[Samba] Server 2008R2 won't join 4.5.0 Domain

Kelvin Yip kelvin at icshk.com
Wed Nov 9 09:59:11 UTC 2016


I am using 4.5.1, the first time I promote a Windows 2008 R2 as a domain controller, everything is fine.
After that, I demote 1 Windows 2008 R2 and 1 Samba DC(4.5.1). Then I promote a Windows 2008 R2 DC again, I get the exact problem as yours. I cancel the process.
Then I ran to DC with all FSMO roles, and type the following command several times:
samba-tool dbcheck --cross-ncs --fix --yes
samba-tool dbcheck --cross-ncs --fix --yes 'fix_replmetadata_unsorted_attid'

There is still errors, but less than before.
Now, I promote Windows 2008 R2 DC again and everything works fine.
Hope it helps.

Kelvin Yip

-----Original Message-----
From: samba [mailto:samba-bounces at lists.samba.org] On Behalf Of Thomas Maerz via samba
Sent: Wednesday, November 9, 2016 12:55 AM
To: samba <samba at lists.samba.org>
Subject: [Samba] Server 2008R2 won't join 4.5.0 Domain


I can’t get a fully patched Server 2008 R2 DC to finish DCPROMO joining as a domain controller to my Samba4 AD domain.

dcpromo.exe begins replication but gets stuck on “Replicating data CN=Configuration,DC=samdom,DC=contoso,DC=com: Received 1999 off of approximately 1999 objects and 74 out of approximately 74 distinguished name (DN) values…

Examining the dcpromo.log file just shows thousands of these messages repeating indefinitely. I have left it for hours and nothing has changed.

After searching the internet I’ve run into a few things I think might be relevant, but I can’t figure out a way to correct it.

This person had similar symptoms: https://lists.samba.org/archive/cifs-protocol/2011-June/001954.html <https://lists.samba.org/archive/cifs-protocol/2011-June/001954.html> The thread just mysteriously ended though with no resolution, and their issue was occurring during boot.

I am also seeing lots of errors with samba-tool dbcheck:

ERROR: incorrect GUID component for member in object CN=arc_info,OU=Groups,DC=samdom,DC=contoso,DC=com - <GUID=d6a2ae825b3487459f31010ce5c2ecb0>;<RMD_ADDTIME=130396389260000000>;<RMD_CHANGETIME=130458616690000000>;<RMD_FLAGS=1>;<RMD_INVOCID=71d80bb55484734b90ba2875af7fcfb7>;<RMD_LOCAL_USN=22603>;<RMD_ORIGINATING_USN=22603>;<RMD_VERSION=1>;<SID=010500000000000515000000304c563cc305b2f7e2cb6a3c56160000>;CN=Kay Jones,CN=Users,DC=ad,DC=brewerscience,DC=com
unable to find object for DN CN=User K,CN=Users,DC=samdom,DC=contoso,DC=com - (No such Base DN: CN=User K,CN=Users,DC=ad,DC=brewerscience,DC=com)
Not removing dangling forward link
ERROR: incorrect DN string component for member in object CN=Test ITAR,OU=Test Groups,DC=ad,DC=brewerscience,DC=com - <GUID=e6261396-5bbc-4136-9728-37bde2789391>;<RMD_ADDTIME=130354186220000000>;<RMD_CHANGETIME=130374712860000000>;<RMD_FLAGS=1>;<RMD_INVOCID=5a39a061-2ec9-4e95-adf8-539291ecd2ea>;<RMD_LOCAL_USN=4330>;<RMD_ORIGINATING_USN=4069>;<RMD_VERSION=1>;<SID=S-1-5-21-1012288560-4155639235-1013631970-1112>;CN=Test User,CN=Users,DC=ad,DC=brewerscience,DC=com
Not fixing string component mismatch
Please use --fix to fix these errors

—fix does not fix the errors at all. I see this bug is present:

https://bugzilla.samba.org/show_bug.cgi?id=12297 <https://bugzilla.samba.org/show_bug.cgi?id=12297>

Is it possible that this issue is related to my inability to join the domain controller? Is there a way around this?

Thomas Maerz
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba

More information about the samba mailing list