join as DC fails: LDAP error 10 LDAP_REFERRAL, or how to properly create application directory partition

Andrew Bartlett abartlet at
Wed Jun 27 18:11:13 UTC 2018

On Wed, 2018-06-27 at 13:46 +0400, Alexey Sheplyakov via samba-
technical wrote:
> Hi,
> On Wed, Jun 27, 2018 at 08:16:42PM +1200, Andrew Bartlett wrote:
> > I'm confused, where in the join is it creating an application
> > partition?  I can imagine it replicating such, but where does it create
> > one?
> I stand corrected. However join does modify the application partition, see
> Windows DC having no domain naming master role refuses to modify application
> partitions, hence the problem.

OK, but that instead just makes me wonder what we need to do.  I don't
think windows has to join the naming master does it?

How does windows handle application partitions and/or how does it set
up the replication status for those?

Some more investigation is required here.


Andrew Bartlett
Andrew Bartlett             
Authentication Developer, Samba Team
Samba Developer, Catalyst IT

More information about the samba-technical mailing list