Role transfer and DNS updates

Ryan Whelan rcwhelan at
Mon Jun 18 13:51:24 MDT 2012

I'm testing samba4 as a replacement for windows AD in our environment.
 I created a domain using the provisioning steps outlined on the wiki
and created a second DC, joining it to the domain via the wiki
documentation.  After getting replication for the DNS Zones working
and setting up DNS on the second DC I tried transferring all the fsmo
roles to the second DC.  The transfer command timed out on the first
attempt to transfer each role; but succeeded on the second.

After transferring the roles, it looks like the the ForestDnsZones and
DomainDnsZones A records didn't get updated ( is the IP
of the first DC):

ForestDnsZones.cngtest.local. 900 IN A
DomainDnsZones.cngtest.local. 900 IN A

And the old PDC SRV record didn't get replaced- just the new one created:

_ldap._tcp.pdc._msdcs.cngtest.local. 900 IN SRV 0 100 389 smb1.cngtest.local.
_ldap._tcp.pdc._msdcs.cngtest.local. 900 IN SRV 0 100 389 smb2.cngtest.local.

I am FAR from an AD expert (i just starting learning about it for this
project).  Is this expected behavior?  Did I miss something?  Is this
a bug?

More information about the samba-technical mailing list