Guten Morgen,
wir haben einen Backup DC zu einem Master hochgestuft und den alten Master DC ausser Betrieb genommen. Bisher gab es keine Probleme. Nun wurde ein Slave DC aufgesetzt auf dem Zarafa installiert werden sollte.
Die Installation schlägt fehlt mit folgender Meldung:
Die Ausführung des Kommandos appcenter/invoke_dry_run ist fehlgeschlagen:
Traceback (most recent call last):
File "/usr/lib/pymodules/python2.7/univention/management/console/base.py", line 283, in execute
function(self, request)
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/appcenter/__init__.py", line 291, in invoke_dry_run
self.invoke(request)
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/decorators.py", line 656, in _decorated
return function(self, request, *args, **kwargs)
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/decorators.py", line 190, in _response
return function(self, request)
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/appcenter/__init__.py", line 492, in invoke
dry_run_result, previously_registered_by_dry_run = application.install_dry_run(self.package_manager, self.component_manager, remove_component=remove_component, username=self._username, password=self.password, only_master_packages=only_master_packages, dont_remote_install=dont_remote_install, function=function, force=force)
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/appcenter/app_center.py", line 1272, in install_dry_run
hosts = self.find_all_hosts(is_master=is_master)
File "/usr/lib/pymodules/python2.7/univention/management/console/ldap.py", line 135, in _decorated
result = func(*args, **kwargs)
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/appcenter/app_center.py", line 1575, in find_all_hosts
hosts.append((get_master(lo), True))
File "/usr/lib/pymodules/python2.7/univention/management/console/modules/appcenter/util.py", line 102, in get_master
return get_hosts(domaincontroller_master, lo)[0].info['fqdn']
IndexError: list index out of range
Anscheinend findet der Slave keinen Master mit LDAP. Im Computer-Objekt des neuen Masters ist jedoch der Dienst ausgeführt und ist auch gestartet.
Führe ich jedoch [quote]ldapsearch -x -h ucs[/quote] aus erhalte ich sowohl auf dem Slave als auch auf dem Master:
ldap_sasl_bind(SIMPLE): Can't contact LDAP server (-1)
Desweiteren gibt es rejects auf dem S4 Connector:
[code]root@bernd:~# univention-s4connector-list-rejected
UCS rejected
1: UCS DN: cn=Printer-Admins,cn=groups,dc=mueller,dc=lan
S4 DN: <not found>
Filename: /var/lib/univention-connector/s4/1448301751.800197
2: UCS DN: cn=Printer-Admins,cn=groups,dc=mueller,dc=lan
S4 DN: <not found>
Filename: /var/lib/univention-connector/s4/1448301793.611938
S4 rejected
1: S4 DN: CN=Print Operators,CN=Builtin,DC=mueller,DC=lan
UCS DN: <not found>
last synced USN: 3863
[/code]
Im /var/log/univention/connector-s4.log steht:
[code]02.12.2015 23:01:46,533 LDAP (PROCESS): sync to ucs: Resync rejected dn: CN=Print Operators,CN=Builtin,DC=mueller,DC=lan
02.12.2015 23:01:46,535 LDAP (PROCESS): sync to ucs: [ group] [ modify] cn=Printer-Admins,cn=groups,dc=mueller,dc=lan
02.12.2015 23:01:46,555 LDAP (PROCESS): Unable to sync cn=Printer-Admins,cn=groups,dc=mueller,dc=lan (UUID: f1a7be28-f974-1034-8e10-ef3f8c0cae3a). The object is currently locked.
02.12.2015 23:02:41,830 LDAP (PROCESS): sync from ucs: Resync rejected file: /var/lib/univention-connector/s4/1448301751.800197
02.12.2015 23:02:41,833 LDAP (PROCESS): sync from ucs: [ group] [ add] cn=Printer-Admins,cn=groups,DC=mueller,DC=lan
02.12.2015 23:02:41,835 LDAP (ERROR ): sync_from_ucs: traceback during add object: cn=Printer-Admins,cn=groups,DC=mueller,DC=lan
02.12.2015 23:02:41,836 LDAP (ERROR ): sync_from_ucs: traceback due to addlist: [(‘objectClass’, [‘top’, ‘group’]), (‘groupType’, [u’-2147483643’]), (u’description’, [u’Members can administer domain printers’]), (‘sAMAccountName’, [u’Print Operators’]), (‘objectSid’, [’\x01\x02\x00\x00\x00\x00\x00\x05 \x00\x00\x00&\x02\x00\x00’])]
02.12.2015 23:02:41,836 LDAP (WARNING): sync failed, saved as rejected
/var/lib/univention-connector/s4/1448301751.800197
02.12.2015 23:02:41,836 LDAP (WARNING): Traceback (most recent call last):
File “/usr/lib/pymodules/python2.7/univention/s4connector/init.py”, line 802, in __sync_file_from_ucs
or (not old_dn and not self.sync_from_ucs(key, object, premapped_ucs_dn, old_dn, old, new))):
File “/usr/lib/pymodules/python2.7/univention/s4connector/s4/init.py”, line 2402, in sync_from_ucs
self.lo_s4.lo.add_ext_s(compatible_modstring(object[‘dn’]), compatible_addlist(addlist), serverctrls=ctrls) #FIXME encoding
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 187, in add_ext_s
resp_type, resp_data, resp_msgid, resp_ctrls = self.result3(msgid,all=1,timeout=self.timeout)
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 476, in result3
resp_ctrl_classes=resp_ctrl_classes
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 483, in result4
ldap_result = self._ldap_call(self._l.result4,msgid,all,timeout,add_ctrls,add_intermediates,add_extop)
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 106, in _ldap_call
result = func(*args,**kwargs)
ALREADY_EXISTS: {‘info’: ‘00002071: …/ldb_tdb/ldb_index.c:1216: Failed to re-index objectSid in CN=Printer-Admins,CN=Groups,DC=mueller,DC=lan - …/ldb_tdb/ldb_index.c:1148: unique index violation on objectSid in CN=Printer-Admins,CN=Groups,DC=mueller,DC=lan’, ‘desc’: ‘Already exists’}
02.12.2015 23:02:41,837 LDAP (PROCESS): sync from ucs: Resync rejected file: /var/lib/univention-connector/s4/1448301793.611938
02.12.2015 23:02:41,839 LDAP (PROCESS): sync from ucs: [ group] [ add] cn=Printer-Admins,cn=groups,DC=mueller,DC=lan
02.12.2015 23:02:41,841 LDAP (ERROR ): sync_from_ucs: traceback during add object: cn=Printer-Admins,cn=groups,DC=mueller,DC=lan
02.12.2015 23:02:41,841 LDAP (ERROR ): sync_from_ucs: traceback due to addlist: [(‘objectClass’, [‘top’, ‘group’]), (‘groupType’, [u’-2147483643’]), (u’description’, [u’Members can administer domain printers’]), (‘sAMAccountName’, [u’Print Operators’]), (‘objectSid’, [’\x01\x02\x00\x00\x00\x00\x00\x05 \x00\x00\x00&\x02\x00\x00’])]
02.12.2015 23:02:41,844 LDAP (WARNING): sync failed, saved as rejected
/var/lib/univention-connector/s4/1448301793.611938
02.12.2015 23:02:41,844 LDAP (WARNING): Traceback (most recent call last):
File “/usr/lib/pymodules/python2.7/univention/s4connector/init.py”, line 802, in __sync_file_from_ucs
or (not old_dn and not self.sync_from_ucs(key, object, premapped_ucs_dn, old_dn, old, new))):
File “/usr/lib/pymodules/python2.7/univention/s4connector/s4/init.py”, line 2402, in sync_from_ucs
self.lo_s4.lo.add_ext_s(compatible_modstring(object[‘dn’]), compatible_addlist(addlist), serverctrls=ctrls) #FIXME encoding
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 187, in add_ext_s
resp_type, resp_data, resp_msgid, resp_ctrls = self.result3(msgid,all=1,timeout=self.timeout)
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 476, in result3
resp_ctrl_classes=resp_ctrl_classes
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 483, in result4
ldap_result = self._ldap_call(self._l.result4,msgid,all,timeout,add_ctrls,add_intermediates,add_extop)
File “/usr/lib/python2.7/dist-packages/ldap/ldapobject.py”, line 106, in _ldap_call
result = func(*args,**kwargs)
ALREADY_EXISTS: {‘info’: ‘00002071: …/ldb_tdb/ldb_index.c:1216: Failed to re-index objectSid in CN=Printer-Admins,CN=Groups,DC=mueller,DC=lan - …/ldb_tdb/ldb_index.c:1148: unique index violation on objectSid in CN=Printer-Admins,CN=Groups,DC=mueller,DC=lan’, ‘desc’: ‘Already exists’}
[/code]
Im Computer Objekt vom neuen Master steht als Typ noch [quote]Typ: Rechner: Domänencontroller Backup[/quote]
Im LDAP ist der Master unter [quote]Position: lan.mueller:/computers/dc[/quote] aufgeführt. Müsste er nicht unter [quote]lan.mueller:/Domain Controllers[/quote] stehen?
Ich benötige Unterstützung, da ich derzeit nicht wirklich weiß wo ich ansetzen kann.