Author Topic: Cannot join zentyal domain  (Read 4388 times)

jbahillo

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1444
  • Karma: +77/-2
    • View Profile
Re: Cannot join zentyal domain
« Reply #15 on: June 17, 2014, 06:53:07 pm »
And if you create a new user in GUI, it is not shown in that command?

IN such case you are facing some serious issue with s4sync, and you should look in zentyal.log for errors


Edo

  • Zen Apprentice
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Re: Cannot join zentyal domain
« Reply #16 on: June 17, 2014, 06:57:39 pm »
sysadmin@dclnx1:~$ cat /var/log/zentyal/zentyal.log | grep s4sync
sysadmin@dclnx1:~$
Zentyal CE 4.0.5

jbahillo

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1444
  • Karma: +77/-2
    • View Profile
Re: Cannot join zentyal domain
« Reply #17 on: June 17, 2014, 06:58:29 pm »
You should rather grep for ERROR

Edo

  • Zen Apprentice
  • *
  • Posts: 11
  • Karma: +0/-0
    • View Profile
Re: Cannot join zentyal domain
« Reply #18 on: June 17, 2014, 07:04:43 pm »
Most are about jabber and remote backup not working.
...
2014/06/12 11:49:44 ERROR> RESTClient.pm:340 EBox::RemoteServices::RESTClient::request - 500 : <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
2014/06/12 11:49:58 ERROR> RESTClient.pm:340 EBox::RemoteServices::RESTClient::request - 500 : <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
2014/06/12 11:51:15 ERROR> OU.pm:140 EBox::Samba::OU::__ANON__ - Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 11:51:15 ERROR> OU.pm:153 EBox::Samba::OU::__ANON__ - Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 11:51:15 ERROR> LDB.pm:336 EBox::LDB::__ANON__ - Error loading OU 'Domain Controllers' in 'DC=lan,DC=ABC,DC=com': Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 11:51:15 ERROR> Provision.pm:660 EBox::Samba::Provision::__ANON__ - 1
2014/06/12 11:51:15 ERROR> GlobalImpl.pm:668 EBox::GlobalImpl::__ANON__ - Failed to save changes in module samba: Error loading OU 'Domain Controllers' in 'DC=lan,DC=ABC,DC=com': Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 11:51:15 ERROR> GlobalImpl.pm:755 EBox::GlobalImpl::saveAllModules - The following modules failed while saving their changes, their state is unknown: samba  at /usr/share/perl5/EBox/GlobalImpl.pm line 755
2014/06/12 11:57:51 ERROR> Base.pm:245 EBox::RemoteServices::Base::_queryServicesNameserver - Trace begun at /usr/share/perl5/EBox/RemoteServices/Base.pm line 244
2014/06/12 11:57:51 ERROR> Iptables.pm:384 EBox::Iptables::__ANON__ - Cannot contact Zentyal Remote: Server vpn6.cloud.zentyal.com not found via DNS server ns.cloud.zentyal.com,127.0.0.1. Reason: query timed out
2014/06/12 11:57:51 ERROR> Sudo.pm:232 EBox::Sudo::_rootError - root command set -e
2014/06/12 11:57:51 ERROR> Iptables.pm:670 EBox::Iptables::__ANON__ - Error executing firewall rules for module openvpn
2014/06/12 12:02:02 ERROR> Ldap.pm:477 EBox::Ldap::safeConnect - Couldn't connect to LDAP server ldapi://%2fvar%2frun%2fslapd%2fldapi: connect: No such file or directory. Retrying
2014/06/12 12:02:29 ERROR> OU.pm:140 EBox::Samba::OU::__ANON__ - Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 12:02:29 ERROR> OU.pm:153 EBox::Samba::OU::__ANON__ - Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 12:02:29 ERROR> LDB.pm:336 EBox::LDB::__ANON__ - Error loading OU 'Domain Controllers' in 'DC=lan,DC=ABC,DC=com': Error creating entry: The client attempted to add an entry that already exists. This can occur as
2014/06/12 12:02:29 ERROR> Provision.pm:660 EBox::Samba::Provision::__ANON__ - 1
2014/06/12 12:02:29 ERROR> Service.pm:992 EBox::Module::Service::__ANON__ - Error restarting service: Error loading OU 'Domain Controllers' in 'DC=lan,DC=ABC,DC=com': Error creating entry: The client attempted to add an entry that already exists. This can occur as
...
Zentyal CE 4.0.5

jbahillo

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1444
  • Karma: +77/-2
    • View Profile
Re: Cannot join zentyal domain
« Reply #19 on: June 17, 2014, 07:06:31 pm »
well, this actually does not:

N__ - Failed to save changes in module samba: Error loading OU 'Domain Controllers' in 'DC=lan,DC=ABC,DC=com': Error creating entry: The client attempted to add an entry that already exists. This can occur as

If you have not too much advanced on this server config, I would go for reinstalling


MasterfulMethods

  • Zen Apprentice
  • *
  • Posts: 3
  • Karma: +0/-0
    • View Profile
Re: Cannot join zentyal domain
« Reply #20 on: June 19, 2014, 01:28:31 am »
Hey Guys,

I was having similar issues when trying to test out AD DS with Zentyal. After seeing the post about samba-tool, I was messing around with that.

I wanted to change the hidden Administrator password, but it wouldn't let me. I used "listmembers" to look at the 'Domain Admins' group and the user that I created with the intention of using as my 'DC Admin' user was not in the list, even though I had added it through the Web UI...So I manually added the 'Admin' user to the 'Domain Admins' group, and also manually changed the password again to make sure it was correct.

Then when I went back to the test Windows 7 machine, I was able to successfully join the domain and log in. However, the new box is yet to show up in the Web UI under 'Manage'...
« Last Edit: June 19, 2014, 01:38:34 am by MasterfulMethods »

StuartNaylor

  • Guest
Re: Cannot join zentyal domain
« Reply #21 on: June 19, 2014, 01:58:58 am »
I would not change the password of the hidden administrator account.

Some of the authentication and ldap browsing methods of some modules are using that account and the password is hard coded into some of the config files.

You should of been able to with samba-tool but probably better that it didn't.

Why Zentyal is using the administrator account rather than maybe something like ebox or even zentyal I dunno.