Univention Bugzilla – Bug 54041
Connector stops working after joining in an AD forest domain
Last modified: 2023-11-02 17:48:05 CET
As we tested in Bug 53944, the problem in UCS 4.4-8 is quite similar, but the problem occurs after the join to an AD Forest Domain. The connector is not starting anymore: Tue Nov 9 12:17:47 2021 Failed to lookup attribute Schema from AD: {'info': "0000208D: NameErr: DSID-03100241, problem 2001 (NO_OBJECT), data 0, best match of:\n\t'DC=beam,DC=example,DC=org'\n", 'matched': 'DC=beam,DC=example,DC=org', 'desc': 'No such object'} In the testenvironment the namingContext is now ## Subdomain: root@primary20:~# ldbsearch -H ldap://10.200.43.118 -b '' \ -U Administrator%Univention.1 -s base namingContexts # record 1 dn: namingContexts: CN=Configuration,DC=example,DC=org namingContexts: CN=Schema,CN=Configuration,DC=example,DC=org namingContexts: DC=ForestDnsZones,DC=example,DC=org namingContexts: DC=subdomain,DC=example,DC=org namingContexts: DC=DomainDnsZones,DC=beam,DC=example,DC=org ## vs forest root: root@primary20:~# ldbsearch -H ldap://10.200.43.114 -b '' \ -U Administrator%Univention.1 -s base namingContexts # record 1 dn: namingContexts: DC=example,DC=org namingContexts: CN=Configuration,DC=example,DC=org namingContexts: CN=Schema,CN=Configuration,DC=example,DC=org namingContexts: DC=DomainDnsZones,DC=example,DC=org namingContexts: DC=ForestDnsZones,DC=example,DC=org --------------- I guess the connector does the following: ldbsearch -H ldap://10.200.43.118 -b 'CN=Schema,CN=Configuration,DC=beam,DC=example,DC=org' -U Administrator%Univention.1 search error - LDAP error 32 LDAP_NO_SUCH_OBJECT - DC=beam,DC=example,DC=org <0000208D: NameErr: DSID-03100241, problem 2001 (NO_OBJECT), data 0, best match of: 'DC=beam,DC=example,DC=org' instead of ldbsearch -H ldap://10.200.43.118 -b 'CN=Schema,CN=Configuration,DC=example,DC=org' -U Administrator%Univention.1 which works.
As far as I understand this, when it comes to UCS 5.0-x this should be fixed with the change for Bug 53944. *** This bug has been marked as a duplicate of bug 53944 ***