[Samba] Samba4 as an additional Domain Controller in existing Windows 2016 AD

David Wilson davew at dcdata.co.za
Mon Oct 8 13:21:56 UTC 2018


Sorry for the pressure guys. Any ideas on this please? 



Regards, 

David Wilson 

From: "samba. org" <samba at lists.samba.org> 
To: "samba. org" <samba at lists.samba.org> 
Sent: Wednesday, 3 October, 2018 16:45:42 
Subject: [Samba] Samba4 as an additional Domain Controller in existing Windows 2016 AD 

Good day guys, 

I hope all is well on your side. 

We are looking at implementing the latest stable version of Samba4 to function as a (secondary) domain controller in an existing Active Directory environment that is currently managed by an existing single Windows Server 2016 server. 

Aside from fairly easily-addressed sysvol replication challenges - looking at the official Samba documentation, it seems that nothing higher than a Domain/Forest Function Level of 2008r2 is supported, if Samba4 is to function as Domain Controller in an existing (Windows Server controlled) Active Directory environment? 
The information available seems to indicate that the reason for this is due to changes within the Windows Server Kerberos services, that are possibly not available within MIT or Heimdal Kerberos? 

Has anyone within the community had experience with this? 

References: 
https://wiki.samba.org/index.php/Raising_the_Functional_Levels 
https://groups.google.com/forum/#!topic/linux.samba/kAbGkR4CGLg 1 
https://docs.microsoft.com/cs-cz/windows-server/identity/ad-ds/active-directory-functional-levels 

I would be most grateful for any guidance and feedback, if possible please. 



Kind regards, 

David Wilson 
-- 
To unsubscribe from this list go to the following URL and read the 
instructions: https://lists.samba.org/mailman/options/samba 


More information about the samba mailing list