Tue Feb 24 08:41:20 GMT 2004

> This just is more evidence that the holy grail of a "consistent" SAM is
> impossible if yo'ure going to have replication.  It can't happen...period.

I agree.

> If you want a consistent SAM across DC's, you can't use replication, or you
> have to prevent anyone from doing operations until you can guarantee that
> replication has occurred.  As long as there is replication (and there needs
> to be in many cases) there is going to be the situation where different
> replicas have different data.  The issue is minimizing security risks and
> other problems caused by the inconsistencies.
> Andrew, in fact the setup you mentioned last night, a PDC using an LDAP
> slave, which you claim is common (I have no reason to doubt that), you
> could make the claim that the PDC inconsistent with itself.  :-)

It is, and I have one such.
I had to add timeouts in smb.conf (ldap replication sleep) and scripts
to be sure the replica happened before going on.
Otherwise user creation or domain joins would fail because the
account/password is not yet in the ldap just after it has been written
into the db.


