<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=2_DC_mit_Replicatiom</id>
	<title>2 DC mit Replicatiom - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=2_DC_mit_Replicatiom"/>
	<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=2_DC_mit_Replicatiom&amp;action=history"/>
	<updated>2026-06-29T01:16:11Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=2_DC_mit_Replicatiom&amp;diff=11744&amp;oldid=prev</id>
		<title>Thomas: Die Seite wurde neu angelegt: „=Zwei DC mit Replikation einrichten= ==Situation==   '''Existierender DC'''  Name: rumba  IP: 192.168.242.201  Ist DNS: Ja  '''Domain Informationen'''  DNS Dom…“</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=2_DC_mit_Replicatiom&amp;diff=11744&amp;oldid=prev"/>
		<updated>2016-12-13T10:59:40Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „=Zwei DC mit Replikation einrichten= ==Situation==   &amp;#039;&amp;#039;&amp;#039;Existierender DC&amp;#039;&amp;#039;&amp;#039;  Name: rumba  IP: 192.168.242.201  Ist DNS: Ja  &amp;#039;&amp;#039;&amp;#039;Domain Informationen&amp;#039;&amp;#039;&amp;#039;  DNS Dom…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Zwei DC mit Replikation einrichten=&lt;br /&gt;
==Situation==&lt;br /&gt;
&lt;br /&gt;
 '''Existierender DC'''&lt;br /&gt;
 Name: rumba&lt;br /&gt;
 IP: 192.168.242.201&lt;br /&gt;
 Ist DNS: Ja&lt;br /&gt;
 '''Domain Informationen'''&lt;br /&gt;
 DNS Domain Name: xinux.test&lt;br /&gt;
 Kerberos realm: XINUX.TEST&lt;br /&gt;
 Domain Admin: administrator&lt;br /&gt;
 Admin-PW: password&lt;br /&gt;
 '''Hinzuzufügender DC'''&lt;br /&gt;
 Name: tango&lt;br /&gt;
 IP: 192.168.242.200&lt;br /&gt;
&lt;br /&gt;
==Vorbereitungen==&lt;br /&gt;
&lt;br /&gt;
*Beide Rechner sollten im selben Netz sein und sich pingen können&lt;br /&gt;
*etc/hosts anpassen: Der Rechner muss sich unter seiner IP finden, bei localhost den Namen löschen&lt;br /&gt;
 127.0.0.1   localhost   &amp;lt;strike&amp;gt;tango tango.xinux.test&amp;lt;/strike&amp;gt;&lt;br /&gt;
 192.168.242.200   tango tango.xinux.test&lt;br /&gt;
*DNS anpassen: searchdomain eintragen und den existierenden DC als DNS angeben&lt;br /&gt;
 nameserver 192.168.242.201&lt;br /&gt;
 search xinux.test&lt;br /&gt;
*DNS testen:&lt;br /&gt;
 host -t A rumba.xinux.test&lt;br /&gt;
 rumba.xinux.test has address 192.168.242.201&lt;br /&gt;
&lt;br /&gt;
==Kerberos==&lt;br /&gt;
&lt;br /&gt;
In der krb5.conf müssen folgende Einträge stehen:&lt;br /&gt;
 [libdefaults]&lt;br /&gt;
    dns_lookup_realm = false&lt;br /&gt;
    dns_lookup_kdc = true&lt;br /&gt;
    default_realm = XINUX.TEST&lt;br /&gt;
&lt;br /&gt;
Testen ob man ein Kerberosticket bekommt&lt;br /&gt;
 root@tango:~# '''kinit administrator'''&lt;br /&gt;
 Password for administrator@XINUX.TEST: &lt;br /&gt;
 &lt;br /&gt;
 root@tango:~# '''klist'''&lt;br /&gt;
 Ticket cache: FILE:/tmp/krb5cc_0&lt;br /&gt;
 Default principal: administrator@XINUX.TEST&lt;br /&gt;
 &lt;br /&gt;
 Valid starting       Expires              Service principal&lt;br /&gt;
 10.09.2015 11:08:57  10.09.2015 21:08:57  krbtgt/XINUX.TEST@XINUX.TEST&lt;br /&gt;
	 renew until 11.09.2015 11:08:44&lt;br /&gt;
==Der Domain beitreten==&lt;br /&gt;
*'''ACHTUNG''' Für das Administrator-Passwort gelten die Standardrichtlinien von SAMBA4!&lt;br /&gt;
*Weiterführende Infos: samba-tool domain join --help&lt;br /&gt;
&lt;br /&gt;
 root@tango:~# samba-tool domain join XINUX.TEST DC -Uadministrator --realm=XINUX.TEST --dns-backend=SAMBA_INTERNAL&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ausgabe:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Finding a writeable DC for domain 'XINUX.TEST'&lt;br /&gt;
Found DC rumba.xinux.test&lt;br /&gt;
Password for [WORKGROUP\administrator]:&lt;br /&gt;
workgroup is XINUX&lt;br /&gt;
realm is xinux.test&lt;br /&gt;
checking sAMAccountName&lt;br /&gt;
Adding CN=TANGO,OU=Domain Controllers,DC=xinux,DC=test&lt;br /&gt;
Adding CN=TANGO,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
Adding CN=NTDS Settings,CN=TANGO,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
Adding SPNs to CN=TANGO,OU=Domain Controllers,DC=xinux,DC=test&lt;br /&gt;
Setting account password for TANGO$&lt;br /&gt;
Enabling account&lt;br /&gt;
Calling bare provision&lt;br /&gt;
No IPv6 address will be assigned&lt;br /&gt;
Provision OK for domain DN DC=xinux,DC=test&lt;br /&gt;
Starting replication&lt;br /&gt;
Schema-DN[CN=Schema,CN=Configuration,DC=xinux,DC=test] objects[402/1550] linked_values[0/0]&lt;br /&gt;
Schema-DN[CN=Schema,CN=Configuration,DC=xinux,DC=test] objects[804/1550] linked_values[0/0]&lt;br /&gt;
Schema-DN[CN=Schema,CN=Configuration,DC=xinux,DC=test] objects[1206/1550] linked_values[0/0]&lt;br /&gt;
Schema-DN[CN=Schema,CN=Configuration,DC=xinux,DC=test] objects[1550/1550] linked_values[0/0]&lt;br /&gt;
Analyze and apply schema objects&lt;br /&gt;
Partition[CN=Configuration,DC=xinux,DC=test] objects[402/1616] linked_values[0/0]&lt;br /&gt;
Partition[CN=Configuration,DC=xinux,DC=test] objects[804/1616] linked_values[0/0]&lt;br /&gt;
Partition[CN=Configuration,DC=xinux,DC=test] objects[1206/1616] linked_values[0/0]&lt;br /&gt;
Partition[CN=Configuration,DC=xinux,DC=test] objects[1608/1616] linked_values[0/0]&lt;br /&gt;
Partition[CN=Configuration,DC=xinux,DC=test] objects[1616/1616] linked_values[28/0]&lt;br /&gt;
Replicating critical objects from the base DN of the domain&lt;br /&gt;
Partition[DC=xinux,DC=test] objects[97/97] linked_values[23/0]&lt;br /&gt;
Partition[DC=xinux,DC=test] objects[365/268] linked_values[23/0]&lt;br /&gt;
Done with always replicated NC (base, config, schema)&lt;br /&gt;
Replicating DC=DomainDnsZones,DC=xinux,DC=test&lt;br /&gt;
Partition[DC=DomainDnsZones,DC=xinux,DC=test] objects[46/46] linked_values[0/0]&lt;br /&gt;
Replicating DC=ForestDnsZones,DC=xinux,DC=test&lt;br /&gt;
Partition[DC=ForestDnsZones,DC=xinux,DC=test] objects[18/18] linked_values[0/0]&lt;br /&gt;
Partition[DC=ForestDnsZones,DC=xinux,DC=test] objects[36/18] linked_values[0/0]&lt;br /&gt;
Committing SAM database&lt;br /&gt;
Sending DsReplicateUpdateRefs for all the replicated partitions&lt;br /&gt;
Setting isSynchronized and dsServiceName&lt;br /&gt;
Setting up secrets database&lt;br /&gt;
Joined domain XINUX (SID S-1-5-21-3964088599-1372953937-1397556401) as a DC&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Anzeige der Replikation==&lt;br /&gt;
DC1:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@rumba:~# samba-tool drs showrepl&lt;br /&gt;
&lt;br /&gt;
Default-First-Site-Name\RUMBA&lt;br /&gt;
DSA Options: 0x00000001&lt;br /&gt;
DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
DSA invocationId: fc6eaa8e-a1cf-4af8-b919-f0af6abddb27&lt;br /&gt;
&lt;br /&gt;
==== INBOUND NEIGHBORS ====&lt;br /&gt;
&lt;br /&gt;
DC=DomainDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:30:34 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:30:34 2015 CEST&lt;br /&gt;
&lt;br /&gt;
DC=ForestDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:30:34 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:30:34 2015 CEST&lt;br /&gt;
&lt;br /&gt;
DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:30:59 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:30:59 2015 CEST&lt;br /&gt;
&lt;br /&gt;
CN=Schema,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:30:34 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:30:34 2015 CEST&lt;br /&gt;
&lt;br /&gt;
CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:30:35 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:30:35 2015 CEST&lt;br /&gt;
&lt;br /&gt;
==== OUTBOUND NEIGHBORS ====&lt;br /&gt;
&lt;br /&gt;
DC=DomainDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
DC=ForestDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
CN=Schema,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\TANGO via RPC&lt;br /&gt;
		DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
==== KCC CONNECTION OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
Connection --&lt;br /&gt;
	Connection name: f31d9725-b1a6-4450-93d4-8b62fabf609f&lt;br /&gt;
	Enabled        : TRUE&lt;br /&gt;
	Server DNS name : TANGO.xinux.test&lt;br /&gt;
	Server DN name  : CN=NTDS Settings,CN=TANGO,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
		TransportType: RPC&lt;br /&gt;
		options: 0x00000001&lt;br /&gt;
Warning: No NC replicated for Connection!&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
DC2:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
root@tango:~# samba-tool drs showrepl&lt;br /&gt;
&lt;br /&gt;
Default-First-Site-Name\TANGO&lt;br /&gt;
DSA Options: 0x00000001&lt;br /&gt;
DSA object GUID: 9038189e-b307-48dc-bca3-fc76bc63ec38&lt;br /&gt;
DSA invocationId: 1278e3ce-dadf-4e44-be9a-43c591e8318d&lt;br /&gt;
&lt;br /&gt;
==== INBOUND NEIGHBORS ====&lt;br /&gt;
&lt;br /&gt;
CN=Schema,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:28:15 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:28:15 2015 CEST&lt;br /&gt;
&lt;br /&gt;
DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:28:15 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:28:15 2015 CEST&lt;br /&gt;
&lt;br /&gt;
DC=DomainDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:31:28 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:31:28 2015 CEST&lt;br /&gt;
&lt;br /&gt;
DC=ForestDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:28:15 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:28:15 2015 CEST&lt;br /&gt;
&lt;br /&gt;
CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ Thu Sep 10 11:28:15 2015 CEST was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ Thu Sep 10 11:28:15 2015 CEST&lt;br /&gt;
&lt;br /&gt;
==== OUTBOUND NEIGHBORS ====&lt;br /&gt;
&lt;br /&gt;
CN=Schema,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
DC=DomainDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
DC=ForestDnsZones,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
	Default-First-Site-Name\RUMBA via RPC&lt;br /&gt;
		DSA object GUID: d91df6e8-fc0f-4d96-8407-1f66f5b5c47d&lt;br /&gt;
		Last attempt @ NTTIME(0) was successful&lt;br /&gt;
		0 consecutive failure(s).&lt;br /&gt;
		Last success @ NTTIME(0)&lt;br /&gt;
&lt;br /&gt;
==== KCC CONNECTION OBJECTS ====&lt;br /&gt;
&lt;br /&gt;
Connection --&lt;br /&gt;
	Connection name: 2770037b-6291-442b-9b94-89c8d6c780c0&lt;br /&gt;
	Enabled        : TRUE&lt;br /&gt;
	Server DNS name : rumba.xinux.test&lt;br /&gt;
	Server DN name  : CN=NTDS Settings,CN=RUMBA,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=xinux,DC=test&lt;br /&gt;
		TransportType: RPC&lt;br /&gt;
		options: 0x00000001&lt;br /&gt;
Warning: No NC replicated for Connection!&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=SeDiskOperatorPrivilege=&lt;br /&gt;
 net rpc rights grant 'XINUX\Domain Admins' SeDiskOperatorPrivilege -Uadministrator&lt;br /&gt;
&lt;br /&gt;
===Vorhandene Rechte lassen sich so Anzeige===	&lt;br /&gt;
 net rpc rights list accounts -Uadministrator&lt;/div&gt;</summary>
		<author><name>Thomas</name></author>
	</entry>
</feed>