Univention-system-check find error during check_for_temporary_udm_sids.sh

UCS Master (version 4.3.3) errata 390 + Nextcloud (version 13.0.7-0):

Problem:

python ./univention-system-check

running [dns] - OK - forward_and_reverse_dns_kdc.sh
running [dns] - OK - forward_dns_myself.sh
running [basic] - OK - joinstatus.sh
running [basic] - OK - check_for_ntpd_process.sh
running [basic] - OK - package_status.sh
running [basic] - OK - univention_ldapsearch_machine_basic.sh
running [basic] - OK - check_for_dockerd_process.sh
running [basic] - OK - secure_apt_is_activated.sh
running [basic] - OK - univention_ldapsearch_machine_kerberos.sh
running [samba] - OK - check_s4_connector_rejects.sh
running [samba] - OK - check_samba_drs_replication.sh
running [samba] - OK - check_guid_msdcs_dns_alias.sh
running [samba] - OK - disabled_drsuapi_adtakeover_incomplete.sh
running [samba] - OK - check_samba_domain_trust.sh
running [samba] - OK - cn_system_exists_only_once.sh
running [samba] - OK - krbtgt_has_rid_502.sh
running [samba] - OK - master_is_member_of_enterprise_domain_controllers.sh
running [samba] - OK - check_samba_processes.sh
running [samba] - OK - check_smbclient_via_krb5_keytab.sh
running [samba] - OK - wbinfo_checks.sh
running [samba] - OK - check_s4_connector_autostart.sh
running [samba] - OK - cn_idmap_exists.sh
running [samba] - FAILED - check_for_temporary_udm_sids.sh
running [samba] - OK - no_3000_mapping_in_net_cache.sh
running [samba] - OK - check_ddns_update.sh
running [samba] - OK - check_s4_connector_listener_active.sh
running [samba] - OK - check_winbind_idmap_range.sh
running [samba] - OK - testjoin.sh
running [samba] - OK - check_for_USN_rollback.sh
running [samba] - OK - maximum_password_age_smaller_999.sh
running [samba] - OK - check_msds_keyversionnumber.sh
running [samba] - OK - hosts_sids_equal_in_ucs_and_samba.sh
running [listener] - OK - replication.sh
running [listener] - OK - all_handlers_initialized.sh
running [basic] - OK - check_nagios_status.py

Tests failed: 1

Test failed: univention-system-check.d/samba/check_for_temporary_udm_sids.sh

  • . /usr/share/univention-lib/ucr.sh
  • check_for_temporary_udm_sids
  • local output
  • local ‘filter=(&(|(&(objectClass=univentionWindows)(!(univentionServerRole=windows_domaincontroller)))(objectClass=computer)(objectClass=univentionMemberServer)(objectClass=univentionUbuntuClient)(objectClass=univentionLinuxClient)(objectClass=univentionMacOSClient)(objectClass=univentionCorporateClient)(&(objectClass=univentionDomainController)(univentionService=Samba 4))(objectClass=computer)(univentionServerRole=windows_domaincontroller))(sambasid=S-1-4-*))’
  • ‘[’ ‘’ = domaincontroller_master -o ‘’ = domaincontroller_backup ‘]’
    ++ univention-ldapsearch -LLL ‘(&(|(&(objectClass=univentionWindows)(!(univentionServerRole=windows_domaincontroller)))(objectClass=computer)(objectClass=univentionMemberServer)(objectClass=univentionUbuntuClient)(objectClass=univentionLinuxClient)(objectClass=univentionMacOSClient)(objectClass=univentionCorporateClient)(&(objectClass=univentionDomainController)(univentionService=Samba 4))(objectClass=computer)(univentionServerRole=windows_domaincontroller))(sambasid=S-1-4-*))’ dn sambasid
  • output=‘dn: cn=nextc-06175452,cn=memberserver,cn=computers,dc=My.Domain,dc=d
    e
    sambaSID: S-1-4-2053’
  • ‘[’ -n ‘dn: cn=nextc-06175452,cn=memberserver,cn=computers,dc=My.Domain,dc=d
    e
    sambaSID: S-1-4-2053’ ‘]’
  • echo ‘ERROR: The following objects have internal UDM SIDs’
    ERROR: The following objects have internal UDM SIDs
  • echo ===================================================
    ===================================================
  • echo ‘dn: cn=nextc-06175452,cn=memberserver,cn=computers,dc=My.Domain,dc=d
    e
    sambaSID: S-1-4-2053’
    dn: cn=nextc-06175452,cn=memberserver,cn=computers,dc=My.Domain,dc=d
    e
    sambaSID: S-1-4-2053
  • echo ===================================================
    ===================================================
  • exit 1

Any solution ?

Bump …

we are facing the same problem at several customer environments.

Any suggestions from Univention?

Kind regards,
René

Mastodon