain and forest functional level in 2008_R2 (two environments)


When i check the replication status from Samba the error is:


[.................]

[root at sambadc02 ~]# samba-tool drs showrepl

ERROR(runtime): DsReplicaGetInfo of type 0 failed - (3221356597, 'The
operation cannot be performed.')

[root at sambadc02 ~]#

[.................]


And the status command:


[.................]

Feb 29 17:36:12 sambadc02.domain.com samba[1065489]: [2024/02/29
17:36:12.190502,  0] ../../source4/rpc_server/common/f>


Feb 29 17:36:12 sambadc02.domain.com samba[1065489]:   IRPC callback failed
for DsReplicaSync - NT_STATUS_IO_TIMEOUT

[.................]


And the scan port the MSRCP is filtered:


[.................]

PORT     STATE    SERVICE      VERSION

53/tcp   open     domain       ISC BIND 9.11.36 (RedHat Enterprise Linux 8)

88/tcp   open     kerberos-sec (server time: 2024-02-29 20:16:52Z)

123/tcp  closed   ntp

135/tcp  filtered msrpc  <---- FILTERED

137/tcp  closed   netbios-ns

138/tcp  closed   netbios-dgm

139/tcp  open     netbios-ssn  Samba smbd 4.6.2

389/tcp  open     ldap         (Anonymous bind OK)

445/tcp  open     netbios-ssn  Samba smbd 4.6.2

464/tcp  open     kpasswd5?

636/tcp  open     ssl/ldap     (Anonymous bind OK)

3268/tcp open     ldap         (Anonymous bind OK)

3269/tcp open     ssl/ldap     (Anonymous bind OK)

[.................]


>From samba i check the integrity and is fine (samba-tool dbcheck
--cross-ncs --fix --yes)


I dont have firewall, iptables, selinux .



Thanks.


More information about the samba mailing list