Internal dns_server does a cross-ncs search for all dnsZone object. This wrong as if there is more than 1 domain and the DC is a GC then it will have (partial)replica of DomainDNS zone for other domain. Also tests against windows have shown that cross-ncs search didn't search into application partitions: ./bin/ldbsearch -H ldap://172.16.100.244 -Uadministrator%totoTATA123 --cross-ncs '(objectclass=dnszone)' dn # record 1 dn: DC=RootDNSServers,CN=MicrosoftDNS,CN=System,DC=w2k3,DC=home,DC=matws,DC=net # returned 1 records # 1 entries # 0 referrals