Hello Cristof,

Have you tried issuing the LDAP commands from a Windows client as well as a Samba client? If so, what tool/command line did you use, and what were the results? 

I would like to collect an LSASS TTT trace with a concurrent network capture of the scenario where no results are returned. 

The LSASS traces can be quite large, but are highly compressible, so please add them to a .zip archive before uploading (file transfer workspace credentials are below). Please log into the workspace and find PartnerTTDRecorder_x86_x64.zip available for download. The x64 tool can be staged onto the Windows server in any location (instructions below assume C:\TTD). 

To collect the needed traces:
	1. From a PowerShell prompt, execute: 
		C:\TTD\tttracer.exe -Attach ([int](Get-Process -NAME lsass | Format-Wide -Property ID).formatEntryInfo.formatPropertyField.propertyValue)
	2. Wait for a little window to pop up in top left corner of your screen, titled "lsass01.run"
	3. start a network trace using netsh or WireShark, etc. 
	4. Repro the attempted operation
	5. Stop the network trace and save it
	6. CAREFULLY: uncheck the checkbox next to "Tracing" in the small "lsass01.run" window. Do not close or exit the small window or you will need to reboot. 
	7. The TTTracer.exe process will generate a trace file, then print out the name and location of the file. 
Compress the *.run file into a .zip archive before uploading with the matching network trace. It is a good idea to reboot the machine at the next opportunity to restart the lsass process.

On Fri, Sep 30, 2022 at 12:07:33PM +1300, Andrew Bartlett wrote:
>    Christof,
>    Is the behaviour different on the Global Catalog port?  Are both servers
>    GC instances?

protocol9 was created first, so that should be a GC instance. And a query to port 3268 returns the same result:

# ldapsearch -H ldap://adprotocol9.com:3268 -x -W -D "administrator at adprotocol9.com" -b "dc=adprotocol9,dc=com" "(member=<SID=S-1-5-21-686935948-1127628631-3386349506-1104>)"
Enter LDAP Password:
# extended LDIF
# LDAPv3
# base <dc=adprotocol9,dc=com> with scope subtree # filter: (member=<SID=S-1-5-21-686935948-1127628631-3386349506-1104>)
# requesting: ALL

# search result
search: 2
result: 0 Success

# numResponses: 1



