[cifs-protocol] Errors when doing a DsAddEntry
hongweis at microsoft.com
Wed Aug 31 09:22:46 MDT 2011
Can you give the information about your configuration ? Are you joining Samba DC to a Windows DC ? If so, what is the version of Windows DC ? Are you referring to the section "22.214.171.124 Server Behavior of the IDL_DRSAddEntry Method" of MS-DRSR for the "impossible" error case ?
Is it possible for you to capture a TTT trace for Windows server when error is returned so I can analyze the behavior ? If so , I can create a FTP workspace for you to upload the trace captured ?
From: Andrew Bartlett [mailto:abartlet at samba.org]
Sent: Tuesday, August 30, 2011 11:29 PM
To: Interoperability Documentation Help
Cc: cifs-protocol at cifs.org
Subject: Errors when doing a DsAddEntry
We have been looking at DRSUAPI/DsAddEntry, and have a few questions.
We are trying to implement subdomain support in Samba4 before the plugfest.
We have been able to generate error cases that do not seem to be 'possible' in the docs. Can you please clarify exactly what errors this function should be able to return, and document how to avoid these:
in join-s1.txt we have an error that is only listed in the docs when removing a DC from the domain.
extended_err : WERR_DS_ROLE_NOT_VERIFIED
This is currently blocking us. Our only theory is that we must perform a replication cycle before we do this call.
in join-s1-2.txt we have another error, that we worked around by creating the partitions object before creating the server object.
However, as we need to match the server-side behaviour, we need to know the undocumented circumstances that cause this error.
extended_err : WERR_DS_NO_CROSSREF_FOR_NC
Finally, is there any documentation of the high-level procedure for creating a subdomain?
Andrew Bartlett http://samba.org/~abartlet/
Authentication Developer, Samba Team http://samba.org
More information about the cifs-protocol