Hallo zusammen,
ich habe hier einen Windows 2012 an welchen wir per Connector den ersten UCS angebunden haben. Nennt sich dieser UCS dann Master oder wie heitßt die Rolle? ADS-Member? … nur rein Informativ.
Ich habe wollte jetzt einen Backup hinzufügen und habe im Installaer auc entsprechend ausgewählt:
-> Mitglied einer UCS-Domäne -> Backup
Funktioniert so etwas überhaupt? Ich bekomme nun nähmlich den Join nicht hin. Wenn ich ihn auf der Konsole aufrufe erhalte ich:
root@backup01:~# univention-join
univention-join: joins a computer to an ucs domain
copyright (c) 2001-2017 Univention GmbH, Germany
Enter DC Master Account : Administrator
Enter DC Master Password:
Search DC Master: done
Check DC Master: done
Search ldap/base done
Search LDAP binddn done
Sync time: done
Join Computer Account: done
Stopping univention-directory-listener daemon: done
Sync ldap.secret: done
Sync ldap-backup.secret: done
Sync SSL directory: done
Check TLS connection: done
Download host certificate: done
Sync SSL settings: done
Restart LDAP Server: done
Sync Kerberos settings: done
Not updating kerberos/adminserver
Configure 03univention-directory-listener.inst done
Configure 08univention-apache.inst done
Configure 18python-univention-directory-manager.inst done
Configure 20univention-directory-policy.inst failed
**************************************************************************
* Join failed! *
* Contact your system administrator *
**************************************************************************
* Message: FAILED: 20univention-directory-policy.inst
**************************************************************************
Im join.log finde ich:
Tue Jan 30 08:03:24 CET 2018: starting /usr/sbin/univention-join
running version check
OK: UCS version on tux.stedry.local is higher or equal (4.23) to the local version (4.22).
Tue Jan 30 08:03:43 CET 2018
univention-server-join: joins a server to an univention domain
copyright (c) 2001-2017 Univention GmbH, Germany
ldap_dn="cn=backup01,cn=dc,cn=computers,dc=stedry,dc=local"
Setting hostname
Setting ldap/hostdn
File: /etc/pam.d/smtp
File: /etc/welcome.msg
Multifile: /etc/postfix/ldap.virtualwithcanonical
File: /etc/apache2/conf-available/ucs.conf
File: /etc/issue
Multifile: /etc/postfix/ldap.virtual_mailbox
Multifile: /etc/hosts
Multifile: /etc/postfix/ldap.sharedfolderlocal_aliases
File: /etc/dhcp/dhclient.conf
Multifile: /etc/postfix/ldap.transport
Multifile: /etc/postfix/ldap.canonicalrecipient
Multifile: /etc/postfix/ldap.virtual
Multifile: /etc/postfix/ldap.saslusermapping
Multifile: /etc/postfix/ldap.virtualdomains
Multifile: /etc/postfix/ldap.distlist
Multifile: /etc/postfix/ldap.groups
Multifile: /etc/postfix/ldap.canonicalsender
Multifile: /etc/postfix/ldap.sharedfolderlocal
File: /etc/mailname
File: /etc/cron.d/univention-directory-policy
Multifile: /etc/postfix/main.cf
Multifile: /etc/postfix/ldap.sharedfolderremote
File: /etc/hostname
File: /etc/apache2/sites-available/univention-proxy.conf
Multifile: /etc/postfix/ldap.external_aliases
Multifile: /etc/apache2/sites-available/default-ssl.conf
Multifile: /etc/pam.d/univention-management-console
ok: down: univention-directory-listener: 0s
Setting ldap/server/name
Setting ldap/server/ip
Not updating ldap/server/port
Setting ldap/master
Not updating ldap/master/port
Setting ldap/server/type
Multifile: /etc/postfix/ldap.external_aliases
File: /etc/pam.d/smtp
Multifile: /etc/postfix/ldap.virtualwithcanonical
File: /etc/krb5.conf
Multifile: /etc/postfix/ldap.virtual_mailbox
Multifile: /etc/postfix/ldap.sharedfolderlocal_aliases
Multifile: /etc/postfix/ldap.transport
Multifile: /etc/postfix/ldap.canonicalrecipient
Multifile: /etc/postfix/ldap.virtual
Multifile: /etc/postfix/ldap.saslusermapping
Multifile: /etc/postfix/ldap.virtualdomains
Multifile: /etc/postfix/ldap.distlist
Multifile: /etc/postfix/ldap.groups
Multifile: /etc/postfix/ldap.canonicalsender
Multifile: /etc/postfix/ldap.sharedfolderlocal
File: /etc/default/ntpdate
Multifile: /etc/postfix/ldap.sharedfolderremote
File: /etc/ntp.conf
rsync: send_files failed to open "/etc/univention/ssl/ucsCA/certs/05.pem": Permission denied (13)
rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1655) [generator=3.1.1]
Clearing symlinks in /etc/ssl/certs...
done.
Updating certificates in /etc/ssl/certs...
174 added, 0 removed; done.
Running hooks in /etc/ca-certificates/update.d...
done.
Could not chdir to home directory /dev/null: Not a directory
Could not chdir to home directory /dev/null: Not a directory
Setting ssl/country
Setting ssl/state
Setting ssl/locality
Setting ssl/organization
Setting ssl/organizationalunit
Setting ssl/common
Setting ssl/email
/usr/sbin/univention-join: Zeile 806: /etc/init.d/slapd: Datei oder Verzeichnis nicht gefunden
/var/lib/heimdal-kdc/: Is a directory
/var/lib/heimdal-kdc/: Is a directory
/var/lib/heimdal-kdc/: Is a directory
/var/lib/heimdal-kdc/: Is a directory
/var/lib/heimdal-kdc/: Is a directory
Not updating ldap/server/name
Not updating ldap/master
30.01.18 08:04:03.906 DEBUG_INIT
UNIVENTION_DEBUG_BEGIN : uldap.__open host=tux.stedry.local port=7389 base=dc=stedry,dc=local
UNIVENTION_DEBUG_END : uldap.__open host=tux.stedry.local port=7389 base=dc=stedry,dc=local
Setting kerberos/realm
File: /etc/krb5.conf
Setting windows/domain
File: /etc/krb5.conf
30.01.18 08:04:06.208 DEBUG_INIT
UNIVENTION_DEBUG_BEGIN : uldap.__open host=tux.stedry.local port=7389 base=dc=stedry,dc=local
UNIVENTION_DEBUG_END : uldap.__open host=tux.stedry.local port=7389 base=dc=stedry,dc=local
30.01.18 08:04:06.399 DEBUG_INIT
Configure 03univention-directory-listener.inst Tue Jan 30 08:04:06 CET 2018
2018-01-30 08:04:06.430407683+01:00 (in joinscript_init)
Setting ldap/database/ldbm/dbsync
30.01.18 08:04:06.672 DEBUG_INIT
30.01.18 08:04:07.278 LISTENER ( WARN ) : Set Schema ID to 9
30.01.18 08:04:07.278 LISTENER ( WARN ) : initializing module gencertificate
30.01.18 08:04:07.279 LISTENER ( ERROR ) : could not get DNs when initializing gencertificate: No such object
30.01.18 08:04:07.279 LISTENER ( WARN ) : initializing module umc-service-providers
30.01.18 08:04:07.280 LISTENER ( ERROR ) : could not get DNs when initializing umc-service-providers: No such object
30.01.18 08:04:07.280 LISTENER ( WARN ) : initializing module univention-saml-servers
30.01.18 08:04:07.281 LISTENER ( ERROR ) : could not get DNs when initializing univention-saml-servers: No such object
30.01.18 08:04:07.281 LISTENER ( WARN ) : initializing module hosteddomains
30.01.18 08:04:07.282 LISTENER ( ERROR ) : could not get DNs when initializing hosteddomains: No such object
30.01.18 08:04:07.282 LISTENER ( WARN ) : initializing module license_uuid
30.01.18 08:04:07.283 LISTENER ( ERROR ) : could not get DNs when initializing license_uuid: No such object
30.01.18 08:04:07.283 LISTENER ( WARN ) : initializing module ldap_server
30.01.18 08:04:07.283 LISTENER ( ERROR ) : could not get DNs when initializing ldap_server: No such object
30.01.18 08:04:07.283 LISTENER ( WARN ) : initializing module udm_extension
30.01.18 08:04:07.284 LISTENER ( ERROR ) : could not get DNs when initializing udm_extension: No such object
Setting ldap/database/ldbm/dbsync
Starting univention-directory-listener (via systemctl): univention-directory-listener.service.
2018-01-30 08:04:22.400958740+01:00 (in joinscript_save_current_version)
Configure 08univention-apache.inst Tue Jan 30 08:04:22 CET 2018
2018-01-30 08:04:22.945075978+01:00 (in joinscript_init)
Module ssl disabled.
To activate the new configuration, you need to run:
service apache2 restart
Considering dependency setenvif for ssl:
Module setenvif already enabled
Considering dependency mime for ssl:
Module mime already enabled
Considering dependency socache_shmcb for ssl:
Module socache_shmcb already enabled
Enabling module ssl.
See /usr/share/doc/apache2/README.Debian.gz on how to configure SSL and create self-signed certificates.
To activate the new configuration, you need to run:
service apache2 restart
Site default-ssl disabled.
To activate the new configuration, you need to run:
service apache2 reload
Enabling site default-ssl.
To activate the new configuration, you need to run:
service apache2 reload
Reloading apache2 configuration (via systemctl): apache2.service.
2018-01-30 08:04:23.536012264+01:00 (in joinscript_save_current_version)
Configure 18python-univention-directory-manager.inst Tue Jan 30 08:04:23 CET 2018
2018-01-30 08:04:23.682746393+01:00 (in joinscript_init)
Object exists: cn=objectFlag,cn=custom attributes,cn=univention,dc=stedry,dc=local
2018-01-30 08:04:25.395185234+01:00 (in joinscript_save_current_version)
Configure 20univention-directory-policy.inst Tue Jan 30 08:04:25 CET 2018
2018-01-30 08:04:25.423444859+01:00 (in joinscript_init)
nfsmounts: FAIL: failed to execute `univention_policy_result cn=backup01,cn=dc,cn=computers,dc=stedry,dc=local'
run-parts: /usr/lib/univention-directory-policy/nfsmounts exited with return code 1
Traceback (most recent call last):
File "/usr/lib/univention-directory-policy/univention-policy-maintenance", line 77, in <module>
p1 = subprocess.Popen(['univention_policy_result', '-D', ldap_hostdn, '-y', '/etc/machine.secret', '-s', ldap_hostdn], stdout=subprocess.PIPE)
File "/usr/lib/python2.7/subprocess.py", line 710, in __init__
errread, errwrite)
File "/usr/lib/python2.7/subprocess.py", line 1335, in _execute_child
raise child_exception
OSError: [Errno 2] No such file or directory
run-parts: /usr/lib/univention-directory-policy/univention-policy-maintenance exited with return code 1
Traceback (most recent call last):
File "/usr/lib/univention-directory-policy/univention-policy-repository-sync", line 51, in <module>
p1 = subprocess.Popen(['univention_policy_result', '-D', ldap_hostdn, '-y', '/etc/machine.secret', '-s', ldap_hostdn], stdout=subprocess.PIPE)
File "/usr/lib/python2.7/subprocess.py", line 710, in __init__
errread, errwrite)
File "/usr/lib/python2.7/subprocess.py", line 1335, in _execute_child
raise child_exception
OSError: [Errno 2] No such file or directory
run-parts: /usr/lib/univention-directory-policy/univention-policy-repository-sync exited with return code 1
Traceback (most recent call last):
File "/usr/lib/univention-directory-policy/univention-policy-set-repository-server", line 114, in <module>
main()
File "/usr/lib/univention-directory-policy/univention-policy-set-repository-server", line 97, in main
new_server, update = query_policy(update, hostdn)
File "/usr/lib/univention-directory-policy/univention-policy-set-repository-server", line 60, in query_policy
p1 = subprocess.Popen(cmd, stdout=subprocess.PIPE)
File "/usr/lib/python2.7/subprocess.py", line 710, in __init__
errread, errwrite)
File "/usr/lib/python2.7/subprocess.py", line 1335, in _execute_child
raise child_exception
OSError: [Errno 2] No such file or directory
run-parts: /usr/lib/univention-directory-policy/univention-policy-set-repository-server exited with return code 1
Traceback (most recent call last):
File "/usr/lib/univention-directory-policy/univention-policy-update-config-registry", line 146, in <module>
main()
File "/usr/lib/univention-directory-policy/univention-policy-update-config-registry", line 118, in main
set_list = get_policy(host_dn, options.verbose)
File "/usr/lib/univention-directory-policy/univention-policy-update-config-registry", line 50, in get_policy
proc = subprocess.Popen(cmd, shell=False, stdout=subprocess.PIPE)
File "/usr/lib/python2.7/subprocess.py", line 710, in __init__
errread, errwrite)
File "/usr/lib/python2.7/subprocess.py", line 1335, in _execute_child
raise child_exception
OSError: [Errno 2] No such file or directory
run-parts: /usr/lib/univention-directory-policy/univention-policy-update-config-registry exited with return code 1
Tue Jan 30 08:04:25 CET 2018: finish /usr/sbin/univention-join
Was genau ist das Problem oder funktioniert die von mir installierte Konstellation gar nicht?
Viele Grüße
Sven