samba- 4.2.1 as PDC in an 2008R2 domain - WERR_DNS_ERROR_DS_UNAVAILABLE

"Dr. Hansjörg Maurer" hansjoerg.maurer at
Tue May 5 13:42:14 MDT 2015


Am 05.05.2015 um 20:32 schrieb "Dr. Hansjörg Maurer":
> Hi
> i successfully joined a samba 4.2.1 server as PDC to an 2008R2 domain
> (which might have a 2003 history).
> The only message during the join I wondered about was
> descriptor_sd_propagation_recursive: DC=DomainDnsZones,DC=XXX,DC=net not
> found under DC=XXX,DC=net
> descriptor_sd_propagation_recursive: DC=ForestDnsZones,DC=XXX,DC=net not
> found under DC=XXX,DC=net
> When I try to query the samba DC for a DNS record using samba-tool
> samba-tool dns query  server01 A -U Administrator
> I got
> ERROR(runtime): uncaught exception - (9717, 'WERR_DNS_ERROR_DS_UNAVAILABLE')
>   File "/usr/lib64/python2.7/site-packages/samba/netcmd/",
> line 175, in _run
>     return*args, **kwargs)
>   File "/usr/lib64/python2.7/site-packages/samba/netcmd/", line
> 994, in run
>     None, record_type, select_flags, None, None)

sorry for replying to my own mail.
I found the solution in an old thread.

In DNS MMC of the MS DC in the properties dialog of I set the
replication settings to

"To all DNS servers in the Active Directory forest"

After a join of the samba dc, it works



Unser System ist mit einem Mailverschluesselungs-Gateway ausgestattet. Wenn Sie moechten, dass an Sie gerichtete E-Mails verschluesselt werden, senden Sie einfach eine S/MIME-signierte E-Mail oder Ihren PGP Public Key an hansjoerg.maurer at

Our system is equipped with an email encryption gateway. If you want email sent to you to be encrypted please send a S/MIME signed email or your PGP public key to hansjoerg.maurer at

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5906 bytes
Desc: not available
URL: <>

More information about the samba-technical mailing list