So I quickly tested this with the following setup:
1x Windows Server 2008 R2 (because I don’t have a french Windows 2003) as Active Directory Domain controller and DNS Server
Domain name: ad.example.org
1x UCS 4.1
I did NOT choose “Join existing AD domain” during the installation, because the other way it’s a bit easier to access the logs:
- As DNS server enter the IP of the Windows Server
- During installation choose “Create new UCS domain”
- Name the domain exactly the same as the AD domain: ad.example.org
- As FQDN I chose ucs.ad.example.org
- Choose “Active Direction Connection” as Software component to be installed
- When the installation is done, log in to the UMC using Administrator and the password chosen during UCS installation
- Go to the Domain category and select the “Active Directory Connection” Module
- Specify the IP Adress of the Windows DC
- Specify the name of the Windows AD Administrator: Administrateur
- Enter the password of the Administrateur account of the Windows AD
- Start the join process and wait for it to finish
- Reload the UMC (or restart the service or even the server)
- Log in to the UMC as Administrateur and the password of the Windows AD
- I could then access all UMC modules
In the log file “/var/log/univention/management-console-module-adconnector.log” I also see this:
02.12.15 22:02:05.374 MODULE ( PROCESS ) : Renaming well known SID objects...
02.12.15 22:02:05.580 MODULE ( PROCESS ) : Matching well known object names
02.12.15 22:02:07.021 MODULE ( PROCESS ) : Create connector/ad/mapping/group/table/Printer-Admins
Process: Renaming 'cn=Domain Admins,cn=groups,dc=ad,dc=example,dc=org' to 'Admins du domaine' in UCS LDAP.
Process: Renaming 'cn=Domain Users,cn=groups,dc=ad,dc=example,dc=org' to 'Utilisateurs du domaine' in UCS LDAP.
Process: Modifying 'cn=default,cn=univention,dc=ad,dc=example,dc=org' in UCS LDAP.
Process: Renaming 'cn=Domain Guests,cn=groups,dc=ad,dc=example,dc=org' to 'Invités du domaine' in UCS LDAP.
Process: Renaming 'uid=Administrator,cn=users,dc=ad,dc=example,dc=org' to 'Administrateur' in UCS LDAP.
That’s fine and expected.
I don’t see the “NT_STATUS_NO_SUCH_USER” in setup.log
If you want to try it again and follow my instructions from above, please delete the computer object of the UCS system and the DNS entries (especially the SRV record “_domaincontroller_master”) from the Windows AD before starting over.