Update: there’s definitively something wrong with ucs/s4 synchronisation. The system error diagnosis tab in UMC shows some python error where there should be concise diagnostic information:
(There is an additional KDC warning concerning the old master I migrated from some months ago, but that seems to be less of a hassle)
The enclosed link (“Univention Support Database - How to deal with s4-connector rejects”) suggests to initiate the analysis of s4-connector rejects with a corresponding list command, but that yields dubious results on my pdc:
root@mypdc:~# univention-s4connector-list-rejected
Failed to get SID from S4: 'objectSid'
This does not really push me in the direction of a workable remedy. What are the best steps to get my system “unstuck”?
Update #2: Studying remotely related posts here lead to the conclusion that my system is beyond repair. To narrow down the culprit, I reverted from my current version system (ucs 4.2-3) to a sufficiently dated backup (4.2-0 errata15 “Lesum”).
The system does not show any errors on the system error diagnosis tab now!
Bad news is: the s4-connector is not running, and univention-s4connector-list-rejected has the same issues with objectSid as before the roll-back…
Will start a new thread now as this is not related to DNS in any way any more.