Unpredicted replication failure from time to time among DSA entries in Symantec Directory
search cancel

Unpredicted replication failure from time to time among DSA entries in Symantec Directory

book

Article ID: 400241

calendar_today

Updated On:

Products

CA Directory

Issue/Introduction

You come across the situation where replication among DSAs result into a failure without prompting any errors.

For example, a user's "attribute1" gets updated originally on one DSA and when check on other DSAs, it still shows the old value for "attribute1" while in theory it should have been replicated. Also, there are no errors reportd on failed replication.

The above doesn't happen all the time or on any specific attribute but it does happen more frequently without any specific time pattern (i.e. not during a specific time of the day).

Cause

It could mostly be related to Operating Systems time out of sync.

Resolution

The problem could be related to Operating Systme (Linux and/or Windows) time.

To find out exactly what is going on, you need to enable replplication log (only available starting version 14.1.03) and reproduce problem. Once done, look for the following message in any of the replication log.

"Modify timestamp is too recent, update won't be applied"

If you do see this, that means the Operating System clocks are out of sync.

Solution is to:

  • Resync the system clocks making sure all involved nodes are in sync.
  • Perform DR (Disaster Recovery) steps to manually sync the data across the board so start with a good (identical) data set on all DSAs.
  • Monitor the replication log and confirm there are no more timestamp related messages that leads to replication failure.