Re: replication broken, can't contact local ldap server on one dc

Thorsten Marquardt via samba <[email protected]> Tue, 14 Apr 2026 12:25:09 +0200
Newsgroups gmane.network.samba.general
Message-ID <[email protected]>
Am 02.04.26 um 10:46 schrieb Rowland Penny via samba:
> On Fri, 27 Mar 2026 13:31:52 +0100
> Thorsten Marquardt via samba <[email protected]> wrote:
>
>> Am 27.03.26 um 12:39 schrieb Rowland Penny via samba:
>>> On Fri, 27 Mar 2026 11:59:12 +0100
>>> Thorsten Marquardt via samba <[email protected]> wrote:
>>>
>>>> Hi,
>>>>
>>>> I use a samba domain (4.22.6-Debian-4.22.6+dfsg-0+deb13u1) with two
>>>> dc's (srv-kb-dc1 and srv-kb-dc2) and have trouble with drs
>>>> replication:
>>>>
>>>> root@srv-kb-dc1:/usr/local/share/ca-certificates# samba-tool drs
>>>> uptodateness
>>>> DOMAIN          maximum: 0  median: 0.0  failure: 0
>>>> CONFIGURATION   maximum: 0  median: 0.0  failure: 0
>>>> SCHEMA          maximum: 0  median: 0.0  failure: 0
>>>> DNSDOMAIN       maximum: 0  median: 0.0  failure: 0
>>>> DNSFOREST       maximum: 0  median: 0.0  failure: 0
>>>>
>>>> samba-tool drs uptodateness
>>>> Failed to connect to ldap URL 'ldap://srv-kb-dc2.local' - LDAP
>>>> client internal error: NT_STATUS_CONNECTION_REFUSED
>>>> Failed to connect to 'ldap://srv-kb-dc2.local' with backend 'ldap':
>>>> LDAP client internal error: NT_STATUS_CONNECTION_REFUSED
>>>> [...]
>>>> missing dn
>>>> CN=SRV-KB-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
>>>> from UTD vector list
>>>> DOMAIN          maximum: -231585  median: -231585.0  failure: 1
>>>> CONFIGURATION   maximum: -231585  median: -231585.0  failure: 1
>>>> SCHEMA          maximum: -231585  median: -231585.0  failure: 1
>>>> DNSDOMAIN       maximum: -231585  median: -231585.0  failure: 1
>>>> DNSFOREST       maximum: -231585  median: -231585.0  failure: 1
>>>>
>>>> I can ldapsearch both host from srv-kb-dc1 and any other host but
>>>> srv-kb-dc2
>>>>
>>>>    From srv-kb-l02 ldapsearch fails with:
>>>>
>>>> root@srv-kb-dc2:ldapsearch -H ldap://srv-kb-dc2.local  -b
>>>> dc=domain,dc=local -D
>>>> "cn=administrator,cn=users,dc=domain,dc=local=de" -W -Z
>>>> ldap_start_tls: Can't contact LDAP server (-1)
>>>>
>>>> Thanks
>>>>
>>>> Thorsten
>>>>
>>> Have you tried running 'samba-tool dbcheck' on srv-kb-dc2 ?
>>>
>>> Also 'cn=administrator,cn=users,dc=domain,dc=local=de' is wrong , a
>>> typo ?
>>>
>>> Rowland
>>>
>> yes i did:
>>
>> root@srv-kb-dc2:~# samba-tool dbcheck
>> Checking 379 objects
>> Checked 379 objects (0 errors)
>>
>> and:
>>
>> root@srv-kb-dc1:~# samba-tool dbcheck
>> Checking 379 objects
>> Checked 379 objects (0 errors)
>>
>>
>> and yes the bind dn was a typo within the mail.
>> Currently I don't see any issues other the drs ones.
>>
> I suggest you try a forced replication from the good DC to the other DC.
>
> Rowland
>
>
>
I'm sorry for the late response, but it took some time to find the 
error. Both the hosts are configured to fixed IP4 and IP6 addresses. 
After the latest system upgrade on one of the hosts (srv-kb-dc1) there 
is a /etc/hosts
with both the local IP4 and IP6 address pointing to  correct lan 
address. On the other (srv-kb-dc2) these entries where pointing to the 
loopback address.

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba