From 86ee5909017880fc8771a62a495a1780a3517d64 Mon Sep 17 00:00:00 2001 From: Stefan Metzmacher Date: Fri, 3 Aug 2012 12:47:11 +0200 Subject: s4:domain join: setup RODC invocationId MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Pair-Programmed-With: Björn Baumbach metze Autobuild-User(master): Stefan Metzmacher Autobuild-Date(master): Sat Aug 4 18:27:21 CEST 2012 on sn-devel-104 --- source4/scripting/python/samba/join.py | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/source4/scripting/python/samba/join.py b/source4/scripting/python/samba/join.py index 0d21279e25..41d97cb477 100644 --- a/source4/scripting/python/samba/join.py +++ b/source4/scripting/python/samba/join.py @@ -788,6 +788,32 @@ class dc_join(object): for nc in ctx.full_nc_list: ctx.send_DsReplicaUpdateRefs(nc) + if ctx.RODC: + print "Setting RODC invocationId" + ctx.local_samdb.set_invocation_id(str(ctx.invocation_id)) + ctx.local_samdb.set_opaque_integer("domainFunctionality", + ctx.behavior_version) + m = ldb.Message() + m.dn = ldb.Dn(ctx.local_samdb, "%s" % ctx.ntds_dn) + m["invocationId"] = ldb.MessageElement(ndr_pack(ctx.invocation_id), + ldb.FLAG_MOD_REPLACE, + "invocationId") + ctx.local_samdb.modify(m) + + # Note: as RODC the invocationId is only stored + # on the RODC itself, the other DCs never see it. + # + # Thats is why we fix up the replPropertyMetaData stamp + # for the 'invocationId' attribute, we need to change + # the 'version' to '0', this is what windows 2008r2 does as RODC + # + # This means if the object on a RWDC ever gets a invocationId + # attribute, it will have version '1' (or higher), which will + # will overwrite the RODC local value. + ctx.local_samdb.set_attribute_replmetadata_version(m.dn, + "invocationId", + 0) + print "Setting isSynchronized and dsServiceName" m = ldb.Message() m.dn = ldb.Dn(ctx.local_samdb, '@ROOTDSE') -- cgit