[Samba] drs showrepl - Failed to bind to UUID - Undetermined error

Andrew Bartlett abartlet at samba.org
Sat Sep 10 19:43:42 UTC 2016

On Sat, 2016-09-10 at 16:28 +0100, Jonathan Hunter via samba wrote:
> Thanks Andrew.
> No - it was my fault for including an easily-solved side query in the
> same
> email as the main query.. :) I haven't solved the original issue,
> which is
> that 'samba-tool drs showrepl' runs on two of my DCs but not on the
> third.
> I don't know if anything else also doesn't work, e.g. some aspect of
> replication I haven't observed yet - but the only problem I can
> actually
> see is that 'samba-tool drs showrepl' doesn't run on this one DC.
> You ask a good question in terms of removing the DC that died. I
> think I
> probably did not do this step correctly. I had two DCs die within a
> short
> time of each other (disk issues) and I built new machines and simply
> joined
> them to the domain 'over the top', using the same name and IP address
> as
> previously. I now realise that this might not have been the best
> idea, as
> they would now have new UUIDs and I have done nothing much to remove
> the
> old UUIDs, apart from removing them from DNS/LDAP where I found them.
> Perhaps I should have explicitly removed the DCs, before re-adding
> them? I
> may well not have removed them fully myself.
> Is there an easy place in AD where these UUIDs are stored - I'm happy
> to go
> through and remove stale entries myself using ADSIEdit or similar? Or
> would
> you recommend I temporarily remove each DC in turn using the demote
> tool,
> then re-add? (Would the demote tool remove *all* UUIDs from the DCs,
> or
> only the first one?)
> Is there some form of AD-checker tool, perhaps (either MS or Samba)
> that
> would check all the various LDAP entries, DNS entries (_msdcs,
> _sites,
> _tcp, _kerberos etc.) and point out what I have wrong? :-)
> At the moment I guess there might be multiple UUIDs somewhere in the
> directory for this one DC, which might be why 'samba-tool drs
> showrepl'
> chokes. There may well be multiple UUIDs for my other server that
> died,
> too, but perhaps the first one that is returned from LDAP for that
> other
> server is the current one, which is why 'samba-tool drs showrepl'
> works on
> that?

If you re-joined over the top, then it would have cleaned up most of
what it needed to.  It probably left some junk in DNS, but that is
mostly harmless.

Where the UUID may be is in the repsFrom and repsTo, but this should be
cleaned up by the new KCC.

There isn't currently a 'is this all correct' tool beyond dbcheck.

For the failure to connect, it is trying to connect to the local server
to perform the query, have you confirmed DNS is set resolving for the
name given and that the server is running, and listening?  Wireshark
may help, as might turning up the log level on the command eg -d10 and
the server.

Andrew Bartlett
Andrew Bartlett                       http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba

More information about the samba mailing list