2017-01-10 01:35:51,053 Found account Administrator with well known RID 500 (Administrator) 2017-01-10 01:35:51,055 Found account krbtgt with well known RID 502 (KRBTGT) 2017-01-10 01:35:51,055 Found account Guest with well known RID 501 (Guest) 2017-01-10 01:35:51,073 Found group Allowed RODC Password Replication Group with well known RID 571 (Allowed RODC Password Replication Group) 2017-01-10 01:35:51,074 Found group Enterprise Read-Only Domain Controllers with well known RID 498 (Enterprise Read-only Domain Controllers) 2017-01-10 01:35:51,074 Found group Denied RODC Password Replication Group with well known RID 572 (Denied RODC Password Replication Group) 2017-01-10 01:35:51,074 Found group Read-Only Domain Controllers with well known RID 521 (Read-Only Domain Controllers) 2017-01-10 01:35:51,074 Found group Group Policy Creator Owners with well known RID 520 (Group Policy Creator Owners) 2017-01-10 01:35:51,074 Found group RAS and IAS Servers with well known RID 553 (RAS and IAS Servers) 2017-01-10 01:35:51,074 Found group Domain Controllers with well known RID 516 (Domain Controllers) 2017-01-10 01:35:51,074 Found group Enterprise Admins with well known RID 519 (Enterprise Admins) 2017-01-10 01:35:51,074 Found group Domain Computers with well known RID 515 (Domain Computers) 2017-01-10 01:35:51,075 Found group Cert Publishers with well known RID 517 (Cert Publishers) 2017-01-10 01:35:51,075 Found group Domain Admins with well known RID 512 (Domain Admins) 2017-01-10 01:35:51,075 Found group Domain Guests with well known RID 514 (Domain Guests) 2017-01-10 01:35:51,075 Found group Schema Admins with well known RID 518 (Schema Admins) 2017-01-10 01:35:51,075 Found group Domain Users with well known RID 513 (Domain Users) 2017-01-10 01:35:51,208 determine_license for current UCS Users: 0 of unlimited 2017-01-10 01:35:51,208 2 Systemaccounts are ignored. 2017-01-10 01:35:51,208 Found 393 Benutzer objects on the remote server. 2017-01-10 01:35:52,669 INFO: Time difference is less than 180 seconds, skipping reset of local time 2017-01-10 01:35:52,702 Starting phase I of the takeover process. 2017-01-10 01:35:52,702 Calling: univention-config-registry set hosts/static/192.168.200.2=zentyal.gr.gc ZENTYAL 2017-01-10 01:35:52,932 Create hosts/static/192.168.200.2 2017-01-10 01:35:52,933 Multifile: /etc/hosts 2017-01-10 01:35:52,933 Calling: /etc/init.d/univention-s4-connector stop 2017-01-10 01:35:52,943 Stopping univention-s4-connector daemon. 2017-01-10 01:35:52,965 done. 2017-01-10 01:35:52,966 Calling: /etc/init.d/samba-ad-dc stop 2017-01-10 01:35:53,296 Stopping Samba AD DC daemon: samba. 2017-01-10 01:35:53,298 Calling: univention-config-registry set nameserver1/local=192.168.200.2 nameserver1=192.168.200.2 directory/manager/web/modules/users/user/properties/username/syntax=string directory/manager/web/modules/groups/group/properties/name/syntax=string dns/backend=ldap 2017-01-10 01:35:53,476 Create nameserver1/local 2017-01-10 01:35:53,476 Setting nameserver1 2017-01-10 01:35:53,476 Setting directory/manager/web/modules/users/user/properties/username/syntax 2017-01-10 01:35:53,476 Setting directory/manager/web/modules/groups/group/properties/name/syntax 2017-01-10 01:35:53,477 Setting dns/backend 2017-01-10 01:35:53,477 File: /etc/resolv.conf 2017-01-10 01:35:53,487 Calling: /etc/init.d/nscd stop 2017-01-10 01:35:53,514 Stopping Name Service Cache Daemon: nscd. 2017-01-10 01:35:53,514 Calling: /etc/init.d/bind9 restart 2017-01-10 01:36:00,166 Restarting bind9 daemon: ...done. 2017-01-10 01:36:00,167 Starting Samba domain join. 2017-01-10 01:36:00,474 SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS 2017-01-10 01:36:00,523 workgroup is GR 2017-01-10 01:36:00,524 realm is gr.gc 2017-01-10 01:36:00,617 SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS 2017-01-10 01:36:01,342 Looking up IPv4 addresses 2017-01-10 01:36:01,344 Looking up IPv6 addresses 2017-01-10 01:36:01,345 No IPv6 address will be assigned 2017-01-10 01:36:01,723 Setting up share.ldb 2017-01-10 01:36:01,740 Setting up secrets.ldb 2017-01-10 01:36:01,766 Setting up the registry 2017-01-10 01:36:01,824 Setting up the privileges database 2017-01-10 01:36:01,854 Setting up idmap db 2017-01-10 01:36:01,873 Setting up SAM db 2017-01-10 01:36:01,880 Setting up sam.ldb partitions and settings 2017-01-10 01:36:01,893 Setting up sam.ldb rootDSE 2017-01-10 01:36:01,910 Pre-loading the Samba 4 and AD schema 2017-01-10 01:36:01,946 A Kerberos configuration suitable for Samba 4 has been generated at /var/lib/samba/private/krb5.conf 2017-01-10 01:36:01,963 SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS 2017-01-10 01:36:02,419 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[402/1550] linked_values[0/0] 2017-01-10 01:36:02,686 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[804/1550] linked_values[0/0] 2017-01-10 01:36:02,955 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[1206/1550] linked_values[0/0] 2017-01-10 01:36:03,183 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[1550/1550] linked_values[0/0] 2017-01-10 01:36:03,184 Analyze and apply schema objects 2017-01-10 01:36:05,588 Partition[CN=Configuration,DC=gr,DC=gc] objects[402/1633] linked_values[0/0] 2017-01-10 01:36:06,256 Partition[CN=Configuration,DC=gr,DC=gc] objects[804/1633] linked_values[0/0] 2017-01-10 01:36:06,912 Partition[CN=Configuration,DC=gr,DC=gc] objects[1206/1633] linked_values[0/0] 2017-01-10 01:36:07,581 Partition[CN=Configuration,DC=gr,DC=gc] objects[1608/1633] linked_values[0/0] 2017-01-10 01:36:08,039 Partition[CN=Configuration,DC=gr,DC=gc] objects[1633/1633] linked_values[48/0] 2017-01-10 01:36:08,316 Partition[DC=gr,DC=gc] objects[99/99] linked_values[35/0] 2017-01-10 01:36:08,442 Failed to commit objects: WERR_DS_DRA_MISSING_PARENT 2017-01-10 01:36:08,492 Could not find machine account in secrets database: Failed to fetch machine account password for GR from both secrets.ldb (Could not find entry to match filter: '(&(flatname=GR)(objectclass=primaryDomain))' base: 'cn=Primary Domains': No such object: dsdb_search at ../source4/dsdb/common/util.c:4575) and from /var/lib/samba/private/secrets.tdb: NT_STATUS_CANT_ACCESS_DOMAIN_INFO 2017-01-10 01:36:08,628 ERROR(runtime): uncaught exception - (8460, "Failed to process 'chunk' of DRS replicated objects: WERR_DS_DRA_MISSING_PARENT") 2017-01-10 01:36:08,629 File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py", line 176, in _run 2017-01-10 01:36:08,642 return self.run(*args, **kwargs) 2017-01-10 01:36:08,643 File "/usr/lib/python2.7/dist-packages/samba/netcmd/domain.py", line 659, in run 2017-01-10 01:36:08,651 keep_existing=keep_existing) 2017-01-10 01:36:08,651 File "/usr/lib/python2.7/dist-packages/samba/join.py", line 1260, in join_DC 2017-01-10 01:36:08,652 ctx.do_join() 2017-01-10 01:36:08,653 File "/usr/lib/python2.7/dist-packages/samba/join.py", line 1160, in do_join 2017-01-10 01:36:08,653 ctx.join_replicate() 2017-01-10 01:36:08,653 File "/usr/lib/python2.7/dist-packages/samba/join.py", line 897, in join_replicate 2017-01-10 01:36:08,653 replica_flags=ctx.domain_replica_flags) 2017-01-10 01:36:08,653 File "/usr/lib/python2.7/dist-packages/samba/drs_utils.py", line 258, in replicate 2017-01-10 01:36:08,654 schema=schema, req_level=req_level, req=req) 2017-01-10 01:36:08,686 Adding CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:08,686 Adding CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:08,687 Adding CN=NTDS Settings,CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:08,687 Adding SPNs to CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:08,687 Setting account password for UCS$ 2017-01-10 01:36:08,687 Enabling account 2017-01-10 01:36:08,687 Calling bare provision 2017-01-10 01:36:08,687 Provision OK for domain DN DC=gr,DC=gc 2017-01-10 01:36:08,687 Starting replication 2017-01-10 01:36:08,687 Replicating critical objects from the base DN of the domain 2017-01-10 01:36:08,687 Join failed - cleaning up 2017-01-10 01:36:08,687 removing samaccount: CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:08,688 Deleted CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:08,688 Deleted CN=NTDS Settings,CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:08,688 Deleted CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:08,730 Calling: univention-config-registry unset hosts/static/192.168.200.2 2017-01-10 01:36:08,956 Unsetting hosts/static/192.168.200.2 2017-01-10 01:36:08,957 Multifile: /etc/hosts 2017-01-10 01:36:08,963 Calling: /etc/init.d/samba-ad-dc start 2017-01-10 01:36:09,462 Starting Samba AD DC daemon: samba. 2017-01-10 01:36:09,462 Calling: /etc/init.d/univention-s4-connector start 2017-01-10 01:36:09,511 Starting univention-s4-connector daemon. 2017-01-10 01:36:13,100 done. 2017-01-10 01:36:13,100 Calling: univention-config-registry set nameserver1=192.168.200.2 2017-01-10 01:36:13,282 Setting nameserver1 2017-01-10 01:36:13,282 File: /etc/resolv.conf 2017-01-10 01:36:13,288 Calling: univention-config-registry unset nameserver1/local 2017-01-10 01:36:13,460 Unsetting nameserver1/local 2017-01-10 01:36:13,460 File: /etc/resolv.conf 2017-01-10 01:36:13,461 Calling: univention-config-registry set dns/backend=samba4 2017-01-10 01:36:13,596 Setting dns/backend 2017-01-10 01:36:13,596 Calling: /etc/init.d/bind9 restart 2017-01-10 01:36:24,431 Restarting bind9 daemon: ...done. 2017-01-10 01:36:24,432 Calling: /etc/init.d/nscd restart 2017-01-10 01:36:24,495 Restarting Name Service Cache Daemon: nscd. 2017-01-10 01:36:24,496 Der Domänenbeitritt schlug fehl, die Logdatei /var/log/univention/ad-takeover.log enthält genauere Details. 2017-01-10 01:36:40,963 Found account Administrator with well known RID 500 (Administrator) 2017-01-10 01:36:40,965 Found account krbtgt with well known RID 502 (KRBTGT) 2017-01-10 01:36:40,965 Found account Guest with well known RID 501 (Guest) 2017-01-10 01:36:40,983 Found group Allowed RODC Password Replication Group with well known RID 571 (Allowed RODC Password Replication Group) 2017-01-10 01:36:40,983 Found group Enterprise Read-Only Domain Controllers with well known RID 498 (Enterprise Read-only Domain Controllers) 2017-01-10 01:36:40,983 Found group Denied RODC Password Replication Group with well known RID 572 (Denied RODC Password Replication Group) 2017-01-10 01:36:40,983 Found group Read-Only Domain Controllers with well known RID 521 (Read-Only Domain Controllers) 2017-01-10 01:36:40,984 Found group Group Policy Creator Owners with well known RID 520 (Group Policy Creator Owners) 2017-01-10 01:36:40,984 Found group RAS and IAS Servers with well known RID 553 (RAS and IAS Servers) 2017-01-10 01:36:40,984 Found group Domain Controllers with well known RID 516 (Domain Controllers) 2017-01-10 01:36:40,984 Found group Enterprise Admins with well known RID 519 (Enterprise Admins) 2017-01-10 01:36:40,984 Found group Domain Computers with well known RID 515 (Domain Computers) 2017-01-10 01:36:40,984 Found group Cert Publishers with well known RID 517 (Cert Publishers) 2017-01-10 01:36:40,984 Found group Domain Admins with well known RID 512 (Domain Admins) 2017-01-10 01:36:40,984 Found group Domain Guests with well known RID 514 (Domain Guests) 2017-01-10 01:36:40,984 Found group Schema Admins with well known RID 518 (Schema Admins) 2017-01-10 01:36:40,985 Found group Domain Users with well known RID 513 (Domain Users) 2017-01-10 01:36:41,104 determine_license for current UCS Users: 0 of unlimited 2017-01-10 01:36:41,104 2 Systemaccounts are ignored. 2017-01-10 01:36:41,105 Found 393 Benutzer objects on the remote server. 2017-01-10 01:36:42,442 INFO: Time difference is less than 180 seconds, skipping reset of local time 2017-01-10 01:36:42,479 Starting phase I of the takeover process. 2017-01-10 01:36:42,479 Calling: univention-config-registry set hosts/static/192.168.200.2=zentyal.gr.gc ZENTYAL 2017-01-10 01:36:42,740 Create hosts/static/192.168.200.2 2017-01-10 01:36:42,741 Multifile: /etc/hosts 2017-01-10 01:36:42,741 Calling: /etc/init.d/univention-s4-connector stop 2017-01-10 01:36:42,753 Stopping univention-s4-connector daemon. 2017-01-10 01:36:42,774 done. 2017-01-10 01:36:42,775 Calling: /etc/init.d/samba-ad-dc stop 2017-01-10 01:36:42,992 Stopping Samba AD DC daemon: samba. 2017-01-10 01:36:43,004 Calling: /etc/init.d/nscd stop 2017-01-10 01:36:43,032 Stopping Name Service Cache Daemon: nscd. 2017-01-10 01:36:43,033 Calling: /etc/init.d/bind9 restart 2017-01-10 01:36:48,453 Restarting bind9 daemon: ...done. 2017-01-10 01:36:48,454 Starting Samba domain join. 2017-01-10 01:36:48,731 SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS 2017-01-10 01:36:48,778 workgroup is GR 2017-01-10 01:36:48,778 realm is gr.gc 2017-01-10 01:36:48,858 SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS 2017-01-10 01:36:49,439 Looking up IPv4 addresses 2017-01-10 01:36:49,440 Looking up IPv6 addresses 2017-01-10 01:36:49,441 No IPv6 address will be assigned 2017-01-10 01:36:49,802 Setting up share.ldb 2017-01-10 01:36:49,822 Setting up secrets.ldb 2017-01-10 01:36:49,851 Setting up the registry 2017-01-10 01:36:49,904 Setting up the privileges database 2017-01-10 01:36:49,931 Setting up idmap db 2017-01-10 01:36:49,949 Setting up SAM db 2017-01-10 01:36:49,956 Setting up sam.ldb partitions and settings 2017-01-10 01:36:49,956 Setting up sam.ldb rootDSE 2017-01-10 01:36:49,959 Pre-loading the Samba 4 and AD schema 2017-01-10 01:36:49,988 A Kerberos configuration suitable for Samba 4 has been generated at /var/lib/samba/private/krb5.conf 2017-01-10 01:36:50,005 SPNEGO(gssapi_krb5) creating NEG_TOKEN_INIT failed: NT_STATUS_NO_LOGON_SERVERS 2017-01-10 01:36:50,450 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[402/1550] linked_values[0/0] 2017-01-10 01:36:50,745 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[804/1550] linked_values[0/0] 2017-01-10 01:36:51,017 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[1206/1550] linked_values[0/0] 2017-01-10 01:36:51,255 Schema-DN[CN=Schema,CN=Configuration,DC=gr,DC=gc] objects[1550/1550] linked_values[0/0] 2017-01-10 01:36:51,255 Analyze and apply schema objects 2017-01-10 01:36:53,709 Partition[CN=Configuration,DC=gr,DC=gc] objects[402/1635] linked_values[0/0] 2017-01-10 01:36:54,343 Partition[CN=Configuration,DC=gr,DC=gc] objects[804/1635] linked_values[0/0] 2017-01-10 01:36:54,976 Partition[CN=Configuration,DC=gr,DC=gc] objects[1206/1635] linked_values[0/0] 2017-01-10 01:36:55,620 Partition[CN=Configuration,DC=gr,DC=gc] objects[1608/1635] linked_values[0/0] 2017-01-10 01:36:56,069 Partition[CN=Configuration,DC=gr,DC=gc] objects[1635/1635] linked_values[50/0] 2017-01-10 01:36:56,361 Partition[DC=gr,DC=gc] objects[99/99] linked_values[35/0] 2017-01-10 01:36:56,483 Failed to commit objects: WERR_DS_DRA_MISSING_PARENT 2017-01-10 01:36:56,532 Could not find machine account in secrets database: Failed to fetch machine account password for GR from both secrets.ldb (Could not find entry to match filter: '(&(flatname=GR)(objectclass=primaryDomain))' base: 'cn=Primary Domains': No such object: dsdb_search at ../source4/dsdb/common/util.c:4575) and from /var/lib/samba/private/secrets.tdb: NT_STATUS_CANT_ACCESS_DOMAIN_INFO 2017-01-10 01:36:56,685 ERROR(runtime): uncaught exception - (8460, "Failed to process 'chunk' of DRS replicated objects: WERR_DS_DRA_MISSING_PARENT") 2017-01-10 01:36:56,686 File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py", line 176, in _run 2017-01-10 01:36:56,686 return self.run(*args, **kwargs) 2017-01-10 01:36:56,686 File "/usr/lib/python2.7/dist-packages/samba/netcmd/domain.py", line 659, in run 2017-01-10 01:36:56,688 keep_existing=keep_existing) 2017-01-10 01:36:56,689 File "/usr/lib/python2.7/dist-packages/samba/join.py", line 1260, in join_DC 2017-01-10 01:36:56,689 ctx.do_join() 2017-01-10 01:36:56,689 File "/usr/lib/python2.7/dist-packages/samba/join.py", line 1160, in do_join 2017-01-10 01:36:56,689 ctx.join_replicate() 2017-01-10 01:36:56,689 File "/usr/lib/python2.7/dist-packages/samba/join.py", line 897, in join_replicate 2017-01-10 01:36:56,690 replica_flags=ctx.domain_replica_flags) 2017-01-10 01:36:56,690 File "/usr/lib/python2.7/dist-packages/samba/drs_utils.py", line 258, in replicate 2017-01-10 01:36:56,690 schema=schema, req_level=req_level, req=req) 2017-01-10 01:36:56,721 Adding CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:56,722 Adding CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:56,722 Adding CN=NTDS Settings,CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:56,722 Adding SPNs to CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:56,722 Setting account password for UCS$ 2017-01-10 01:36:56,722 Enabling account 2017-01-10 01:36:56,722 Calling bare provision 2017-01-10 01:36:56,722 Provision OK for domain DN DC=gr,DC=gc 2017-01-10 01:36:56,722 Starting replication 2017-01-10 01:36:56,723 Replicating critical objects from the base DN of the domain 2017-01-10 01:36:56,723 Join failed - cleaning up 2017-01-10 01:36:56,723 removing samaccount: CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:56,723 Deleted CN=UCS,OU=Domain Controllers,DC=gr,DC=gc 2017-01-10 01:36:56,723 Deleted CN=NTDS Settings,CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:56,723 Deleted CN=UCS,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=gr,DC=gc 2017-01-10 01:36:56,764 Calling: univention-config-registry unset hosts/static/192.168.200.2 2017-01-10 01:36:56,981 Unsetting hosts/static/192.168.200.2 2017-01-10 01:36:56,981 Multifile: /etc/hosts 2017-01-10 01:36:56,989 Calling: /etc/init.d/samba-ad-dc start 2017-01-10 01:36:57,489 Starting Samba AD DC daemon: samba. 2017-01-10 01:36:57,489 Calling: /etc/init.d/univention-s4-connector start 2017-01-10 01:36:57,536 Starting univention-s4-connector daemon. 2017-01-10 01:37:01,019 done. 2017-01-10 01:37:01,019 Warning: Weird, unable to determine previous nameserver1... Using localhost as fallback, probably that's the right thing to do. 2017-01-10 01:37:01,019 Calling: univention-config-registry set nameserver1=127.0.0.1 2017-01-10 01:37:01,195 Setting nameserver1 2017-01-10 01:37:01,196 File: /etc/resolv.conf 2017-01-10 01:37:01,197 Calling: univention-config-registry set dns/backend=samba4 2017-01-10 01:37:01,331 Setting dns/backend 2017-01-10 01:37:01,332 Calling: /etc/init.d/bind9 restart 2017-01-10 01:37:03,817 Restarting bind9 daemon: ...done. 2017-01-10 01:37:03,817 Calling: /etc/init.d/nscd restart 2017-01-10 01:37:03,876 Restarting Name Service Cache Daemon: nscd. 2017-01-10 01:37:03,876 Der Domänenbeitritt schlug fehl, die Logdatei /var/log/univention/ad-takeover.log enthält genauere Details.