Univention Bugzilla – Bug 57111
S4connector cannot handle subdomains and produces ._msdcs rejects
Last modified: 2024-04-16 11:34:55 CEST
Created attachment 11196 [details] connector-s4.log Environment: Primary and replica with UCS 5.0-6 and samba4 installed. The domain of the primary is: example.com. The domain of the replica is: subdomain.example.com. Steps to reproduce: - Create a DNS zone subdomain.example.com - Join the replica with: univention-join -dcname primary.example.com - Join fails because of 92univention-management-console-web-server.inst --> ucr set umc/saml/idp-server='https://ucs-sso.example.com/simplesamlphp/saml2/idp/metadata.php' - univention-run-join-scripts This results in the following rejects after the join: UCS rejected 1: UCS DN: relativeDomainName=0eaabe28-c68a-42d0-839c-d15bf59937c6._msdcs,zoneName=subdomain.samba-test.intranet,cn=dns,dc=samba-test,dc=intranet S4 DN: <not found> Filename: /var/lib/univention-connector/s4/1709568265.483867 2: UCS DN: relativeDomainName=_ldap._tcp.dc._msdcs,zoneName=subdomain.samba-test.intranet,cn=dns,dc=samba-test,dc=intranet S4 DN: <not found> Filename: /var/lib/univention-connector/s4/1709568267.768083 3: UCS DN: relativeDomainName=_ldap._tcp.09caae8e-984b-407b-88d3-d5a356adc368.domains._msdcs,zoneName=subdomain.samba-test.intranet,cn=dns,dc=samba-test,dc=intranet S4 DN: <not found> Filename: /var/lib/univention-connector/s4/1709568268.774607 4: UCS DN: relativeDomainName=_kerberos._tcp.dc._msdcs,zoneName=subdomain.samba-test.intranet,cn=dns,dc=samba-test,dc=intranet S4 DN: <not found> Filename: /var/lib/univention-connector/s4/1709568271.812686 5: UCS DN: relativeDomainName=_ldap._tcp.Default-First-Site-Name._sites.dc._msdcs,zoneName=subdomain.samba-test.intranet,cn=dns,dc=samba-test,dc=intranet S4 DN: <not found> Filename: /var/lib/univention-connector/s4/1709568275.308666 6: UCS DN: relativeDomainName=_kerberos._tcp.Default-First-Site-Name._sites.dc._msdcs,zoneName=subdomain.samba-test.intranet,cn=dns,dc=samba-test,dc=intranet S4 DN: <not found> Filename: /var/lib/univention-connector/s4/1709568277.308242
Created attachment 11197 [details] check_essential_samba4_dns_records from primary
Created attachment 11198 [details] check_essential_samba4_dns_records from replica
> The domain of the primary is: example.com. > The domain of the replica is: subdomain.example.com. This is out of scope of the UCS domain concept. A replica has to be in the same domain as the primary.
(In reply to Arvid Requate from comment #3) > > The domain of the primary is: example.com. > > The domain of the replica is: subdomain.example.com. > > This is out of scope of the UCS domain concept. A replica has to be in the > same domain as the primary. So do we have that in the documentation, that this is not in the domain concept? We have not found it. And if this is neither documented, nor allowed to do that, we should prevent this. I also think, that we should point that out, that we do not support that. In a windows AD, it is possible and allowed, to join a subdomain.
> In a windows AD, it is possible and allowed, to join a subdomain. In MS that's done by creating a forest (of two domains and a trust config etc between them). We can make a statement in the documentation about things like these (product is not suitable to do XYZ) but that list may grow a lot and it's unclear if people would have seen it before trying. I'll discuss with some documentation specialist about it.