Novell Home

My Favorites

Close

Please to see your favorites.

Troubleshooting DSfW sysvolsync

This document (7013046) is provided subject to the disclaimer at the end of this document.

Environment

Novell Open Enterprise Server 11 SP1 (OES11 SP1)
Domain Services for Windows
DSfW

Situation

How to troubleshoot sysvolsync
Troubleshooting DSfW sysvolsync
Troubleshooting sysvolsync

Resolution

1) Enable debugging TID 7008500

2) Check for duplicate objectsids TID 7011617
If a duplicate objectsid exists on a DC object in the domain controllers container, it will cause a failure.

3) Examine the /var/log/messages for errors

4) Check the /var/opt/novell/xad/log/kdc.log for errors regarding "Decrypt integrity check failed " for Domain Controllers
    Reset the Domain Controllers password from the server using the setpassword command if the Decrypt integrity check failed" error is seen for the Domain Controller .
    /opt/novell/xad/sbin/setpassword -NDSOf -r -E Domainserver -k /var/opt/novell/xad/ds/kerb5kdc/krb5.keytab -u DOMAINSERVER$

    For mixed case Domain Controllers (DomainServer) or hyphenated names (Domain-Server)
    /opt/novell/xad/sbin/setpassword -NDSOf -r -E DomainServer,domainSERVER,DOMAINserver -k /var/opt/novell/xad/ds/kerb5kdc/krb5.keytab -u DOMAINSERVER$
    /opt/novell/xad/sbin/setpassword -NDSOf -r -E Domain-Server,domain-SERVER,DOMAIN-server -k /var/opt/novell/xad/ds/kerb5kdc/krb5.keytab -u DOMAIN-SERVER$

5) Verify the /etc/ssh/sshd_config has "GSSAPIAuthentication yes"
grep GSSAPIAuthentication /etc/ssh/sshd_config

6) dig -t SRV _ldap._tcp.dc._msdcs.<domain-name> +short
You can find out the shortname by doing grep workgroup /etc/samaba/smb.conf
Example:
dig -t SRV _ldap._tcp.dc._msdcs.dsfw-s1.dsfw.lan dsfw-s1

7) From the PDC and the ADC receiving the error use dig and nslookup for each servers A record
dig <dsfw-server-name.domain-name>
Example:
dig dsfw-s1.dsfw.lan
nslookup dsfw-s1.dsfw.lan

8) wbinfo -i for each DSfW server
wbinfo -i dsfw-s1$

9) Check the command "id <hostname of pdc>$" works correctly in the PDC
example for DSfW server with a name of dsfw-s1
id dsfw-s1$

10) Examine the /etc/hosts file to be sure the servers IP address and name are correct.  If other DSfW servers are listed ensure their entries are correct.
<IP Address> <Server.DomainName> <ShortName>
Example for server dsfw-s1 with domain name of dsfw.lan
192.168.0.10 dsfw-s1.dsfw.lan dsfw-s1

Disclaimer

This Support Knowledgebase provides a valuable tool for NetIQ/Novell/SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.

  • Document ID:7013046
  • Creation Date:14-AUG-13
  • Modified Date:06-SEP-13
    • NovellOpen Enterprise Server
    • SUSESUSE Linux Enterprise Server
    • NetIQeDirectory

Did this document solve your problem? Provide Feedback