[Samba] samba rodc

Cristian Saavedra csg at asualcance.com
Sun Mar 3 17:56:11 MST 2013


What is the status of the samba RODC?

I'm trying to setup a PDC - RODC schema and this is what i do

On my RODC
kinit administrator


samba-tool domain join my domain.com rodc -U Administrator

The sync is complete

Committing SAM database
Sending DsReplicateUpdateRefs for all the replicated partitions
Setting RODC invocationId
Setting isSynchronized and dsServiceName
Setting up secrets database
Joined domain FORSA (SID S-1-5-21-3380525496-3468030855-4252408690) as an RODC

But after that i see this on my PDC log
2013/03/03 19:54:50,  0] ../source4/librpc/rpc/dcerpc_util.c:660(dcerpc_pipe_auth_recv)
  Failed to bind to uuid e3514235-4b06-11d1-ab04-00c04fc2dcd2 for e3514235-4b06-11d1-ab04-00c04fc2dcd2 at ncacn_ip_tcp:37a0236c-89bb-481c-95e9-257682646e2a._msdcs.forsa.com.co[1024,seal,krb5] NT_STATUS_UNSUCCESSFUL

And in my RODC i see this

DSA Options: 0x00000025
DSA object GUID: 37a0236c-89bb-481c-95e9-257682646e2a
DSA invocationId: 64f4a862-309d-4a0d-a3de-5aa8998da68a


ERROR(runtime): DsReplicaGetInfo of type 0 failed - (8453, 'WERR_DS_DRA_ACCESS_DENIED')

I don't know where else to search.

Appreciate your help.

