Ad-takeover fail ucs add old domain server

Dear Everybody!
I migrated many times from Zentyal to UCS with the “ad-takeover” feature, which has always been successful.
Now, the migration process stops without error message when you put the UCS server on your domain.
Groups and users are read without error. Instead of the following screen, I get an error message stating that the log explains the error. However, the logfile does not contain any relevant information.
What could be the problem?
Thanks, Gyula
" root@gyesgy-ucs:/var/log/univention# cat ad-takeover.log
2019-10-10 17:53:31,393 Authentication failed.
2019-10-10 17:53:43,284 Authentication failed.
2019-10-10 17:53:56,486 Authentication failed.
2019-10-10 17:54:06,276 Found account Administrator with well known RID 500 (Administrator)
2019-10-10 17:54:06,276 Found account krbtgt with well known RID 502 (KRBTGT)
2019-10-10 17:54:06,277 Found account Guest with well known RID 501 (Guest)
2019-10-10 17:54:06,281 Found group Allowed RODC Password Replication Group with well known RID 571 (Allowed RODC Password Replication
Group)
2019-10-10 17:54:06,281 Found group Enterprise Read-Only Domain Controllers with well known RID 498 (Enterprise Read-only Domain Contr
ollers)
2019-10-10 17:54:06,281 Found group Denied RODC Password Replication Group with well known RID 572 (Denied RODC Password Replication G
roup)
2019-10-10 17:54:06,281 Found group Read-Only Domain Controllers with well known RID 521 (Read-Only Domain Controllers)
2019-10-10 17:54:06,281 Found group Group Policy Creator Owners with well known RID 520 (Group Policy Creator Owners)
2019-10-10 17:54:06,281 Found group RAS and IAS Servers with well known RID 553 (RAS and IAS Servers)
2019-10-10 17:54:06,281 Found group Domain Controllers with well known RID 516 (Domain Controllers)
2019-10-10 17:54:06,281 Found group Enterprise Admins with well known RID 519 (Enterprise Admins)
2019-10-10 17:54:06,281 Found group Domain Computers with well known RID 515 (Domain Computers)
2019-10-10 17:54:06,281 Found group Cert Publishers with well known RID 517 (Cert Publishers)
2019-10-10 17:54:06,281 Found group Domain Admins with well known RID 512 (Domain Admins)
2019-10-10 17:54:06,281 Found group Domain Guests with well known RID 514 (Domain Guests)
2019-10-10 17:54:06,281 Found group Schema Admins with well known RID 518 (Schema Admins)
2019-10-10 17:54:06,281 Found group Domain Users with well known RID 513 (Domain Users)
2019-10-10 17:54:06,299 determine_license for current UCS Users: 1 of unlimited
2019-10-10 17:54:06,299 0 Systemaccounts are ignored.
2019-10-10 17:54:06,299 Found 23 users objects on the remote server.
2019-10-10 17:54:16,118 INFO: Time difference is less than 180 seconds, skipping reset of local time
2019-10-10 17:54:16,128 Starting phase I of the takeover process.
2019-10-10 17:54:16,128 Calling: univention-config-registry set hosts/static/192.168.3.2=zentylal-gyesgy.gyesgy.lan ZENTYLAL-GYESGY
2019-10-10 17:54:16,417 Create hosts/static/192.168.3.2
2019-10-10 17:54:16,418 Multifile: /etc/hosts
2019-10-10 17:54:16,418 Calling: /etc/init.d/univention-s4-connector stop
2019-10-10 17:54:16,461 Stopping univention-s4-connector (via systemctl): univention-s4-connector.service.
2019-10-10 17:54:16,461 Calling: /etc/init.d/samba-ad-dc stop
2019-10-10 17:54:16,547 Stopping samba-ad-dc (via systemctl): samba-ad-dc.service.
2019-10-10 17:54:16,548 Calling: univention-config-registry set nameserver1/local=192.168.3.7 nameserver1=192.168.3.2 directory/manage
r/web/modules/users/user/properties/username/syntax=string directory/manager/web/modules/groups/group/properties/name/syntax=string dn
s/backend=ldap
2019-10-10 17:54:16,936 Create nameserver1/local
2019-10-10 17:54:16,936 Setting nameserver1
2019-10-10 17:54:16,936 Create directory/manager/web/modules/users/user/properties/username/syntax
2019-10-10 17:54:16,936 Create directory/manager/web/modules/groups/group/properties/name/syntax
2019-10-10 17:54:16,936 Setting dns/backend
2019-10-10 17:54:16,936 File: /etc/systemd/system/bind9.service.d/10-configure-backend.conf
2019-10-10 17:54:16,936 File: /etc/init.d/bind9
2019-10-10 17:54:16,936 File: /etc/resolv.conf
2019-10-10 17:54:16,940 Calling: /etc/init.d/nscd stop
2019-10-10 17:54:16,971 Stopping nscd (via systemctl): nscd.service.
2019-10-10 17:54:16,971 Calling: /etc/init.d/bind9 restart
2019-10-10 17:54:18,011 Restarting bind9 (via systemctl): bind9.service.
2019-10-10 17:54:18,011 Starting Samba domain join.
2019-10-10 17:54:18,472 INFO 2019-10-10 17:54:18,471 pid:9353 /usr/lib/python2.7/dist-packages/samba/join.py #1519: workgroup is GYESG
Y
2019-10-10 17:54:18,472 INFO 2019-10-10 17:54:18,472 pid:9353 /usr/lib/python2.7/dist-packages/samba/join.py #1522: realm is gyesgy.la
n
2019-10-10 17:54:20,084 INFO 2019-10-10 17:54:20,084 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2359: Look
ing up IPv4 addresses
2019-10-10 17:54:20,084 INFO 2019-10-10 17:54:20,084 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2376: Look
ing up IPv6 addresses
2019-10-10 17:54:20,084 WARNING 2019-10-10 17:54:20,084 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2383: N
o IPv6 address will be assigned
2019-10-10 17:54:20,501 INFO 2019-10-10 17:54:20,501 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2549: Sett
ing up share.ldb
2019-10-10 17:54:20,828 INFO 2019-10-10 17:54:20,828 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2553: Sett
ing up secrets.ldb
2019-10-10 17:54:21,062 INFO 2019-10-10 17:54:21,062 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2559: Sett
ing up the registry
2019-10-10 17:54:21,825 INFO 2019-10-10 17:54:21,825 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2562: Sett
ing up the privileges database
2019-10-10 17:54:22,266 INFO 2019-10-10 17:54:22,266 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2565: Sett
ing up idmap db
2019-10-10 17:54:22,665 INFO 2019-10-10 17:54:22,665 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2572: Sett
ing up SAM db
2019-10-10 17:54:22,826 INFO 2019-10-10 17:54:22,825 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #887: Setti
ng up sam.ldb partitions and settings
2019-10-10 17:54:22,845 INFO 2019-10-10 17:54:22,845 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #899: Setti
ng up sam.ldb rootDSE
2019-10-10 17:54:23,009 INFO 2019-10-10 17:54:23,009 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #1302: Pre-
loading the Samba 4 and AD schema
2019-10-10 17:54:23,010 Unable to determine the DomainSID, can not enforce uniqueness constraint on local domainSIDs
2019-10-10 17:54:23,594 INFO 2019-10-10 17:54:23,593 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2622: A Ke
rberos configuration suitable for Samba AD has been generated at /var/lib/samba/private/krb5.conf
2019-10-10 17:54:23,594 INFO 2019-10-10 17:54:23,593 pid:9353 /usr/lib/python2.7/dist-packages/samba/provision/init.py #2623: Merg
e the contents of this file with your system krb5.conf or replace it with this one. Do not create a symlink!
2019-10-10 17:54:23,818 Schema-DN[CN=Schema,CN=Configuration,DC=gyesgy,DC=lan] objects[402/1552] linked_values[0/0]
2019-10-10 17:54:23,901 Schema-DN[CN=Schema,CN=Configuration,DC=gyesgy,DC=lan] objects[804/1552] linked_values[0/0]
2019-10-10 17:54:24,002 Schema-DN[CN=Schema,CN=Configuration,DC=gyesgy,DC=lan] objects[1206/1552] linked_values[0/0]
2019-10-10 17:54:24,080 Schema-DN[CN=Schema,CN=Configuration,DC=gyesgy,DC=lan] objects[1552/1552] linked_values[0/0]
2019-10-10 17:54:24,080 Analyze and apply schema objects
2019-10-10 17:54:25,264 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[402/1626] linked_values[0/1]
2019-10-10 17:54:25,527 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[804/1626] linked_values[0/1]
2019-10-10 17:54:25,684 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[1206/1626] linked_values[0/1]
2019-10-10 17:54:25,840 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[1608/1626] linked_values[0/1]
2019-10-10 17:54:25,928 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[1626/1626] linked_values[42/42]
2019-10-10 17:54:25,936 Failed to commit objects: DOS code 0x000021bf
2019-10-10 17:54:26,046 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[2028/1626] linked_values[42/1]
2019-10-10 17:54:26,214 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[2430/1626] linked_values[42/1]
2019-10-10 17:54:26,386 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[2832/1626] linked_values[42/1]
2019-10-10 17:54:26,557 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[3234/1626] linked_values[42/1]
2019-10-10 17:54:26,657 Partition[CN=Configuration,DC=gyesgy,DC=lan] objects[3252/1626] linked_values[84/42]
2019-10-10 17:54:26,725 Could not find machine account in secrets database: Failed to fetch machine account password for GYESGY from b
oth secrets.ldb (Could not find entry to match filter: ‘(&(flatname=GYESGY)(objectclass=primaryDomain))’ base: ‘cn=Primary Domains’: N
o such object: dsdb_search at …/…/source4/dsdb/common/util.c:4712) and from /var/lib/samba/private/secrets.tdb: NT_STATUS_CANT_ACCES
S_DOMAIN_INFO
2019-10-10 17:54:27,195 ERROR(runtime): uncaught exception - (8409, ‘WERR_DS_DATABASE_ERROR’)
2019-10-10 17:54:27,196 File “/usr/lib/python2.7/dist-packages/samba/netcmd/init.py”, line 185, in _run
2019-10-10 17:54:27,196 return self.run(*args, **kwargs)
2019-10-10 17:54:27,196 File “/usr/lib/python2.7/dist-packages/samba/netcmd/domain.py”, line 699, in run
2019-10-10 17:54:27,211 backend_store=backend_store)
2019-10-10 17:54:27,211 File “/usr/lib/python2.7/dist-packages/samba/join.py”, line 1535, in join_DC
2019-10-10 17:54:27,221 ctx.do_join()
2019-10-10 17:54:27,221 File “/usr/lib/python2.7/dist-packages/samba/join.py”, line 1429, in do_join
2019-10-10 17:54:27,221 ctx.join_replicate()
2019-10-10 17:54:27,221 File “/usr/lib/python2.7/dist-packages/samba/join.py”, line 973, in join_replicate
2019-10-10 17:54:27,221 replica_flags=ctx.domain_replica_flags)
2019-10-10 17:54:27,221 File “/usr/lib/python2.7/dist-packages/samba/drs_utils.py”, line 338, in replicate
2019-10-10 17:54:27,226 (level, ctr) = self.drs.DsGetNCChanges(self.drs_handle, req_level, req)
2019-10-10 17:54:27,234 Adding CN=GYESGY-UCS,OU=Domain Controllers,DC=gyesgy,DC=lan
2019-10-10 17:54:27,234 Adding CN=GYESGY-UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gyesgy,DC=lan
2019-10-10 17:54:27,234 Adding CN=NTDS Settings,CN=GYESGY-UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gyesg
y,DC=lan
2019-10-10 17:54:27,234 Adding SPNs to CN=GYESGY-UCS,OU=Domain Controllers,DC=gyesgy,DC=lan
2019-10-10 17:54:27,234 Setting account password for GYESGY-UCS$
2019-10-10 17:54:27,234 Enabling account
2019-10-10 17:54:27,234 Calling bare provision
2019-10-10 17:54:27,234 Provision OK for domain DN DC=gyesgy,DC=lan
2019-10-10 17:54:27,234 Starting replication
2019-10-10 17:54:27,234 Missing target object - retrying with DRS_GET_TGT
2019-10-10 17:54:27,234 Replicating critical objects from the base DN of the domain
2019-10-10 17:54:27,234 Join failed - cleaning up
2019-10-10 17:54:27,235 Deleted CN=GYESGY-UCS,OU=Domain Controllers,DC=gyesgy,DC=lan
2019-10-10 17:54:27,235 Deleted CN=NTDS Settings,CN=GYESGY-UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gyes
gy,DC=lan
2019-10-10 17:54:27,235 Deleted CN=GYESGY-UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gyesgy,DC=lan
2019-10-10 17:54:27,255 Calling: univention-config-registry unset hosts/static/192.168.3.2
2019-10-10 17:54:27,468 Unsetting hosts/static/192.168.3.2
2019-10-10 17:54:27,468 Multifile: /etc/hosts
2019-10-10 17:54:27,470 Calling: /etc/init.d/samba-ad-dc start
2019-10-10 17:54:27,762 Starting samba-ad-dc (via systemctl): samba-ad-dc.service.
2019-10-10 17:54:27,762 Calling: /etc/init.d/univention-s4-connector start
2019-10-10 17:54:28,127 Starting univention-s4-connector (via systemctl): univention-s4-connector.service.
2019-10-10 17:54:28,127 Calling: univention-config-registry set nameserver1=192.168.3.7
2019-10-10 17:54:28,511 Setting nameserver1
2019-10-10 17:54:28,511 File: /etc/resolv.conf
2019-10-10 17:54:28,527 Calling: univention-config-registry unset nameserver1/local
2019-10-10 17:54:28,748 Unsetting nameserver1/local
2019-10-10 17:54:28,748 File: /etc/resolv.conf
2019-10-10 17:54:28,748 Calling: univention-config-registry set dns/backend=samba4
2019-10-10 17:54:29,075 Setting dns/backend
2019-10-10 17:54:29,075 File: /etc/systemd/system/bind9.service.d/10-configure-backend.conf
2019-10-10 17:54:29,076 File: /etc/init.d/bind9
2019-10-10 17:54:29,076 Calling: /etc/init.d/bind9 restart
2019-10-10 17:54:30,137 Restarting bind9 (via systemctl): bind9.service.
2019-10-10 17:54:30,137 Calling: /etc/init.d/nscd restart
2019-10-10 17:54:30,157 Restarting nscd (via systemctl): nscd.service.
2019-10-10 17:54:30,157 The domain join failed. See /var/log/univention/ad-takeover.log for details."

Mastodon