[Samba] DNS problems on windows AD

Marc Muehlfeld mmuehlfeld at samba.org
Mon Jan 18 19:06:04 UTC 2016


Hello Olivier,

sorry for the delay.


Am 08.01.2016 um 16:52 schrieb Olivier Weinstoerffer:
> samba is 4.1.22.
> I let the dcpromote choose the DC.
> DNS is internal
> Yes the windows DC has also global catalog


I can reproduce the "refused" error here when trying to add an DNS
record to the Windows 2008R2 DC.

I saw, that DNS changes made on the Samba DCs are not replicated to the
Windows DC as well. I see no "outbound neighbors" entry for
DomainDnsZones and ForestDnsZones from my existing Samba 4.3.4 DCs to
the Windows DC:

# samba-tool drs showrepl
...
==== OUTBOUND NEIGHBORS ====

DC=DomainDnsZones,DC=samdom,DC=example,DC=com
	Default-First-Site-Name\DC1 via RPC
		DSA object GUID: 4a6bd92a-6612-4b15-aa8c-9ec371e8994f
		Last attempt @ NTTIME(0) was successful
		0 consecutive failure(s).
		Last success @ NTTIME(0)
...
DC=ForestDnsZones,DC=samdom,DC=example,DC=com
	Default-First-Site-Name\DC1 via RPC
		DSA object GUID: 4a6bd92a-6612-4b15-aa8c-9ec371e8994f
		Last attempt @ NTTIME(0) was successful
		0 consecutive failure(s).
		Last success @ NTTIME(0)



For both an entry should be listed to the Windows DC, like in my example
on the Wiki page (that's why I guess, it worked in the past or did
something wrong today :-)). Can you confirm that you also have no
Domain/ForestDnsZones entry to the Windows host in the "outbound" area?


Regards,
Marc



More information about the samba mailing list