join as DC fails: LDAP error 10 LDAP_REFERRAL, or how to properly create application directory partition

Alexey Sheplyakov asheplyakov at
Wed Jun 27 09:46:07 UTC 2018


On Wed, Jun 27, 2018 at 08:16:42PM +1200, Andrew Bartlett wrote:
> I'm confused, where in the join is it creating an application
> partition?  I can imagine it replicating such, but where does it create
> one?

I stand corrected. However join does modify the application partition, see;a=blob;f=python/samba/;h=30ecce77c55852ed5ff542ea05c3e5f0c535835c;hb=d9914b9b6a66aebab367bcdc535bf8eaaa46abeb#l677

Windows DC having no domain naming master role refuses to modify application
partitions, hence the problem.

Best regards,

