[Samba] ODP: ODP: ODP: Demoting AD DC failed, now it won't start up after ldb and tdb files removed

Rowland Penny rpenny at samba.org
Sat Apr 2 18:58:36 UTC 2022

On Sat, 2022-04-02 at 18:32 +0000, Krzysztof Kucybała wrote:
> So the dbcheck command comes up clean on the original, VM-based DC,
> but spits out a whole lot of errors (307 to be exact) on the physical
> one (the one that's been acting up, whose db should now be a pristine
> replica I would've thought). These are errors that look like this:
> RROR: wrong instanceType 4 on CN=9738c400-7795-4d6e-b19d-
> c16cd6486166,CN=Operations,CN=DomainUpdates,CN=System,DC=***,DC=com,
> should be 0
> Not changing instanceType from 4 to 0 on CN=9738c400-7795-4d6e-b19d-
> c16cd6486166,CN=Operations,CN=DomainUpdates,CN=System,DC=***,DC=com
> but they concern many different db objects - user accounts, groups,
> computers... 

You can ignore them (and filter them, see the help for the command),
'instanceType' can be different on each DC.

> I did not manage to get the other command to work on either DC, error
> is the same:
> root at meraki:~# samba-tool ldapcmp primarydc meraki domain
> ERROR(ldb): uncaught exception - LDAP error 1 LDAP_OPERATIONS_ERROR -
>  <00002020: Operation unavailable without authentication> <>

As it says, you need to authenticate.


More information about the samba mailing list