Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Joining Zentyal Community Server to Windows Server 2008 domain.

Posted on 2015-01-22
10
Medium Priority
?
490 Views
Last Modified: 2015-06-09
I am trying to install a Zentyal Community Edition server to act as an RODC for my network. It's basically a backup DNS Server/DC in case one of our virtual hosts goes down. Every time I try to join the Zentyal server as an additional DC using the web console, I get a samba error. When I attempt to join using the console, for troubleshooting purposes, I notice that the process hangs up at an AD entry for exchange OWA. Does anyone have any advice on how to work around this issue?
0
Comment
Question by:Jake Davis
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 5
10 Comments
 
LVL 62

Accepted Solution

by:
gheist earned 1500 total points
ID: 40564859
By zentyal you mean ripoff ubuntu samba?
No Samba does not work as RODC.
0
 

Author Comment

by:Jake Davis
ID: 40564886
While RODC would be ideal, I'm not married to the idea of having it work that way, I more want it to be a DC. The error I am trying to work around is within SAMBA, when at starts replicating the Exchange AD entries.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40565079
Samba can be AD controller or AD client. Since all other setups make you pay Microsoft CAL, I see no purpose having other software in that position.
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:Jake Davis
ID: 40571554
Well, I want to use the Samba DC as a backup domain controller. Here is my issue. I enter this command to join the domain as a dc:

sudo samba-tool domain join tf-technology.local DC  -Uadministrator  --workgroup=tfti  --server=172.16.100.20  --dns-backend=BIND9_DLZ  --realm=TF-TECHNOLOGY.LOCAL  --site=Default-First-Site

I run into an issue here, and the domain join fails:

Failed to apply records: attribute 'msExchOWAAllowedFileTypes': value #1 on 'CN=owa (Default Web Site),CN=HTTP,CN=Protocols,CN=TFTIEXC01,CN=Servers,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=TF-TECHNOLOGY,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=TF-TECHNOLOGY,DC=LOCAL' provided more than once: Attribute or value exists

Now, I've gone to this entry using the LDP tool on the domain controller, I've removed tons of entries and backed them  up so that I can reapply them once I get Samba synced up with the domain. What I'm looking for is any insight into why it doesn't like the entries and how to make it work around them. Can I provision the same domain using the Samba tool, and then use the Active directory tool to marry them together, or should I just keep removing entries?
0
 
LVL 62

Expert Comment

by:gheist
ID: 40572133
Grandfather of zentyal keeps documentation about editing smb.conf to join domain without creepy tools:
https://wiki.debian.org/AuthenticatingLinuxWithActiveDirectory
0
 

Author Comment

by:Jake Davis
ID: 40594108
Any advice at all on having it function as a DC? I've got most of the functionality out of it that I want, I would just like my users to be able to authenticate if the Virtual DC goes down and I don't want a physical windows DC.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40594113
Read your question until you find DC being asked there.
0
 

Author Comment

by:Jake Davis
ID: 40820614
I've requested that this question be deleted for the following reason:

No one responded with an appropriate solution to my question.
0
 
LVL 62

Expert Comment

by:gheist
ID: 40820615
Sorry - you asked for RDC - you get answer NO
Then you flipped and flapped the DC requirement getting instructions on all possible other setups.
Please accept http:#a40564859 as complete answer
0
 

Author Comment

by:Jake Davis
ID: 40820954
Okay, I will accept that answer.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this post we will be converting StringData saved within a text file into a hash table. This can be further used in a PowerShell script for replacing settings that are dynamic in nature from environment to environment.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question