Migrating Samba NT4 Domain to Samba AD

Rowland penny rpenny at samba.org
Thu Sep 12 20:17:34 UTC 2019


On 12/09/2019 20:37, Bartłomiej Solarz-Niesłuchowski via samba-technical 
wrote:
> Dear List,
Sorry but this is the wrong list, it should have been the samba mailing 
list, not samba-technical, I have cc'ed the samba list, please reply there.
>
> I need to migrate my Samba NT4 domain (5000+ users, 600+ workstation, 
> 50+ printers) urgently.
>
>
> Backend for samba is on an replicated openldap environment is mixed 
> (both linux and windows) i use password aging on windows AND linux and 
> use ldap with samba.schema and posix.schema.
>
> Please help me to find manuals for those migration.
>
> I found:
>
> https://wiki.samba.org/index.php/Migrating_a_Samba_NT4_Domain_to_Samba_AD_(Classic_Upgrade) 
>
You have found it, that is where to start if you want to migrate to AD
>
> and
>
> https://wiki.samba.org/index.php/Samba4/LDAP_Backend
For what you require, you can basically ignore that.
>
>
> Problems which i have not found good links:
>
> how to replicate ldap (one ldap server for network in my size is not 
> enought)?

You migrate your NT4-style domain to AD and then just join additional 
DCs and replication is done for you, see here:

https://wiki.samba.org/index.php/Joining_a_Samba_DC_to_an_Existing_Active_Directory

>
> how to use both samba.schema (windows user data) and posix.schema 
> (unix user data) + password aging in both environments?
You don't
>
> how configure and use bind9 as dns backend for samba AD?

see here:

https://wiki.samba.org/index.php/BIND9_DLZ_DNS_Back_End
https://wiki.samba.org/index.php/Setting_up_a_BIND_DNS_Server

>
> how backup (daily) contents of the samba data (e.g. slapcat)?

Nope you would use the samba-tool backup commands, see here:

https://wiki.samba.org/index.php/Back_up_and_Restoring_a_Samba_AD_DC

>
>
> Migration will be try to done at this sunday so i am in hurry......

I will be round on Monday to sweep up the pieces ;-)

You need more time to test and fix problems before you do it for real, 3 
days is nowhere near enough time.

>
>
> Please help me with those migration if you have links for good howtos.
>
See above links and remember to reply to the samba mailing list: 
samba at lists.samba.org

Rowland





More information about the samba-technical mailing list