Guten morgen!
Ja, habe ich jetzt gemacht und ausprobiert.
Ich kann jedoch nichts sinnvolles finden. Der Auszug aus dem Log vom DC-Master:
11.12.17 08:52:41.456 LDAP ( INFO ) : connecting to ldap://ucs-ad.domain.lan:7389
11.12.17 08:52:41.470 LDAP ( INFO ) : simple_bind as cn=admin,dc=domain,dc=lan
11.12.17 08:52:41.470 LISTENER ( PROCESS ) : updating ‘uid=benutzer,ou=Benutzer,dc=domain,dc=lan’ command m
11.12.17 08:52:41.470 LISTENER ( INFO ) : dntree_lookup_id4ldapdn: found id=1248
11.12.17 08:52:41.470 LISTENER ( INFO ) : got 3533 bytes for uid=benutzer,ou=benutzer,dc=domain,dc=lan
11.12.17 08:52:41.472 LISTENER ( INFO ) : dntree_lookup_id4ldapdn: found id=1248
11.12.17 08:52:41.472 LISTENER ( INFO ) : got 3533 bytes for uid=benutzer,ou=benutzer,dc=domain,dc=lan
11.12.17 08:52:41.472 LISTENER ( INFO ) : running handlers for uid=benutzer,ou=Benutzer,dc=domain,dc=lan
11.12.17 08:52:41.472 LISTENER ( INFO ) : handler: samba4-idmap (up-to-date)
11.12.17 08:52:41.472 LISTENER ( INFO ) : 1 master handler
UNIVENTION_DEBUG_BEGIN : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.486 LDAP ( INFO ) : establishing new connection with retry_max=11
11.12.17 08:52:41.495 LDAP ( INFO ) : bind binddn=cn=ucs-ad,cn=dc,cn=computers,dc=domain,dc=lan
UNIVENTION_DEBUG_END : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.503 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnActive=1) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
UNIVENTION_DEBUG_BEGIN : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.618 LDAP ( INFO ) : establishing new connection with retry_max=11
11.12.17 08:52:41.632 LDAP ( INFO ) : bind binddn=cn=ucs-ad,cn=dc,cn=computers,dc=domain,dc=lan
UNIVENTION_DEBUG_END : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.644 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnLicense=*) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
11.12.17 08:52:41.725 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnAccount=1) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
11.12.17 08:52:41.827 LISTENER ( INFO ) : 1 Found 1 active openvpn users (5 allowed)
11.12.17 08:52:41.827 LISTENER ( INFO ) : 1 Create new certificate for benutzer in /home/benutzer
11.12.17 08:52:41.827 LISTENER ( INFO ) : handler: openvpn-master (successful)
11.12.17 08:52:41.828 LISTENER ( INFO ) : handler: well-known-sid-name-mapping (up-to-date)
11.12.17 08:52:41.828 LISTENER ( INFO ) : handler: faillog (successful)
11.12.17 08:52:41.828 LISTENER ( INFO ) : dntree_lookup_id4ldapdn: found id=1248
11.12.17 08:52:41.832 LISTENER ( INFO ) : Last Notifier ID: 2818
11.12.17 08:52:56.835 LISTENER ( INFO ) : running postrun handlers
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: openvpn-master2 (prepared=0)
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: ldap_extension (prepared=0)
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: ldap_server (prepared=0)
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: openvpn-master (prepared=-1)
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: univention-saml-servers (prepared=0)
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: faillog (prepared=-1)
11.12.17 08:52:56.835 LISTENER ( INFO ) : postrun handler: gencertificate (prepared=0)
Und das Log vom DC-Backup:
11.12.17 08:52:41.456 LDAP ( INFO ) : connecting to ldap://ucs-ad.domain.lan:7389
11.12.17 08:52:41.475 LDAP ( INFO ) : simple_bind as cn=admin,dc=domain,dc=lan
11.12.17 08:52:41.476 LISTENER ( PROCESS ) : updating ‘uid=benutzer,ou=Benutzer,dc=domain,dc=lan’ command m
11.12.17 08:52:41.476 LISTENER ( INFO ) : dntree_lookup_id4ldapdn: found id=954
11.12.17 08:52:41.476 LISTENER ( INFO ) : got 3535 bytes for uid=benutzer,ou=benutzer,dc=domain,dc=lan
11.12.17 08:52:41.479 LISTENER ( INFO ) : checking parent_dn of uid=benutzer,ou=Benutzer,dc=domain,dc=lan in local LDAP
11.12.17 08:52:41.479 LDAP ( INFO ) : connecting to ldap://localhost:7389
11.12.17 08:52:41.491 LDAP ( INFO ) : simple_bind as cn=admin,dc=domain,dc=lan
11.12.17 08:52:41.493 LISTENER ( INFO ) : dntree_lookup_id4ldapdn: found id=954
11.12.17 08:52:41.493 LISTENER ( INFO ) : got 3535 bytes for uid=benutzer,ou=benutzer,dc=domain,dc=lan
11.12.17 08:52:41.493 LISTENER ( INFO ) : running handlers for uid=benutzer,ou=Benutzer,dc=domain,dc=lan
11.12.17 08:52:41.493 LISTENER ( INFO ) : replication: Running handler m for: uid=benutzer,ou=Benutzer,dc=domain,dc=lan
11.12.17 08:52:41.496 LISTENER ( INFO ) : replication: listener does not have value for key modifiersName
11.12.17 08:52:41.496 LISTENER ( INFO ) : replication: old entries from LDAP server and Listener do not match
11.12.17 08:52:41.499 LISTENER ( INFO ) : handler: replication (successful)
11.12.17 08:52:41.499 LISTENER ( INFO ) : 1 master handler
UNIVENTION_DEBUG_BEGIN : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.513 LDAP ( INFO ) : establishing new connection with retry_max=11
11.12.17 08:52:41.526 LDAP ( INFO ) : bind binddn=cn=dc-backup,cn=dc,cn=computers,dc=domain,dc=lan
UNIVENTION_DEBUG_END : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.539 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnActive=1) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
UNIVENTION_DEBUG_BEGIN : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.669 LDAP ( INFO ) : establishing new connection with retry_max=11
11.12.17 08:52:41.682 LDAP ( INFO ) : bind binddn=cn=dc-backup,cn=dc,cn=computers,dc=domain,dc=lan
UNIVENTION_DEBUG_END : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.695 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnLicense=) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
11.12.17 08:52:41.789 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnAccount=1) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
11.12.17 08:52:41.881 LISTENER ( INFO ) : 1 Found 1 active openvpn users (5 allowed)
11.12.17 08:52:41.881 LISTENER ( INFO ) : 1 Create new certificate for user in /home/user
11.12.17 08:52:41.881 LISTENER ( INFO ) : handler: openvpn-master (successful)
11.12.17 08:52:41.882 LISTENER ( INFO ) : handler: faillog (successful)
11.12.17 08:52:41.882 LISTENER ( INFO ) : handler: well-known-sid-name-mapping (up-to-date)
11.12.17 08:52:41.882 LISTENER ( INFO ) : 4 server2 handler
UNIVENTION_DEBUG_BEGIN : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.895 LDAP ( INFO ) : establishing new connection with retry_max=11
11.12.17 08:52:41.908 LDAP ( INFO ) : bind binddn=cn=dc-backup,cn=dc,cn=computers,dc=domain,dc=lan
UNIVENTION_DEBUG_END : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.921 LDAP ( INFO ) : uldap.search filter=(cn=dc-backup) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
UNIVENTION_DEBUG_BEGIN : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.939 LDAP ( INFO ) : establishing new connection with retry_max=11
11.12.17 08:52:41.952 LDAP ( INFO ) : bind binddn=cn=dc-backup,cn=dc,cn=computers,dc=domain,dc=lan
UNIVENTION_DEBUG_END : uldap.__open host=ucs-ad.domain.lan port=7389 base=dc=domain,dc=lan
11.12.17 08:52:41.966 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnLicense=) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
11.12.17 08:52:42.059 LDAP ( INFO ) : uldap.search filter=(univentionOpenvpnAccount=1) base= scope=sub attr=[] unique=0 required=0 timeout=-1 sizelimit=0
11.12.17 08:52:42.149 LISTENER ( INFO ) : 4 Found 1 active openvpn users (5 allowed)
11.12.17 08:52:42.152 LISTENER ( INFO ) : handler: openvpn-server2 (successful)
11.12.17 08:52:42.152 LISTENER ( INFO ) : dntree_lookup_id4ldapdn: found id=954
11.12.17 08:52:42.154 LISTENER ( INFO ) : write to transaction file dn=[uid=name,ou=Benutzer,dc=domain,dc=lan], command=[m]
11.12.17 08:52:42.157 LISTENER ( INFO ) : Last Notifier ID: 2818
11.12.17 08:52:57.173 LISTENER ( INFO ) : running postrun handlers
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: replication (prepared=-1)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: openvpn-sitetosite (prepared=0)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: openvpn-master2 (prepared=0)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: openvpn-master (prepared=-1)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: gencertificate (prepared=0)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: faillog (prepared=-1)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: ldap_extension (prepared=0)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: openvpn-server (prepared=0)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: ldap_server (prepared=0)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: openvpn-server2 (prepared=-1)
11.12.17 08:52:57.173 LISTENER ( INFO ) : postrun handler: univention-saml-simplesamlphp-configuration (prepared=0)
Liebe Grüße!