Re: replication broken, can't contact local ldap server on one dc

Rowland Penny via samba <[email protected]> Thu, 2 Apr 2026 09:46:06 +0100
Newsgroups gmane.network.samba.general
Message-ID <[email protected]>
On Fri, 27 Mar 2026 13:31:52 +0100
Thorsten Marquardt via samba <[email protected]> wrote:

> 
> Am 27.03.26 um 12:39 schrieb Rowland Penny via samba:
> > On Fri, 27 Mar 2026 11:59:12 +0100
> > Thorsten Marquardt via samba <[email protected]> wrote:
> >
> >> Hi,
> >>
> >> I use a samba domain (4.22.6-Debian-4.22.6+dfsg-0+deb13u1) with two
> >> dc's (srv-kb-dc1 and srv-kb-dc2) and have trouble with drs
> >> replication:
> >>
> >> root@srv-kb-dc1:/usr/local/share/ca-certificates# samba-tool drs
> >> uptodateness
> >> DOMAIN          maximum: 0  median: 0.0  failure: 0
> >> CONFIGURATION   maximum: 0  median: 0.0  failure: 0
> >> SCHEMA          maximum: 0  median: 0.0  failure: 0
> >> DNSDOMAIN       maximum: 0  median: 0.0  failure: 0
> >> DNSFOREST       maximum: 0  median: 0.0  failure: 0
> >>
> >> samba-tool drs uptodateness
> >> Failed to connect to ldap URL 'ldap://srv-kb-dc2.local' - LDAP
> >> client internal error: NT_STATUS_CONNECTION_REFUSED
> >> Failed to connect to 'ldap://srv-kb-dc2.local' with backend 'ldap':
> >> LDAP client internal error: NT_STATUS_CONNECTION_REFUSED
> >> [...]
> >> missing dn
> >> CN=SRV-KB-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
> >> from UTD vector list
> >> DOMAIN          maximum: -231585  median: -231585.0  failure: 1
> >> CONFIGURATION   maximum: -231585  median: -231585.0  failure: 1
> >> SCHEMA          maximum: -231585  median: -231585.0  failure: 1
> >> DNSDOMAIN       maximum: -231585  median: -231585.0  failure: 1
> >> DNSFOREST       maximum: -231585  median: -231585.0  failure: 1
> >>
> >> I can ldapsearch both host from srv-kb-dc1 and any other host but
> >> srv-kb-dc2
> >>
> >>   From srv-kb-l02 ldapsearch fails with:
> >>
> >> root@srv-kb-dc2:ldapsearch -H ldap://srv-kb-dc2.local  -b
> >> dc=domain,dc=local -D
> >> "cn=administrator,cn=users,dc=domain,dc=local=de" -W -Z
> >> ldap_start_tls: Can't contact LDAP server (-1)
> >>
> >> Thanks
> >>
> >> Thorsten
> >>
> > Have you tried running 'samba-tool dbcheck' on srv-kb-dc2 ?
> >
> > Also 'cn=administrator,cn=users,dc=domain,dc=local=de' is wrong , a
> > typo ?
> >
> > Rowland
> >
> yes i did:
> 
> root@srv-kb-dc2:~# samba-tool dbcheck
> Checking 379 objects
> Checked 379 objects (0 errors)
> 
> and:
> 
> root@srv-kb-dc1:~# samba-tool dbcheck
> Checking 379 objects
> Checked 379 objects (0 errors)
> 
> 
> and yes the bind dn was a typo within the mail.
> Currently I don't see any issues other the drs ones.
> 

I suggest you try a forced replication from the good DC to the other DC.

Rowland



-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba