[Samba] Secondary domain controller and promotion

Brian Candler b.candler at pobox.com
Tue Jun 17 15:11:16 MDT 2014

On 17/06/2014 20:07, Marc Muehlfeld wrote:
> AD DC are multi-master.
Thank you for your extremely helpful reply.

I have two test Samba4 AD VMs configured now and can see multi-master 
replication working.

>   Byside
> the FSME roles, each DC is eqal.
(For list reference: that's FSMO)

>> Is it the same to process to add a second Samba machine to an existing
>> Samba 4 domain?
> No.
> DC:
> https://wiki.samba.org/index.php/Join_a_domain_as_a_DC#Joining_the_existing_domain_as_a_DC
> # samba-tool domain join .....
> Member Servers:
> https://wiki.samba.org/index.php/Setup_a_Samba_AD_Member_Server#Joining_a_Member_Server_to_the_domain
> # net [rpc|ads] join -U administrator

Ah, maybe I wasn't clear. What I meant was "add another Samba machine to 
be a replica Active Directory server to an existing Samba Active 
Directory domain".

Is the process the same whether the the initial Active Directory server 
is Windows AD or Samba AD?

I have now successfully added a second Samba AD following 
"Join_a_domain_as_a_DC", so I guess that answers my question :-)

<< snip lots of useful stuff >>

>> (4) Is it possible to migrate a Windows 2003 domain to Samba 4 by:
>> - adding Samba 4 to the existing Windows domain
>> - making it the master
>> - copying sysvol
>> - retiring the Windows server?
> Almost:
> - adding a Samba DC to the existing domain
> - copy sysvol
... migrate all FSMO roles to Samba ...
> - demote the windows server

Cool. And I'm presuming that "demote the windows server" would be done 
using the ADUC tool, and Samba would pick up that change automatically?



