Join scripts / notifier translog problems (foreign dn)

Hello, my UCS (we upgraded currently to 5.0) shows a few errors. I don’t know if they are related but I suspect they are.

One of the first things I noticed was following notification after logging in on the UCS portal:

Not all installed components have been registered. Please visit the ["Domain join" module](javascript:void(0)) to register the remaining components.

If I follow to the “Domain join” module I see three scripts in pending state (all others are “successful”):

  • 30univention-appcenter
  • 33univention-portal
  • 35univention-server-overview

“Execute all pending join scripts” shows a progress bar but after that the three scripts are still in “pending” status.

Here is the latest Join Log:

univention-run-join-scripts started
Di Aug 31 09:38:48 CEST 2021

univention-join-hooks: looking for hook type "join/pre-joinscripts" on ucs.domain.tld
Found hooks:

RUNNING 30univention-appcenter.inst
2021-08-31 09:38:48.657120803+02:00 (in joinscript_init)
Object exists: cn=apps,cn=univention,dc=domain,dc=tld
Object exists: cn=ldapschema,cn=univention,dc=domain,dc=tld
Object exists: cn=ldapacl,cn=univention,dc=domain,dc=tld
Object exists: cn=udm_syntax,cn=univention,dc=domain,dc=tld
Object exists: cn=udm_module,cn=univention,dc=domain,dc=tld
No modification: cn=univention-app,cn=ldapschema,cn=univention,dc=domain,dc=tld

No modification: cn=66univention-appcenter_app,cn=ldapacl,cn=univention,dc=domain,dc=tld

No modification: cn=app_syntax,cn=udm_syntax,cn=univention,dc=domain,dc=tld

No modification: cn=appcenter/app,cn=udm_module,cn=univention,dc=domain,dc=tld

Waiting for activation of the extension object univention-app: .........................................................INFO: No change of core data of object univention-app.
INFO: No change of core data of object 66univention-appcenter_app.
INFO: No change of core data of object app_syntax.
INFO: No change of core data of object appcenter/app.
ERROR: Primary Directory Node did not mark the extension object active within 180 seconds.
ERROR
ucs_registerLDAPExtension: registraton of /usr/share/univention-appcenter/univention-app.schema failed.

EXITCODE=1
5cbd14bd-c1fa-4c54-a934-3b95a3c58336
RUNNING 33univention-portal.inst
2021-08-31 09:41:55.161474119+02:00 (in joinscript_init)
Object exists: cn=UMC,cn=univention,dc=domain,dc=tld
Object exists: cn=UMC,cn=policies,dc=domain,dc=tld
Object exists: cn=operations,cn=UMC,cn=univention,dc=domain,dc=tld
Object exists: cn=default-umc-all,cn=UMC,cn=policies,dc=domain,dc=tld
No modification: cn=Domain Admins,cn=groups,dc=domain,dc=tld
Object exists: cn=default-umc-users,cn=UMC,cn=policies,dc=domain,dc=tld
No modification: cn=Domain Users,cn=groups,dc=domain,dc=tld
Object exists: cn=ldapschema,cn=univention,dc=domain,dc=tld
Object exists: cn=ldapacl,cn=univention,dc=domain,dc=tld
Object exists: cn=udm_syntax,cn=univention,dc=domain,dc=tld
No modification: cn=univention-portal,cn=ldapschema,cn=univention,dc=domain,dc=tld

No modification: cn=62univention-portal,cn=ldapacl,cn=univention,dc=domain,dc=tld

No modification: cn=univention-portal,cn=udm_syntax,cn=univention,dc=domain,dc=tld

Waiting for activation of the extension object univention-portal: .........................................................INFO: No change of core data of object univention-portal.
INFO: No change of core data of object 62univention-portal.
INFO: No change of core data of object univention-portal.
ERROR: Primary Directory Node did not mark the extension object active within 180 seconds.
ERROR
ucs_registerLDAPExtension: registraton of /usr/lib/univention-portal/schema/univention-portal.schema failed.

EXITCODE=1
64648c2d-7c2c-4933-828c-c61f35b985af
RUNNING 35univention-server-overview.inst
2021-08-31 09:44:58.933014906+02:00 (in joinscript_init)
Object exists: cn=UMC,cn=univention,dc=domain,dc=tld
Object exists: cn=UMC,cn=policies,dc=domain,dc=tld
Object exists: cn=operations,cn=UMC,cn=univention,dc=domain,dc=tld
Object exists: cn=default-umc-all,cn=UMC,cn=policies,dc=domain,dc=tld
No modification: cn=Domain Admins,cn=groups,dc=domain,dc=tld
Object exists: cn=default-umc-users,cn=UMC,cn=policies,dc=domain,dc=tld
No modification: cn=Domain Users,cn=groups,dc=domain,dc=tld
Object exists: cn=server-overview-all,cn=operations,cn=UMC,cn=univention,dc=domain,dc=tld
WARNING: cannot append cn=server-overview-all,cn=operations,cn=UMC,cn=univention,dc=domain,dc=tld to allow, value exists
No modification: cn=default-umc-all,cn=UMC,cn=policies,dc=domain,dc=tld
unknown module portals/entry.

Available Modules are:
appcenter/app
computers/computer
computers/domaincontroller_backup
computers/domaincontroller_master
computers/domaincontroller_slave
computers/ipmanagedclient
computers/linux
computers/macos
computers/memberserver
computers/trustaccount
computers/ubuntu
computers/windows
computers/windows_domaincontroller
container/cn
container/dc
container/ou
dhcp/dhcp
dhcp/host
dhcp/pool
dhcp/server
dhcp/service
dhcp/shared
dhcp/sharedsubnet
dhcp/subnet
dns/alias
dns/dns
dns/forward_zone
dns/host_record
dns/ns_record
dns/ptr_record
dns/reverse_zone
dns/srv_record
dns/txt_record
groups/group
kerberos/kdcentry
mail/domain
mail/folder
mail/lists
mail/mail
nagios/nagios
nagios/service
nagios/timeperiod
networks/network
policies/admin_container
policies/desktop
policies/dhcp_boot
policies/dhcp_dns
policies/dhcp_dnsupdate
policies/dhcp_leasetime
policies/dhcp_netbios
policies/dhcp_routing
policies/dhcp_scope
policies/dhcp_statements
policies/ldapserver
policies/maintenance
policies/masterpackages
policies/memberpackages
policies/nfsmounts
policies/policy
policies/printserver
policies/pwhistory
policies/registry
policies/release
policies/repositoryserver
policies/repositorysync
policies/share_userquota
policies/slavepackages
policies/umc
saml/idpconfig
saml/serviceprovider
settings/cn
settings/data
settings/default
settings/directory
settings/extended_attribute
settings/extended_options
settings/ldapacl
settings/ldapschema
settings/license
settings/lock
settings/packages
settings/portal
settings/portal_all
settings/portal_category
settings/portal_entry
settings/printermodel
settings/printeruri
settings/prohibited_username
settings/sambaconfig
settings/sambadomain
settings/service
settings/settings
settings/syntax
settings/udm_hook
settings/udm_module
settings/udm_syntax
settings/umc_operationset
settings/usertemplate
shares/print
shares/printer
shares/printergroup
shares/share
users/contact
users/ldap
users/passwd
users/self
users/user
35univention-server-overview.inst:
EXITCODE=1
c8e50cb5-0220-4267-8418-c398574132c3
univention-join-hooks: looking for hook type "join/post-joinscripts" on ucs.domain.tld
Found hooks:


Di Aug 31 09:45:00 CEST 2021
univention-run-join-scripts finished

Tue Aug 31 13:12:40 CEST 2021: starting /usr/sbin/univention-join
Tue Aug 31 13:12:40 CEST 2021: finish /usr/sbin/univention-join

After digging for a while I found out that the univention-directory-notifier service was failing. With the help of Problem: UMC Diagnostic Module Complains about Problems with UDN Replication I managed to solve that.

But /usr/share/univention-directory-notifier/univention-translog check is still showing the following errors:

root@ucs:~# /usr/share/univention-directory-notifier/univention-translog check
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742859:'16177646 uid=userA,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742860:'16177647 uid=userA,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742861:'16177648 uid=userB,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742862:'16177649 uid=userB,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742863:'16177650 uid=userC,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742864:'16177651 uid=userC,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742865:'16177652 uid=userD,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742866:'16177653 uid=userD,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,233:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742867:'16177654 uid=userE,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
2021-08-31 13:15:08,234:ERROR:/var/lib/univention-ldap/listener/listener.priv:4742868:'16177655 uid=userE,ou=users,ou=localOU,ou=benutzer,dc=domain,dc=tld m\n': Foreign dn
root@ucs:~#

How can I fix these problems?

Mastodon