Join a domain as a DC - replicating problems

Marc Muehlfeld Marc.Muehlfeld at
Tue Nov 6 08:43:42 MST 2012


I bring my test environment back in use for trying this (I was to afraid to do 
this in production, after the join as DC doesn't work like described in the 
wiki). :-)

I made a 1:1 copy (incl. names/IPs) of my live system and a brand new rc4+Bind 
setup in my testenvironment.

Am 02.11.2012 09:02, schrieb Marc Muehlfeld:
>> 1. An A record for the failing (to replicate) DC in the DOMAIN.NAME zone

I added this on the old DC and when I looked in the DNS console to the new 
server, the entry was there. It seems, something replicated it.

>> 2. A CNAME record for the GUID (obtained with: ldbsearch -H
>> /usr/local/samba/private/sam.ldb '(invocationid=*)' --cross-ncs objectguid) of
>> failing (to replicate) DC in the _msdcs.DOMAIN.NAME zone which pointed at the
>> previously created record.

I extracted the GUID and added the CNAME record to the old DC. This one was 
also replicated to the new host automatically.

But 'samba-tool drs showrepl' still fails:
ERROR(<class 'samba.drs_utils.drsException'>): DRS connection to failed - drsException: DRS connection to failed: (-1073741772, 
   File "/usr/local/samba/lib64/python2.6/site-packages/samba/netcmd/", 
line 39, in drsuapi_connect
     (ctx.drsuapi, ctx.drsuapi_handle, ctx.bind_supported_extensions) = 
drs_utils.drsuapi_connect(ctx.server, ctx.lp, ctx.creds)
   File "/usr/local/samba/lib64/python2.6/site-packages/samba/", 
line 54, in drsuapi_connect
     raise drsException("DRS connection to %s failed: %s" % (server, e))

I also created a bug report about the problem that the DNS entries are not 


Marc Muehlfeld (IT-Leiter)
Zentrum fuer Humangenetik und Laboratoriumsmedizin
Dr. Klein, Dr. Rost und Kollegen
Lochhamer Str. 29 - D-82152 Martinsried
Telefon: +49(0)89/895578-0 - Fax: +49(0)89/895578-780

More information about the samba-technical mailing list