[Samba] Upgrading from 4.6.x to 4.7.x AD and member server setup - recommended path
rpenny at samba.org
Mon Jan 1 19:03:30 UTC 2018
On Mon, 1 Jan 2018 19:18:51 +0100
Götz Reinicke via samba <samba at lists.samba.org> wrote:
> > Am 31.12.2017 um 17:32 schrieb Rowland Penny via samba
> > <samba at lists.samba.org>:
> > On Sun, 31 Dec 2017 16:18:27 +0100
> > Götz Reinicke via samba <samba at lists.samba.org> wrote:
> >> Hi,
> >> we have three 4.6.x AD servers in a cluster
> > What do you mean by 'a cluster' ?
> > If you mean an actual cluster, how are you doing this and why ?
> I was a bit misleading, yes, just 3 DCs.
> >> and some member
> >> Fileservers. What is the best/savest/recomended upgrade path?
> >> Can I upgrade the AD servers one by one and run a „mixed“ setup for
> >> some time (minutes) ?
> > Hopefully you mean that you just have 3 DCs, if this is the case
> > then it depends on how you are doing the updates. if you are
> > updating using packages, then the packages should stop Samba before
> > doing the update. If you are going to compile Samba yourself, you
> > will need to use the configure options as originally and stop Samba
> > before running 'make install'.
> > Either way, I would start with the DC holding all the FSMO roles.
> > Then the other two DCs, one by one.
> I’d do the upgrade by rpm.
> I did find something in the samba wiki as I had time to google, which
> says the other way round; starting with a server that dose NOT hols a
> If you are updating multiple Samba Active Directory (AD) Domain
> Controllers (DC), the recommended order is: Update one Samba AD DC
> that does not hold any flexible single master operations (FSMO) role.
> So thats the way to go ?
> And dose all DCs should be shut down at that time?
> Regards . Götz
To be honest, you shouldn't upgrade the DCs, you should add new a DC
running the latest version of Samba, transfer the FSMO roles to this,
if everything is okay, demote the original DC.
Repeat for the other two DCs (apart from the FSMO roles)
If you must upgrade in place, then I would transfer the FSMO roles to
one of the other DCs, stop the DC, carry out the upgrade and then
restart the DC, transfer the roles back. repeat for the other two.
You can, if you wish, stop all three DCs, the only difference would be
to stop 'cannot replicate to DC X' in the logs.
More information about the samba