Re: replication broken, can't contact local ldap server on one dc
Rowland Penny via samba <[email protected]> Thu, 2 Apr 2026 09:46:06 +0100
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 27 Mar 2026 13:31:52 +0100 Thorsten Marquardt via samba <[email protected]> wrote: > > Am 27.03.26 um 12:39 schrieb Rowland Penny via samba: > > On Fri, 27 Mar 2026 11:59:12 +0100 > > Thorsten Marquardt via samba <[email protected]> wrote: > > > >> Hi, > >> > >> I use a samba domain (4.22.6-Debian-4.22.6+dfsg-0+deb13u1) with two > >> dc's (srv-kb-dc1 and srv-kb-dc2) and have trouble with drs > >> replication: > >> > >> root@srv-kb-dc1:/usr/local/share/ca-certificates# samba-tool drs > >> uptodateness > >> DOMAIN maximum: 0 median: 0.0 failure: 0 > >> CONFIGURATION maximum: 0 median: 0.0 failure: 0 > >> SCHEMA maximum: 0 median: 0.0 failure: 0 > >> DNSDOMAIN maximum: 0 median: 0.0 failure: 0 > >> DNSFOREST maximum: 0 median: 0.0 failure: 0 > >> > >> samba-tool drs uptodateness > >> Failed to connect to ldap URL 'ldap://srv-kb-dc2.local' - LDAP > >> client internal error: NT_STATUS_CONNECTION_REFUSED > >> Failed to connect to 'ldap://srv-kb-dc2.local' with backend 'ldap': > >> LDAP client internal error: NT_STATUS_CONNECTION_REFUSED > >> [...] > >> missing dn > >> CN=SRV-KB-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local > >> from UTD vector list > >> DOMAIN maximum: -231585 median: -231585.0 failure: 1 > >> CONFIGURATION maximum: -231585 median: -231585.0 failure: 1 > >> SCHEMA maximum: -231585 median: -231585.0 failure: 1 > >> DNSDOMAIN maximum: -231585 median: -231585.0 failure: 1 > >> DNSFOREST maximum: -231585 median: -231585.0 failure: 1 > >> > >> I can ldapsearch both host from srv-kb-dc1 and any other host but > >> srv-kb-dc2 > >> > >> From srv-kb-l02 ldapsearch fails with: > >> > >> root@srv-kb-dc2:ldapsearch -H ldap://srv-kb-dc2.local -b > >> dc=domain,dc=local -D > >> "cn=administrator,cn=users,dc=domain,dc=local=de" -W -Z > >> ldap_start_tls: Can't contact LDAP server (-1) > >> > >> Thanks > >> > >> Thorsten > >> > > Have you tried running 'samba-tool dbcheck' on srv-kb-dc2 ? > > > > Also 'cn=administrator,cn=users,dc=domain,dc=local=de' is wrong , a > > typo ? > > > > Rowland > > > yes i did: > > root@srv-kb-dc2:~# samba-tool dbcheck > Checking 379 objects > Checked 379 objects (0 errors) > > and: > > root@srv-kb-dc1:~# samba-tool dbcheck > Checking 379 objects > Checked 379 objects (0 errors) > > > and yes the bind dn was a typo within the mail. > Currently I don't see any issues other the drs ones. > I suggest you try a forced replication from the good DC to the other DC. Rowland -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba