Re: replication broken, can't contact local ldap server on one dc
Thorsten Marquardt via samba <[email protected]> Tue, 14 Apr 2026 12:25:09 +0200
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <[email protected]> |
Am 02.04.26 um 10:46 schrieb Rowland Penny via samba: > On Fri, 27 Mar 2026 13:31:52 +0100 > Thorsten Marquardt via samba <[email protected]> wrote: > >> Am 27.03.26 um 12:39 schrieb Rowland Penny via samba: >>> On Fri, 27 Mar 2026 11:59:12 +0100 >>> Thorsten Marquardt via samba <[email protected]> wrote: >>> >>>> Hi, >>>> >>>> I use a samba domain (4.22.6-Debian-4.22.6+dfsg-0+deb13u1) with two >>>> dc's (srv-kb-dc1 and srv-kb-dc2) and have trouble with drs >>>> replication: >>>> >>>> root@srv-kb-dc1:/usr/local/share/ca-certificates# samba-tool drs >>>> uptodateness >>>> DOMAIN maximum: 0 median: 0.0 failure: 0 >>>> CONFIGURATION maximum: 0 median: 0.0 failure: 0 >>>> SCHEMA maximum: 0 median: 0.0 failure: 0 >>>> DNSDOMAIN maximum: 0 median: 0.0 failure: 0 >>>> DNSFOREST maximum: 0 median: 0.0 failure: 0 >>>> >>>> samba-tool drs uptodateness >>>> Failed to connect to ldap URL 'ldap://srv-kb-dc2.local' - LDAP >>>> client internal error: NT_STATUS_CONNECTION_REFUSED >>>> Failed to connect to 'ldap://srv-kb-dc2.local' with backend 'ldap': >>>> LDAP client internal error: NT_STATUS_CONNECTION_REFUSED >>>> [...] >>>> missing dn >>>> CN=SRV-KB-DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local >>>> from UTD vector list >>>> DOMAIN maximum: -231585 median: -231585.0 failure: 1 >>>> CONFIGURATION maximum: -231585 median: -231585.0 failure: 1 >>>> SCHEMA maximum: -231585 median: -231585.0 failure: 1 >>>> DNSDOMAIN maximum: -231585 median: -231585.0 failure: 1 >>>> DNSFOREST maximum: -231585 median: -231585.0 failure: 1 >>>> >>>> I can ldapsearch both host from srv-kb-dc1 and any other host but >>>> srv-kb-dc2 >>>> >>>> From srv-kb-l02 ldapsearch fails with: >>>> >>>> root@srv-kb-dc2:ldapsearch -H ldap://srv-kb-dc2.local -b >>>> dc=domain,dc=local -D >>>> "cn=administrator,cn=users,dc=domain,dc=local=de" -W -Z >>>> ldap_start_tls: Can't contact LDAP server (-1) >>>> >>>> Thanks >>>> >>>> Thorsten >>>> >>> Have you tried running 'samba-tool dbcheck' on srv-kb-dc2 ? >>> >>> Also 'cn=administrator,cn=users,dc=domain,dc=local=de' is wrong , a >>> typo ? >>> >>> Rowland >>> >> yes i did: >> >> root@srv-kb-dc2:~# samba-tool dbcheck >> Checking 379 objects >> Checked 379 objects (0 errors) >> >> and: >> >> root@srv-kb-dc1:~# samba-tool dbcheck >> Checking 379 objects >> Checked 379 objects (0 errors) >> >> >> and yes the bind dn was a typo within the mail. >> Currently I don't see any issues other the drs ones. >> > I suggest you try a forced replication from the good DC to the other DC. > > Rowland > > > I'm sorry for the late response, but it took some time to find the error. Both the hosts are configured to fixed IP4 and IP6 addresses. After the latest system upgrade on one of the hosts (srv-kb-dc1) there is a /etc/hosts with both the local IP4 and IP6 address pointing to correct lan address. On the other (srv-kb-dc2) these entries where pointing to the loopback address. -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba