[Samba] Setup a Samba AD DC as an additional DC

Andrew Ruscica andrew.lists at ruscica.com
Wed Dec 5 17:26:57 UTC 2018

On Tue, Dec 4, 2018 at 11:46 PM Andrew Bartlett <abartlet at samba.org> wrote:

> ...
> It is very likely 'just a bug'.  We do some DNS things trying to make
> sure the new DC can work the moment it starts (before that, folks had a
> lot of difficulty with the new DC not being in global DNS).
> This is different to what windows does, and there is a variety of
> different ways DNS can be set up on windows, so clearly it isn't
> interoperable right now.
> Sorry about that.
> Andrew Bartlett

Thank you for the responses, Andrew and Barry;

I have achieved success:  it was necessary to (re)create the
_msdcs.my.domain zone at Windows DNS.  It previously did not exist, for
reasons unknown to me. I'm assuming related to the domain functional level
being upgraded over time from 2003 to 2008R2.

There are a number of guidelines out there to accomplish this, but when
doing so, but some miss a required option for Samba: you must ensure the
Replication is set to all DNS servers in the *forest. *

More information about the samba mailing list