[quote=“Thorp-Hansen”]Dear fmp,
I still have eyes on your issue and as I said we want to help you. I want to give some inside in the progress and most likely causes of your present issue.
Since it is rather hard to solve your issues permanently without trying to find the underlying problem, I try to paint the way of the issue for clarification till now:
In july you had a failed AD-Takeover because of a service principal that was where it should not be at this point of the process. There was a workaround, so the AD-Takeover could commence.
Following this, there was a workaround, because the DNS Data was not where expected. Then a workaround for the S4 connector, so that it does not interfere with previous workarounds and additional help via forum and feedback all regarding the system in its present state.
We want to make the system work for you, but we need to first fix the underlying problems.
Can you confirm/check and send the following output from the console? We suspect that there is an issue that interfered with your AD-Takeover process and if that is the case we want to fix this issue and make you able to create a working system.
eval “$(ucr shell)”
univention-s4search --cross-ncs DC=“gc._msdcs”
univention-s4search --cross-ncs DC=“gc”
univention-s4search --cross-ncs DC="_gc._tcp.FMPHN._sites"
univention-s4search --cross-ncs DC="$domainname"
IF our suspicion turns out true the next step to really solve your issues and not create workaround after workaround would be to start over in a test environment first by doing the following steps:
- We provide a bugfix
- Start over with a UCS 4.0-3 Master with installed Bugfix
- Install S4 Connector (Important: Installation HAS to commence AFTER the installation of the bugfix)
- next steps as usual
Kind Regards,
Jens Thorp-Hansen[/quote]
Dear Jens Thorp-Hansen,
Appericate for your reply. Honestly, we are not familiar with UCS and Samba4 so we met a lot of trouble at the first time using UCS. In July, we had an error during the AD takeover progress. It’s true, and with help from an UCS specialist, we finished the AD takeover progress successfully. But we had problems in SSO between UCS and a system of us, so we came back to Windows AD. At the end of September, after finding out a solution for our SSO requirement, we came back to UCS. We got problems and started posting here, this thread. After a few days without a solution, we decied to re-install a new UCS server, turn on Windows AD and start everything from beginning (I’ve mentioned this at https://help.univention.com/t/windows-vertrauensstellung/118/1). So we think there’s no underlying problems here. Below is the result of commands as your requests:
root@ucs:~# [b]univention-s4search --cross-ncs DC="gc._msdcs"[/b]
Processing section "[netlogon]"
Processing section "[sysvol]"
Processing section "[IPC$]"
WARNING: No path in service IPC$ - making it unavailable!
NOTE: Service IPC$ is flagged unavailable.
Processing section "[homes]"
Processing section "[printers]"
Processing section "[print$]"
Processing section "[global]"
pm_process() returned Yes
GENSEC backend 'gssapi_spnego' registered
GENSEC backend 'gssapi_krb5' registered
GENSEC backend 'gssapi_krb5_sasl' registered
GENSEC backend 'spnego' registered
GENSEC backend 'schannel' registered
GENSEC backend 'naclrpc_as_system' registered
GENSEC backend 'sasl-EXTERNAL' registered
GENSEC backend 'ntlmssp' registered
GENSEC backend 'http_basic' registered
GENSEC backend 'http_ntlm' registered
GENSEC backend 'krb5' registered
GENSEC backend 'fake_gssapi_krb5' registered
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
resolve_lmhosts: Attempting lmhosts lookup for name ucs.fmphn.com<0x20>
startlmhosts: Can't open lmhosts file /etc/samba/lmhosts. Error was No such file or directory
Received smb_krb5 packet of length 268
Received smb_krb5 packet of length 1263
Received smb_krb5 packet of length 1259
Received smb_krb5 packet of length 1255
# record 1
dn: DC=gc._msdcs,DC=fmphn.com,CN=MicrosoftDNS,CN=System,DC=fmphn,DC=com
objectClass: top
objectClass: dnsNode
instanceType: 4
whenCreated: 20151010151635.0Z
uSNCreated: 10380
showInAdvancedViewOnly: TRUE
name: gc._msdcs
objectGUID: 4eb572d1-3fd6-4453-bf2f-30abc46022d2
objectCategory: CN=Dns-Node,CN=Schema,CN=Configuration,DC=fmphn,DC=com
dc: gc._msdcs
dnsRecord:: BAABAAXwAAABAAAAAAADhAAAAAAAAAAAwKgBDw==
dnsRecord:: BAABAAXwAAABAAAAAAADhAAAAAAAAAAAwKgBDg==
whenChanged: 20151010171516.0Z
uSNChanged: 10673
distinguishedName: DC=gc._msdcs,DC=fmphn.com,CN=MicrosoftDNS,CN=System,DC=fmphn,DC=com
# returned 1 records
# 1 entries
# 0 referrals
root@ucs:~#
# 0 referrals
root@ucs:~# [b]univention-s4search --cross-ncs DC="gc"[/b]
Processing section "[netlogon]"
Processing section "[sysvol]"
Processing section "[IPC$]"
WARNING: No path in service IPC$ - making it unavailable!
NOTE: Service IPC$ is flagged unavailable.
Processing section "[homes]"
Processing section "[printers]"
Processing section "[print$]"
Processing section "[global]"
pm_process() returned Yes
GENSEC backend 'gssapi_spnego' registered
GENSEC backend 'gssapi_krb5' registered
GENSEC backend 'gssapi_krb5_sasl' registered
GENSEC backend 'spnego' registered
GENSEC backend 'schannel' registered
GENSEC backend 'naclrpc_as_system' registered
GENSEC backend 'sasl-EXTERNAL' registered
GENSEC backend 'ntlmssp' registered
GENSEC backend 'http_basic' registered
GENSEC backend 'http_ntlm' registered
GENSEC backend 'krb5' registered
GENSEC backend 'fake_gssapi_krb5' registered
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
resolve_lmhosts: Attempting lmhosts lookup for name ucs.fmphn.com<0x20>
startlmhosts: Can't open lmhosts file /etc/samba/lmhosts. Error was No such file or directory
Received smb_krb5 packet of length 268
Received smb_krb5 packet of length 1263
Received smb_krb5 packet of length 1259
Received smb_krb5 packet of length 1255
# record 1
dn: DC=gc,DC=_msdcs.fmphn.com,CN=MicrosoftDNS,DC=DomainDnsZones,DC=fmphn,DC=com
objectClass: top
objectClass: dnsNode
instanceType: 4
whenCreated: 20150827172740.0Z
uSNCreated: 9893
showInAdvancedViewOnly: TRUE
name: gc
objectGUID: 21a9c627-ffe6-44d7-a635-5804f3b12c79
objectCategory: CN=Dns-Node,CN=Schema,CN=Configuration,DC=fmphn,DC=com
dNSTombstoned: FALSE
dc: gc
whenChanged: 20151010150729.0Z
uSNChanged: 10217
dnsRecord:: BAABAAXwAABQAAAAAAACWAAAAABoejcAwKgBDg==
dnsRecord:: BAABAAXwAABQAAAAAAADhAAAAABvejcAwKgBDw==
distinguishedName: DC=gc,DC=_msdcs.fmphn.com,CN=MicrosoftDNS,DC=DomainDnsZones ,DC=fmphn,DC=com
# returned 1 records
# 1 entries
# 0 referrals
root@ucs:~#
# 0 referrals
root@ucs:~# [b]univention-s4search --cross-ncs DC="_gc._tcp.FMPHN._sites"[/b]
Processing section "[netlogon]"
Processing section "[sysvol]"
Processing section "[IPC$]"
WARNING: No path in service IPC$ - making it unavailable!
NOTE: Service IPC$ is flagged unavailable.
Processing section "[homes]"
Processing section "[printers]"
Processing section "[print$]"
Processing section "[global]"
pm_process() returned Yes
GENSEC backend 'gssapi_spnego' registered
GENSEC backend 'gssapi_krb5' registered
GENSEC backend 'gssapi_krb5_sasl' registered
GENSEC backend 'spnego' registered
GENSEC backend 'schannel' registered
GENSEC backend 'naclrpc_as_system' registered
GENSEC backend 'sasl-EXTERNAL' registered
GENSEC backend 'ntlmssp' registered
GENSEC backend 'http_basic' registered
GENSEC backend 'http_ntlm' registered
GENSEC backend 'krb5' registered
GENSEC backend 'fake_gssapi_krb5' registered
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
resolve_lmhosts: Attempting lmhosts lookup for name ucs.fmphn.com<0x20>
startlmhosts: Can't open lmhosts file /etc/samba/lmhosts. Error was No such file or directory
Received smb_krb5 packet of length 268
Received smb_krb5 packet of length 1263
Received smb_krb5 packet of length 1259
Received smb_krb5 packet of length 1255
# record 1
dn: DC=_gc._tcp.FMPHN._sites,DC=fmphn.com,CN=MicrosoftDNS,DC=DomainDnsZones,DC=fmphn,DC=com
objectClass: top
objectClass: dnsNode
instanceType: 4
whenCreated: 20150727102250.0Z
whenChanged: 20150830161541.0Z
uSNCreated: 9867
uSNChanged: 9867
showInAdvancedViewOnly: TRUE
name: _gc._tcp.FMPHN._sites
objectGUID: 28632a27-874d-4434-89eb-f887cd0a8836
dnsRecord:: GwAhAAXwAACsNAAAAAACWAAAAAAAAAAAAAAAZAzEEwMHdWJxLXN2cgVmbXBobgNjb2
0A
dnsRecord:: GgAhAAXwAACsNAAAAAACWAAAAAAAAAAAAAAAZAzEEgMGZm1wLWFkBWZtcGhuA2NvbQ
A=
objectCategory: CN=Dns-Node,CN=Schema,CN=Configuration,DC=fmphn,DC=com
dNSTombstoned: FALSE
dc: _gc._tcp.FMPHN._sites
distinguishedName: DC=_gc._tcp.FMPHN._sites,DC=fmphn.com,CN=MicrosoftDNS,DC=Do
mainDnsZones,DC=fmphn,DC=com
# record 2
dn: DC=_gc._tcp.FMPHN._sites,DC=fmphn.com,CN=MicrosoftDNS,CN=System,DC=fmphn,DC=com
objectClass: top
objectClass: dnsNode
instanceType: 4
whenCreated: 20150828040039.0Z
uSNCreated: 4765
showInAdvancedViewOnly: TRUE
name: _gc._tcp.FMPHN._sites
objectGUID: efd23287-34cf-4877-acb9-6c8864e77ee4
objectCategory: CN=Dns-Node,CN=Schema,CN=Configuration,DC=fmphn,DC=com
dNSTombstoned: FALSE
dc: _gc._tcp.FMPHN._sites
dnsRecord:: GwAhAAXwAAABAAAAAAADhAAAAAAAAAAAAAAAZAzEEwMHZm1wLWRjMQVmbXBobgNjb2
0A
dnsRecord:: FwAhAAXwAAABAAAAAAADhAAAAAAAAAAAAAAAZAzEDwMDdWNzBWZtcGhuA2NvbQA=
whenChanged: 20151010151742.0Z
uSNChanged: 10453
distinguishedName: DC=_gc._tcp.FMPHN._sites,DC=fmphn.com,CN=MicrosoftDNS,CN=Sy
stem,DC=fmphn,DC=com
# returned 2 records
# 2 entries
# 0 referrals
root@ucs:~#
root@ucs:~# [b]univention-s4search --cross-ncs DC="$domainname"[/b]
Processing section "[netlogon]"
Processing section "[sysvol]"
Processing section "[IPC$]"
WARNING: No path in service IPC$ - making it unavailable!
NOTE: Service IPC$ is flagged unavailable.
Processing section "[homes]"
Processing section "[printers]"
Processing section "[print$]"
Processing section "[global]"
pm_process() returned Yes
GENSEC backend 'gssapi_spnego' registered
GENSEC backend 'gssapi_krb5' registered
GENSEC backend 'gssapi_krb5_sasl' registered
GENSEC backend 'spnego' registered
GENSEC backend 'schannel' registered
GENSEC backend 'naclrpc_as_system' registered
GENSEC backend 'sasl-EXTERNAL' registered
GENSEC backend 'ntlmssp' registered
GENSEC backend 'http_basic' registered
GENSEC backend 'http_ntlm' registered
GENSEC backend 'krb5' registered
GENSEC backend 'fake_gssapi_krb5' registered
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0:1 ip=192.168.1.14 bcast=192.168.1.255 netmask=255.255.255.0
added interface eth0 ip=192.168.1.15 bcast=192.168.1.255 netmask=255.255.255.0
resolve_lmhosts: Attempting lmhosts lookup for name ucs.fmphn.com<0x20>
startlmhosts: Can't open lmhosts file /etc/samba/lmhosts. Error was No such file or directory
Received smb_krb5 packet of length 268
Received smb_krb5 packet of length 1263
Received smb_krb5 packet of length 1259
Received smb_krb5 packet of length 1255
# returned 0 records
# 0 entries
# 0 referrals
root@ucs:~#
About this issue, we think that this is a special situation because the system told us that everything was successfully via UMC but in fact, BIND cannot access to update Samba internal DNS records which we can reach via DNS or LDAP in UMC. If you need any further information, please let us know. Thank you for your support.
Regards,
FMP