problems demoting samba4 DC

Greg Dickie greg at
Sun Jun 17 13:51:19 MDT 2012


  Using 4.0.0beta2-GIT-6440720 and trying to demote a samba4 DC from a
domain which was migrated from samba3.

First problem I get is:

[root at hamba4 ~]# /usr/local/samba/bin/samba-tool domain demote 
ERROR: Current DC is still the owner of 2 role(s), use the role command
to transfer roles to another DC

Hmmm I thought I transferred all the roles to the windows DC so put in
some debug in

Then I get:

Still has role CN=Infrastructure,DC=DomainDnsZones,DC=example,DC=local
Still has role CN=Infrastructure,DC=ForestDnsZones,DC=example,DC=local

Don't see a way to change roles on application partitions either in
samba or Windows so I just used ldbmodify.

Now demote proceeds but I get this:

[root at hamba4 ~]# /usr/local/samba/bin/samba-tool domain demote 
Using MTL-DC1.example.local as partner server for the demotion
Password for [administrator at EXAMPLE.LOCAL]:
Desactivating inbound replication
Asking partner server MTL-DC1.example.local to synchronize from us
Error while demoting, re-enabling inbound replication
ERROR(<class 'samba.drs_utils.drsException'>): Error while sending a
DsReplicaSync for partion DC=example,DC=local - drsException:
DsReplicaSync failed (8606,
line 280, in run
    sendDsReplicaSync(drsuapiBind, drsuapi_handle, ntds_guid, str(part),
line 83, in sendDsReplicaSync
    raise drsException("DsReplicaSync failed %s" % estr)

Any ideas?


Greg Dickie
just a guy

More information about the samba-technical mailing list