[Samba] Problem to demote samba4 dc

Andrew Bartlett abartlet at samba.org
Thu Aug 1 20:11:33 MDT 2013

On Wed, 2013-07-31 at 15:10 +0200, Davy HUBERT wrote:
> Hi all,
> I recently migrated our samba 3 domain to an AD domain using Samba 4 
> classic upgrade tool. Well, every seems to work fine since i'm still 
> alive ;) .
> I promoted a Windows 2k8 box as a new DC of this domain and I transfer 
> the 5 FSMO roles to it.
> Now I would like to demote the Samba4 DC but when I tried I got this 
> message :
> # samba-tool domain demote
> ERROR: Current DC is still the owner of 2 role(s), use the role command 
> to transfer roles to another DC
> When check the fsmo roles status via "samba-tool fsmo show" it confirms 
> that the Samba 4 DC doesn't own anything.
> How can I manage to demote the Samba 4 box ?

The best option would be to turn off the Samba DC, and then use ADUC on
Windows and tell it that the Samba DC is permanently off-line.  The
roles can be seized from there.

Andrew Bartlett

Andrew Bartlett
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Catalyst IT                   http://catalyst.net.nz

More information about the samba mailing list