[Samba] recommendations for new AD with samba as backup DC

Mikel Pérez io at mikelpr.com
Fri Jan 19 21:07:55 UTC 2024


I'm about to deploy a new directory since I had only one Windows
Server 2019 DC and its storage died out (specifically, a block/page
where part of ntdis.dit happened to be stored because I was able to
rescue everything else. amazing)

Anyways, this time around I definitely need to have a backup DC. I
planned to have Windows be the primary DC and samba be the backup. I
wanted to know what precautions should I take,
- I saw that samba is still being prepared for functional level 2016
and schema 2019, is this still the case? should I instead provision
the domain as 2012R2 or 2008R2?
- should I instead have the samba one be the primary DC?

I never got GPOs working on a domain with just one samba DC as primary
even with a heimdal build (and the MIT one had weird issues when
authenticating on other machines for RDP) so I do need a windows
server DC and I'm guessing it has to be the primary DC.

I'd love to know before I spend time in vain setting up a new forest
based on bad decisions that I have to tear down and recreate after
finding out I made mistakes :')

Thanks in advance <3



More information about the samba mailing list