Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-102369

Unresponsive second DC can cause idmapping failure when using idmap_ad [rhel-10]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • samba-4.22.3-101.el10
    • No
    • Important
    • 1
    • rhel-idm-uah
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • RHELs: 10.1, 9.7
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      The problem is we're calling get_kdc_ip_string() which calls netlogon_pings() to contact the secondary DC (we already have a working connection to a "first" DC) and netlogon_pings() returns an error if all DCs it was supposed to ping fail to respond. This causes get_kdc_ip_string() to return an error causing complete idmapping failure.

              anschnei@redhat.com Andreas Schneider
              anschnei@redhat.com Andreas Schneider
              Andreas Schneider Andreas Schneider
              Martin Myska Martin Myska
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: