[Samba] Upgrade Samba 4

Marcio Demetrio Bacci marciobacci at gmail.com
Fri Aug 30 16:35:33 UTC 2019


Hi,

Now, my functional level is 2008_R2.

samba-tool domain level show
Domain and forest function level for domain 'DC=empres,DC=com,DC=br'

Forest function level: (Windows) 2008 R2
Domain function level: (Windows) 2008 R2
Lowest function level of a DC: (Windows) 2008 R2


Everything looks fine, the replication, the consistency between the DCs,
however I have checked this information in /var/log/samba/log.samba which I
don't know if is normal:


Kerberos: Looking for PKINIT pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.965040,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for ENC-TS pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.965075,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: No preauth found, returning PREAUTH-REQUIRED -- COMP0002$@
EMPRESA.COM.BR
[2019/08/30 13:16:56.966512,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'kdc_tcp_call_loop:
tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:16:56.969161,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: AS-REQ COMP0002$@EMPRESA.COM.BR from ipv4:192.168.8.12:55590
for krbtgt/EMPRESA.COM.BR at EMPRESA.COM.BR
[2019/08/30 13:16:56.972700,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Client sent patypes: encrypted-timestamp, 128
[2019/08/30 13:16:56.972736,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for PKINIT pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.972758,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Looking for ENC-TS pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.972830,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: ENC-TS Pre-authentication succeeded -- COMP0002$@EMPRESA.COM.BR
using aes256-cts-hmac-sha1-96
[2019/08/30 13:16:56.972875,  3]
../../auth/auth_log.c:647(log_authentication_event_human_readable)
  Auth: [Kerberos KDC,ENC-TS Pre-authentication] user [(null)]\[COMP0002$@
EMPRESA.COM.BR] at [Fri, 30 Aug 2019 13:16:56.972857 -03] with
[aes256-cts-hmac-sha1-96] status [NT_STATUS_OK] workstation [(null)] remote
host [ipv4:192.168.8.12:55590] became [EMPRESA]\[COMP0002$]
[S-1-5-21-1712526294-259020848-313593124-7480]. local host [NULL]
  {"timestamp": "2019-08-30T13:16:56.972930-0300", "type":
"Authentication", "Authentication": {"version": {"major": 1, "minor": 1},
"eventId": 4624, "logonType": 3, "status": "NT_STATUS_OK", "localAddress":
null, "remoteAddress": "ipv4:192.168.8.12:55590", "serviceDescription":
"Kerberos KDC", "authDescription": "ENC-TS Pre-authentication",
"clientDomain": null, "clientAccount": "COMP0002$@EMPRESA.COM.BR",
"workstation": null, "becameAccount": "COMP0002$", "becameDomain":
"EMPRESA", "becameSid": "S-1-5-21-1712526294-259020848-313593124-7480",
"mappedAccount": "COMP0002$", "mappedDomain": "EMPRESA",
"netlogonComputer": null, "netlogonTrustAccount": null,
"netlogonNegotiateFlags": "0x00000000", "netlogonSecureChannelType": 0,
"netlogonTrustAccountSid": null, "passwordType": "aes256-cts-hmac-sha1-96",
"duration": 3822}}
[2019/08/30 13:16:57.025109,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: AS-REQ authtime: 2019-08-30T13:16:56 starttime: unset endtime:
2019-08-30T23:16:56 renew till: 2019-09-06T13:16:56
[2019/08/30 13:16:57.025190,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96,
arcfour-hmac-md5, -133, -128, 24, -135, using
aes256-cts-hmac-sha1-96/aes256-cts-hmac-sha1-96
[2019/08/30 13:16:57.025216,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: Requested flags: renewable-ok, canonicalize, renewable,
forwardable
[2019/08/30 13:16:57.031762,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'kdc_tcp_call_loop:
tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:16:57.035529,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: TGS-REQ COMP0002$@EMPRESA.COM.BR from ipv4:192.168.8.12:55591
for ajur0002$@EMPRESA.COM.BR [canonicalize, renewable, forwardable]
[2019/08/30 13:16:57.040500,  3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
  Kerberos: TGS-REQ authtime: 2019-08-30T13:16:56 starttime:
2019-08-30T13:16:57 endtime: 2019-08-30T23:16:56 renew till:
2019-09-06T13:16:56
[2019/08/30 13:16:57.042891,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'kdc_tcp_call_loop:
tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:04.113053,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:06.123652,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:12.796283,  3]
../../lib/ldb-samba/ldb_wrap.c:332(ldb_wrap_connect)
  ldb_wrap open of secrets.ldb
[2019/08/30 13:17:12.796760,  3]
../../auth/gensec/schannel.c:618(schannel_update_internal)
  Could not find session key for attempted schannel connection from
COMP0002: NT_STATUS_NOT_FOUND
[2019/08/30 13:17:12.797902,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:12.800680,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:16.935086,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_RESET'
[2019/08/30 13:17:24.112678,  3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
  stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'

I have tested kerberos authentication and looks fine for me.

Regards,

Márcio Bacci

Em sex, 30 de ago de 2019 às 12:17, L.P.H. van Belle <belle at bazuin.nl>
escreveu:

> 
> P.s
>
> Im getting out of the office, so other question mail the list, Rowland
> will help further if needed.
>
> Greetz,
>
> Louis
>
>
> ------------------------------
> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
> *Verzonden:* vrijdag 30 augustus 2019 17:00
> *Aan:* L.P.H. van Belle
> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>
> Hi,
>
> I followed your directions and here are the results:
>
> samba-tool domain level show
> Domain and forest function level for domain 'DC=empresa,DC=com,DC=br'
>
> Forest function level: (Windows) 2003
> Domain function level: (Windows) 2008
> Lowest function level of a DC: (Windows) 2008 R2
>
> root at samba4-dc1:/var/log/samba# dpkg -l |egrep
> "talloc|tevent|ldb|tdb|wrapper"
> ii  ldb-tools                        2:1.5.5-1.1deb9~1              amd64
>        LDAP-like embedded database - tools
> ii  libgmpxx4ldbl:amd64              2:6.1.2+dfsg-1                 amd64
>        Multiprecision arithmetic library (C++ bindings)
> ii  libgnutls-openssl27:amd64        3.5.8-5+deb9u4                 amd64
>        GNU TLS library - OpenSSL wrapper
> ii  libldb1:amd64                    2:1.5.5-1.1deb9~1              amd64
>        LDAP-like embedded database - shared library
> ii  libltdl-dev:amd64                2.4.6-2                        amd64
>        System independent dlopen wrapper for GNU libtool
> ii  libltdl7:amd64                   2.4.6-2                        amd64
>        System independent dlopen wrapper for GNU libtool
> ii  libmldbm-perl                    2.05-2                         all
>        module for storing multidimensional hash structures in perl tied
> hashes
> ii  libtalloc2:amd64                 2.1.16-0nmu1~deb9              amd64
>        hierarchical pool based memory allocator
> ii  libtdb1:amd64                    1.3.18-0.1nmu0~deb9            amd64
>        Trivial Database - shared library
> ii  libtevent0:amd64                 0.9.39-0.1nmu1~deb9            amd64
>        talloc-based event loop library - shared library
> ii  libwrap0:amd64                   7.6.q-26                       amd64
>        Wietse Venema's TCP wrappers library
> ii  python-gpgme                     0.3-1.2                        amd64
>        python wrapper for the GPGME library
> ii  python-talloc:amd64              2.1.16-0nmu1~deb9              amd64
>        hierarchical pool based memory allocator - Python bindings
> ii  python-tdb                       1.3.18-0.1nmu0~deb9            amd64
>        Python bindings for TDB
> ii  python3-gpgme                    0.3-1.2                        amd64
>        python wrapper for the GPGME library (Python 3)
> ii  python3-ldb                      2:1.5.5-1.1deb9~1              amd64
>        Python 3 bindings for LDB
> ii  python3-talloc                   2.1.16-0nmu1~deb9              amd64
>        hierarchical pool based memory allocator - Python3 bindings
> ii  python3-tdb                      1.3.18-0.1nmu0~deb9            amd64
>        Python3 bindings for TDB
> ii  ssl-cert                         1.0.39                         all
>        simple debconf wrapper for OpenSSL
> ii  tcpd                             7.6.q-26                       amd64
>        Wietse Venema's TCP wrapper utilities
> ii  tdb-tools                        1.3.18-0.1nmu0~deb9            amd64
>        Trivial Database - bundled binaries
> root at samba4-dc1:/var/log/samba#
>
> root at samba4-dc1:/var/log/samba# /etc/init.d/samba-ad-dc status
> ● samba-ad-dc.service - Samba AD Daemon
>    Loaded: loaded (
> ]8;;file://samba4-dc1/lib/systemd/system/samba-ad-dc.service/lib/systemd/system/samba-ad-dc.service
> ]8;;; enabled; vendor preset: enabled)
>    Active: active (running) since Fri 2019-08-30 11:54:12 -03; 9s ago
>      Docs: ]8;;man:samba(8)man:samba(8) ]8;;
>             ]8;;man:samba(7)man:samba(7) ]8;;
>             ]8;;man:smb.conf(5)man:smb.conf(5) ]8;;
>  Main PID: 1755 (samba)
>    Status: "smbd: ready to serve connections..."
>     Tasks: 27 (limit: 4720)
>    CGroup: /system.slice/samba-ad-dc.service
>            ├─1755 samba: root process
>            ├─1756 samba: task[s3fs_parent]
>            ├─1757 samba: task[dcesrv]
>            ├─1758 samba: task[nbtd]
>            ├─1759 samba: tfork waiter process
>            ├─1760 samba: task[wrepl]
>            ├─1761 samba: task[ldapsrv]
>            ├─1762 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1763 samba: task[cldapd]
>            ├─1764 samba: conn[kdc_tcp] c[ipv4:* MailScanner heeft een
> e-mail met mogelijk een poging tot fraude gevonden van
> "192.168.94.63:62130" * *MailScanner warning: numerical links are often
> malicious:* 192.168.94.63:62130 <http://192.168.94.63:62130>] s[ipv4:*
> MailScanner heeft een e-mail met mogelijk een poging tot fraude gevonden
> van "192.168.1.20:88" * *MailScanner warning: numerical links are often
> malicious:* 192.168.1.20:88 <http://192.168.1.20:88>] server_id[1764.40]
>            ├─1765 samba: task[dreplsrv]
>            ├─1766 samba: task[winbindd_parent]
>            ├─1767 samba: task[ntp_signd]
>            ├─1768 samba: task[kccsrv]
>            ├─1769 samba: task[dnsupdate]
>            ├─1770 samba: conn[dns_tcp] c[ipv4:* MailScanner heeft een
> e-mail met mogelijk een poging tot fraude gevonden van "192.168.6.24:59870"
> * *MailScanner warning: numerical links are often malicious:*
> 192.168.6.24:59870 <http://192.168.6.24:59870>] s[ipv4:* MailScanner
> heeft een e-mail met mogelijk een poging tot fraude gevonden van
> "192.168.1.20:53" * *MailScanner warning: numerical links are often
> malicious:* 192.168.1.20:53 <http://192.168.1.20:53>] server_id[1770.42]
>            ├─1771 samba: tfork waiter process
>            ├─1772 /usr/sbin/winbindd -D --option=server role
> check:inhibit=yes --foreground
>            ├─1797 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1798 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1799 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1804 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1805 samba: conn[rpc] c[ipv4:* MailScanner heeft een e-mail
> met mogelijk een poging tot fraude gevonden van "10.67.92.134:53636" * *MailScanner
> warning: numerical links are often malicious:* 10.67.92.134:53636
> <http://10.67.92.134:53636>] s[ipv4:* MailScanner heeft een e-mail met
> mogelijk een poging tot fraude gevonden van "192.168.1.20:49152" * *MailScanner
> warning: numerical links are often malicious:* 192.168.1.20:49152
> <http://192.168.1.20:49152>] server_id[1805]
>            ├─1806 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1807 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
>            ├─1808 winbindd: domain child [EMPRESA]
>            └─1809 winbindd: idmap child
>
> ago 30 11:54:12 samba4-dc1 samba[1755]: root process[1755]:   Copyright
> Andrew Tridgell and the Samba Team 1992-2019
> ago 30 11:54:12 samba4-dc1 samba[1755]: root process[1755]: [2019/08/30
> 11:54:12.469019,  0] ../../source4/smbd/server.c:773(binary_smbd_main)
> ago 30 11:54:12 samba4-dc1 samba[1755]: root process[1755]:
> binary_smbd_main: samba: using 'standard' process model
> ago 30 11:54:12 samba4-dc1 winbindd[1772]: [2019/08/30 11:54:12.939861,
>  0] ../../source3/winbindd/winbindd_cache.c:3166(initialize_winbindd_cache)
> ago 30 11:54:12 samba4-dc1 winbindd[1772]:   initialize_winbindd_cache:
> clearing cache and re-creating with version number 2
> ago 30 11:54:12 samba4-dc1 winbindd[1772]: [2019/08/30 11:54:12.942535,
>  0] ../../lib/util/become_daemon.c:136(daemon_ready)
> ago 30 11:54:12 samba4-dc1 winbindd[1772]:   daemon_ready: daemon
> 'winbindd' finished starting up and ready to serve connections
> ago 30 11:54:12 samba4-dc1 systemd[1]: Started Samba AD Daemon.
> ago 30 11:54:12 samba4-dc1 smbd[1762]: [2019/08/30 11:54:12.993254,  0]
> ../../lib/util/become_daemon.c:136(daemon_ready)
> ago 30 11:54:12 samba4-dc1 smbd[1762]:   daemon_ready: daemon 'smbd'
> finished starting up and ready to serve connections
>
> Regards,
>
> Márcio Bacci
>
> Em sex, 30 de ago de 2019 às 11:40, L.P.H. van Belle <belle at bazuin.nl>
> escreveu:
>
>> 
>> Hai,
>>
>> No, its not automaticly raised.
>> that is shown here :
>> https://wiki.samba.org/index.php/Raising_the_Functional_Levels
>> samba-tool domain level show   : show current level.
>> On every DC, run : samba-tool dbcheck --reindex
>> This was not always done in the past, should be done at upgrade, but i
>> always run if after major updates to be sure.
>>
>> Can you post the me this :  dpkg -l |egrep
>> "talloc|tevent|ldb|tdb|wrapper"
>> asking that because of these you showed.
>> samba4-dc1 samba[17835]: task[dcesrv][17835]:
>> standard_child_pipe_handler: Child 18438 () terminated with signal 6
>>
>> im guessing that these are of the upgrade, simple to verify..
>> stop samba-ad
>>
>> clear the samba logs
>> start samba-ad
>>
>> Check the logs.
>>
>>
>> Greetz,
>>
>> Louis
>>
>>
>>
>>
>> ------------------------------
>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>> *Verzonden:* vrijdag 30 augustus 2019 16:31
>> *Aan:* L.P.H. van Belle
>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>
>> Hi,
>>
>> I was able to upgrade both DC to Samba 4.10.7. Apparently everything is
>> OK.
>>
>> root at samba4-dc1:~# /etc/init.d/samba-ad-dc status
>> ● samba-ad-dc.service - Samba AD Daemon
>>    Loaded: loaded (
>> ]8;;file://samba4-dc1/lib/systemd/system/samba-ad-dc.service/lib/systemd/system/samba-ad-dc.service
>> ]8;;; enabled; vendor preset: enabled)
>>    Active: active (running) since Fri 2019-08-30 10:50:23 -03; 28min ago
>>      Docs: ]8;;man:samba(8)man:samba(8) ]8;;
>>             ]8;;man:samba(7)man:samba(7) ]8;;
>>             ]8;;man:smb.conf(5)man:smb.conf(5) ]8;;
>>  Main PID: 17833 (samba)
>>    Status: "winbindd: ready to serve connections..."
>>     Tasks: 31 (limit: 4720)
>>    CGroup: /system.slice/samba-ad-dc.service
>>            ├─17833 samba: root process
>>            ├─17834 samba: task[s3fs_parent]
>>            ├─17835 samba: task[dcesrv]
>>            ├─17836 samba: task[nbtd]
>>            ├─17837 samba: task[wrepl]
>>            ├─17838 samba: tfork waiter process
>>            ├─17839 samba: task[ldapsrv]
>>            ├─17840 samba: task[cldapd]
>>            ├─17841 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─17842 samba: conn[kdc_tcp] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van "192.168.3.37:54843"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.3.37:54843 <http://192.168.3.37:54843>] s[ipv4:* MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:88" **MailScanner warning: numerical links are often
>> malicious:* 192.168.1.20:88 <http://192.168.1.20:88>] server_id[17842.40]
>>            ├─17843 samba: task[dreplsrv]
>>            ├─17844 samba: task[winbindd_parent]
>>            ├─17845 samba: task[ntp_signd]
>>            ├─17846 samba: task[kccsrv]
>>            ├─17847 samba: task[dnsupdate]
>>            ├─17848 samba: conn[dns_tcp] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van "192.168.6.24:59744"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.6.24:59744 <http://192.168.6.24:59744>] s[ipv4:* MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:53" **MailScanner warning: numerical links are often
>> malicious:* 192.168.1.20:53 <http://192.168.1.20:53>] server_id[17848.41]
>>            ├─17849 samba: tfork waiter process
>>            ├─17850 /usr/sbin/winbindd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─17858 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─17859 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─17860 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─17863 winbindd: domain child [EMPRESA]
>>            ├─17864 winbindd: idmap child
>>            ├─18052 winbindd: domain child [BUILTIN]
>>            ├─18134 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─18135 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─19037 samba: conn[ldap] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van "192.168.1.17:43234"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.1.17:43234 <http://192.168.1.17:43234>] s[ipv4:* MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:389" **MailScanner warning: numerical links are often
>> malicious:* 192.168.1.20:389 <http://192.168.1.20:389>] server_id[19037]
>>            ├─19112 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            ├─19126 samba: conn[rpc] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van "192.168.1.76:60575"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.1.76:60575 <http://192.168.1.76:60575>] s[ipv4:* MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:49152" **MailScanner warning: numerical links are often
>> malicious:* 192.168.1.20:49152 <http://192.168.1.20:49152>]
>> server_id[19126]
>>            ├─19129 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>            └─19131 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #13
>> /usr/lib/x86_64-linux-gnu/libtevent.so.0(tevent_common_loop_wait+0x1b)
>> [0x7f2e4e7e949b]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #14 /usr/lib/x86_64-linux-gnu/libtevent.so.0(+0xaf77)
>> [0x7f2e4e7edf77]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #15
>> /usr/lib/x86_64-linux-gnu/samba/process_model/standard.so(+0x2261)
>> [0x7f2e498f6261]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #16
>> /usr/lib/x86_64-linux-gnu/samba/libservice.so.0(task_server_startup+0x5c)
>> [0x7f2e5ba90a0c]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #17
>> /usr/lib/x86_64-linux-gnu/samba/libservice.so.0(server_service_startup+0x96)
>> [0x7f2e5ba8f386]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #18 samba: task[rpc] standard worker(+0x57ad)
>> [0x55e4060187ad]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #19
>> /lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0xf1) [0x7f2e4d2702e1]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]:    #20 samba: task[rpc] standard worker(_start+0x2a)
>> [0x55e406016e4a]
>> ago 30 11:03:11 samba4-dc1 samba[17835]: task[dcesrv][17835]: [2019/08/30
>> 11:03:11.847514,  0]
>> ../../source4/smbd/process_standard.c:160(standard_child_pipe_handler)
>> ago 30 11:03:11 samba4-dc1 samba[17835]: task[dcesrv][17835]:
>> standard_child_pipe_handler: Child 18438 () terminated with signal 6
>>
>>
>> I thought the option to raise the Forest functional level to Windows
>> Server 2012 would now be available, but it isn't.
>>
>> Is this normal ?
>>
>> Regards,
>>
>> Márcio Bacci
>>
>> Em sex, 30 de ago de 2019 às 09:23, L.P.H. van Belle <belle at bazuin.nl>
>> escreveu:
>>
>>> 
>>> Yes, you can transfer the roles, but personaly, i never do that.
>>> I upgrade as is, everything looks good atm, so i dont think moving roles
>>> is really needed.
>>>
>>>
>>> Greetz,
>>>
>>> Louis
>>>
>>>
>>>
>>> ------------------------------
>>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>>> *Verzonden:* vrijdag 30 augustus 2019 14:07
>>> *Aan:* L.P.H. van Belle
>>> *CC:* samba at lists.samba.org
>>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>>
>>> Hi,
>>>
>>> I was able to update.
>>>
>>> Apparently everything is OK.
>>>
>>> Is it safe to transfer FSMO rols to DC2 (samba 4.10.7) to upgrade DC1
>>> (Samba 4.5.16)?
>>>
>>> Below are the tests I did:
>>>
>>> Checking smb.conf with testparm
>>> Load smb config files from /etc/samba/smb.conf
>>> Loaded services file OK.
>>> Server role: ROLE_ACTIVE_DIRECTORY_DC
>>>
>>> Done
>>> Checking smb.conf with samba-tool
>>> INFO 2019-08-30 08:46:53,674 pid:6665
>>> /usr/lib/python3/dist-packages/samba/netcmd/testparm.py #96: Loaded smb
>>> config files from /etc/samba/smb.conf
>>> INFO 2019-08-30 08:46:53,675 pid:6665
>>> /usr/lib/python3/dist-packages/samba/netcmd/testparm.py #97: Loaded
>>> services file OK.
>>> Done
>>> Setting up winbind (2: 4.10.7-0.1 ~ deb9) ...
>>> Samba is being run as an AD Domain Controller: Masking winbind.service
>>> Please ignore the following error about deb-systemd-helper not finding
>>> those services.
>>> (winbind.service already masked)
>>> Setting up samba (2: 4.10.7-0.1 ~ deb9) ...
>>> Samba is being run as an AD Domain Controller: Masking smbd.service
>>> nmbd.service
>>> Please ignore the following error about deb-systemd-helper not finding
>>> those services.
>>> (smbd.service already masked)
>>> (nmbd.service already masked)
>>> Processing triggers for libc-bin (2.24-11 + deb9u4) ...
>>>
>>> root at samba4-dc2:~# samba -V
>>> Version 4.10.7-Debian
>>>
>>>
>>> root at samba4-dc2:~# systemctl status samba-ad-dc
>>> ● samba-ad-dc.service - Samba AD Daemon
>>>    Loaded: loaded (/lib/systemd/system/samba-ad-dc.service; enabled;
>>> vendor preset: enabled)
>>>    Active: active (running) since Fri 2019-08-30 08:48:26 -03; 21s ago
>>>      Docs: man:samba(8)
>>>            man:samba(7)
>>>            man:smb.conf(5)
>>>  Main PID: 6992 (samba)
>>>    Status: "smbd: ready to serve connections..."
>>>     Tasks: 23 (limit: 4915)
>>>    CGroup: /system.slice/samba-ad-dc.service
>>>            ├─6992 samba: root process
>>>            ├─6993 samba: task[s3fs_parent]
>>>            ├─6994 samba: task[dcesrv]
>>>            ├─6995 samba: task[nbtd]
>>>            ├─6996 samba: task[wrepl]
>>>            ├─6997 samba: task[ldapsrv]
>>>            ├─6998 samba: tfork waiter process
>>>            ├─6999 samba: task[cldapd]
>>>            ├─7000 samba: conn[kdc_tcp] c[ipv4:* MailScanner heeft een
>>> e-mail met mogelijk een poging tot fraude gevonden van
>>> "192.168.91.14:59442" **MailScanner warning: numerical links are often
>>> malicious:* 192.168.91.14:59442 <http://192.168.91.14:59442>] s[ipv4:*
>>> MailScanner heeft een e-mail met mogelijk een poging tot fraude gevonden
>>> van "192.168.1.22:88" **MailScanner warning: numerical links are often
>>> malicious:* 192.168.1.22:88 <http://192.168.1.22:88>] server_id[7000.40]
>>>            ├─7001 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>>            ├─7002 samba: task[dreplsrv]
>>>            ├─7003 samba: task[winbindd_parent]
>>>            ├─7004 samba: task[ntp_signd]
>>>            ├─7005 samba: task[kccsrv]
>>>            ├─7006 samba: task[dnsupdate]
>>>            ├─7007 samba: task[dns]
>>>            ├─7008 samba: tfork waiter process
>>>            ├─7009 /usr/sbin/winbindd -D --option=server role
>>> check:inhibit=yes --foreground
>>>            ├─7017 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>>            ├─7018 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>>            ├─7019 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>>            ├─7022 winbindd: domain child [EMPRESA]
>>>            └─7023 winbindd: idmap child
>>>
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873694,  0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'http_ntlm' registered
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873741,  0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'http_negotiate' registered
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873788,  0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'krb5' registered
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873837,  0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'fake_gssapi_krb5' registered
>>> ago 30 08:48:40 samba4-dc2 samba[7005]: task[kccsrv][7005]: [2019/08/30
>>> 08:48:40.887442,  0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:40 samba4-dc2 samba[7005]: task[kccsrv][7005]:
>>> /usr/sbin/samba_kcc: ldb_wrap open of secrets.ldb
>>>
>>>
>>> root at samba4-dc2:~# samba-tool drs showrepl
>>> ldb_wrap open of secrets.ldb
>>> GENSEC backend 'gssapi_spnego' registered
>>> GENSEC backend 'gssapi_krb5' registered
>>> GENSEC backend 'gssapi_krb5_sasl' registered
>>> GENSEC backend 'spnego' registered
>>> GENSEC backend 'schannel' registered
>>> GENSEC backend 'naclrpc_as_system' registered
>>> GENSEC backend 'sasl-EXTERNAL' registered
>>> GENSEC backend 'ntlmssp' registered
>>> GENSEC backend 'ntlmssp_resume_ccache' registered
>>> GENSEC backend 'http_basic' registered
>>> GENSEC backend 'http_ntlm' registered
>>> GENSEC backend 'http_negotiate' registered
>>> GENSEC backend 'krb5' registered
>>> GENSEC backend 'fake_gssapi_krb5' registered
>>> Using binding ncacn_ip_tcp:samba4-dc2.empresa.com.br[,seal]
>>> resolve_lmhosts: Attempting lmhosts lookup for name
>>> samba4-dc2.empresa.com.br<0x20>
>>> resolve_lmhosts: Attempting lmhosts lookup for name
>>> samba4-dc2.empresa.com.br<0x20>
>>> resolve_lmhosts: Attempting lmhosts lookup for name
>>> samba4-dc2.empresa.com.br<0x20>
>>> Default-First-Site-Name\SAMBA4-DC2
>>> DSA Options: 0x00000001
>>> DSA object GUID: 45b5b534-9bcc-483c-8f6d-5bbc37dc35e9
>>> DSA invocationId: f621cfd8-7f92-48be-84d9-daa14ef20c05
>>>
>>> ==== INBOUND NEIGHBORS ====
>>>
>>> DC=ForestDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:48:40 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:48:40 2019 -03
>>>
>>> CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:48:40 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:48:40 2019 -03
>>>
>>> DC=DomainDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:50:16 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:50:16 2019 -03
>>>
>>> CN=Schema,CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:48:40 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:48:40 2019 -03
>>>
>>> DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:50:36 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:50:36 2019 -03
>>>
>>> ==== OUTBOUND NEIGHBORS ====
>>>
>>> DC=ForestDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> DC=DomainDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> CN=Schema,CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> ==== KCC CONNECTION OBJECTS ====
>>>
>>> Connection --
>>> Connection name: 3135cf0d-0109-4a40-be6f-44e1eca5b5d2
>>> Enabled        : TRUE
>>> Server DNS name : samba4-dc1.empresa.com.br
>>> Server DN name  : CN=NTDS
>>> Settings,CN=SAMBA4-DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=empresa,DC=com,DC=br
>>> TransportType: RPC
>>> options: 0x00000001
>>> Warning: No NC replicated for Connection!
>>>
>>>
>>>
>>> root at samba4-dc2:~# samba-tool ldapcmp ldap://SAMBA4-DC1
>>> ldap://SAMBA4-DC2 -UAdministrator
>>> resolve_lmhosts: Attempting lmhosts lookup for name SAMBA4-DC1<0x20>
>>> GENSEC backend 'gssapi_spnego' registered
>>> GENSEC backend 'gssapi_krb5' registered
>>> GENSEC backend 'gssapi_krb5_sasl' registered
>>> GENSEC backend 'spnego' registered
>>> GENSEC backend 'schannel' registered
>>> GENSEC backend 'naclrpc_as_system' registered
>>> GENSEC backend 'sasl-EXTERNAL' registered
>>> GENSEC backend 'ntlmssp' registered
>>> GENSEC backend 'ntlmssp_resume_ccache' registered
>>> GENSEC backend 'http_basic' registered
>>> GENSEC backend 'http_ntlm' registered
>>> GENSEC backend 'http_negotiate' registered
>>> GENSEC backend 'krb5' registered
>>> GENSEC backend 'fake_gssapi_krb5' registered
>>> Password for [EMPRESA\Administrador]:
>>> resolve_lmhosts: Attempting lmhosts lookup for name SAMBA4-DC2<0x20>
>>>
>>> * Comparing [DOMAIN] context...
>>>
>>> * Objects to be compared: 1869
>>>
>>> * Result for [DOMAIN]: SUCCESS
>>>
>>> * Comparing [CONFIGURATION] context...
>>>
>>> * Objects to be compared: 1640
>>>
>>> * Result for [CONFIGURATION]: SUCCESS
>>>
>>> * Comparing [SCHEMA] context...
>>>
>>> * Objects to be compared: 1518
>>>
>>> * Result for [SCHEMA]: SUCCESS
>>>
>>> * Comparing [DNSDOMAIN] context...
>>>
>>> * Objects to be compared: 565
>>>
>>> * Result for [DNSDOMAIN]: SUCCESS
>>>
>>> * Comparing [DNSFOREST] context...
>>>
>>> * Objects to be compared: 31
>>>
>>> * Result for [DNSFOREST]: SUCCESS
>>>
>>> Regards,
>>>
>>> Márcio Bacci
>>>
>>> Em sex, 30 de ago de 2019 às 08:44, L.P.H. van Belle <belle at bazuin.nl>
>>> escreveu:
>>>
>>>> No, thats also correct.
>>>>
>>>> Because in 4.10 new packages are added and removed.
>>>>
>>>> you need to run : apt-get dist-upgrade
>>>>
>>>> Small note, i always run : apt-get dist-upgrade -y
>>>> -dy , download and yes.
>>>>
>>>> then run : apt-get dist-upgrade -y
>>>>
>>>> that makes sure you always have all the needed packages on you server
>>>> before you upgrade.
>>>>
>>>> Greetz,
>>>>
>>>> Louis
>>>>
>>>>
>>>> ------------------------------
>>>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>>>> *Verzonden:* vrijdag 30 augustus 2019 13:40
>>>> *Aan:* L.P.H. van Belle
>>>> *CC:* samba at lists.samba.org
>>>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>>>
>>>> Hi,
>>>>
>>>> Really, version 4.9-12 solved the DBCHECK problem.
>>>>
>>>> Apparently, in version 4.9-12 everything is OK, just not being able to
>>>> upgrade to version 4.10, as follows:
>>>>
>>>> Reading package lists ... Ready
>>>> Building dependency tree
>>>> Reading status info ... Ready
>>>> 10 packages can be upgraded. Run 'apt list --upgradable' to see them.
>>>> Reading package lists ... Ready
>>>> Building dependency tree
>>>> Reading status info ... Ready
>>>> Calculating update ... Ready
>>>> The following packages have been installed automatically and are no
>>>> longer required:
>>>>    libfile-copy-recursive-perl update-inetd
>>>> Use 'apt autoremove' to remove them.
>>>> The following packages will be kept in their current versions:
>>>>    libldb1 libwbclient0 samba samba common samba common bin samba dsdb
>>>> modules samba libs samba vfs modules winbind
>>>> 0 updated packages, 0 new packages installed, 0 to be removed and 9 not
>>>> updated.
>>>>
>>>> I'm using Debian 9.9.
>>>>
>>>> Regards,
>>>>
>>>> Márcio Bacci
>>>>
>>>> Em sex, 30 de ago de 2019 às 06:51, L.P.H. van Belle <belle at bazuin.nl>
>>>> escreveu:
>>>>
>>>>> Hai,
>>>>>
>>>>> You can safely ignore that mesage.
>>>>>
>>>>> If both servers are done and running 4.8.  procede to 4.9
>>>>>
>>>>> >> ERROR(<type 'exceptions.KeyError'>): uncaught exception - 'No such
>>>>> element'
>>>>> is fixed in later samba versions
>>>>>
>>>>> Greetz,
>>>>>
>>>>> Louis
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> ------------------------------
>>>>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>>>>> *Verzonden:* vrijdag 30 augustus 2019 11:39
>>>>> *Aan:* L.P.H. van Belle
>>>>> *CC:* samba at lists.samba.org
>>>>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>>>>
>>>>> Hi,
>>>>>
>>>>> I upgraded to Samba 4.8-12 as follows:
>>>>>
>>>>> Checking smb.conf with testparm
>>>>> Load smb config files from /etc/samba/smb.conf
>>>>> Loaded services file OK.
>>>>> Server role: ROLE_ACTIVE_DIRECTORY_DC
>>>>>
>>>>> Done
>>>>> Checking smb.conf with samba-tool
>>>>> Done
>>>>> Configurando samba-dsdb-modules:amd64 (2:4.8.12-1~deb9) ...
>>>>> Configurando winbind (2:4.8.12-1~deb9) ...
>>>>> Instalando nova versão do arquivo de configuração /etc/init.d/winbind
>>>>> ...
>>>>> Instalando nova versão do arquivo de configuração
>>>>> /etc/logrotate.d/winbind ...
>>>>> Samba is being run as an AD Domain Controller: Masking winbind.service
>>>>> Please ignore the following error about deb-systemd-helper not finding
>>>>> those services.
>>>>> (winbind.service masked)
>>>>> Removing obsolete conffile /etc/init/winbind.conf ...
>>>>> Configurando samba (2:4.8.12-1~deb9) ...
>>>>> Instalando nova versão do arquivo de configuração /etc/init.d/nmbd ...
>>>>> Instalando nova versão do arquivo de configuração
>>>>> /etc/init.d/samba-ad-dc ...
>>>>> Instalando nova versão do arquivo de configuração /etc/init.d/smbd ...
>>>>> Instalando nova versão do arquivo de configuração
>>>>> /etc/logrotate.d/samba ...
>>>>> Samba is being run as an AD Domain Controller: Masking smbd.service
>>>>> nmbd.service
>>>>> Please ignore the following error about deb-systemd-helper not finding
>>>>> those services.
>>>>> (smbd.service masked)
>>>>> (nmbd.service masked)
>>>>> Removing obsolete conffile /etc/init.d/samba ...
>>>>> Removing obsolete conffile /etc/init/nmbd.conf ...
>>>>> Removing obsolete conffile /etc/init/reload-smbd.conf ...
>>>>> Removing obsolete conffile /etc/init/samba-ad-dc.conf ...
>>>>> Removing obsolete conffile /etc/init/smbd.conf ...
>>>>> A processar 'triggers' para libc-bin (2.24-11+deb9u4) ...
>>>>> A processar 'triggers' para systemd (232-25+deb9u11) ...
>>>>>
>>>>> Replication looks OK (samba-tool drs showrepl), but dbcheck does not.
>>>>>
>>>>> samba-tool dbcheck --cross-ncs
>>>>> ERROR(<type 'exceptions.KeyError'>): uncaught exception - 'No such
>>>>> element'
>>>>>   File "/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py",
>>>>> line 177, in _run
>>>>>     return self.run(*args, **kwargs)
>>>>>   File "/usr/lib/python2.7/dist-packages/samba/netcmd/dbcheck.py",
>>>>> line 142, in run
>>>>>     check_expired_tombstones=selftest_check_expired_tombstones)
>>>>>   File "/usr/lib/python2.7/dist-packages/samba/dbchecker.py", line
>>>>> 200, in __init__
>>>>>     self.tombstoneLifetime = int(res[0]["tombstoneLifetime"][0])
>>>>>
>>>>> Regards,
>>>>>
>>>>> Márcio Bacci
>>>>>
>>>>> Em sex, 30 de ago de 2019 às 06:18, L.P.H. van Belle via samba <
>>>>> samba at lists.samba.org> escreveu:
>>>>>
>>>>>> Hai,
>>>>>>
>>>>>> No, keep everything as is.
>>>>>>
>>>>>> Since your upgrading from 4.5 ( and this is probely why your upgrade
>>>>>> to 4.7 broke )
>>>>>> Make sure you settings are respecting config requirements of 4.8.
>>>>>>
>>>>>> If you do hit an error.
>>>>>> Read : http://downloads.van-belle.nl/samba4/Upgrade-info.txt
>>>>>> And if needed mail the list, im buzy with some servers atm, but i'll
>>>>>> keep an eye on the list.
>>>>>>
>>>>>>
>>>>>> Greetz,
>>>>>>
>>>>>> Louis
>>>>>>
>>>>>>
>>>>>>
>>>>>> > -----Oorspronkelijk bericht-----
>>>>>> > Van: samba [mailto:samba-bounces at lists.samba.org] Namens
>>>>>> > Marcio Demetrio Bacci via samba
>>>>>> > Verzonden: vrijdag 30 augustus 2019 11:13
>>>>>> > Aan: sambalist
>>>>>> > Onderwerp: [Samba] Upgrade Samba 4
>>>>>> >
>>>>>> > Hi,
>>>>>> >
>>>>>> > To upgrade my secondary DC Samba 4.5-16 to 4.8 should I
>>>>>> > remove the smb.conf
>>>>>> > file in /etc/samba first? I remember I tried last month to
>>>>>> > upgrade from
>>>>>> > 4.5-16 to 4.7 and broke the installation.
>>>>>> >
>>>>>> > Or are just the procedures below enough?
>>>>>> >
>>>>>> > Create this file repo file for apt.
>>>>>> > echo "deb http://apt.van-belle.nl/debian stretch-samba48 main
>>>>>> contrib
>>>>>> > non-free" | sudo tee -a /etc/apt/sources.list.d/van-belle.list
>>>>>> >
>>>>>> > Import my key.
>>>>>> > wget -O - http://apt.van-belle.nl/louis-van-belle.gpg-key.asc
>>>>>> > | apt-key add
>>>>>> > -
>>>>>> >
>>>>>> > apt update -y && apt upgrade -y
>>>>>> > Remove the 4.8 line from the repo, enable 4.9 repeat apt update &&
>>>>>> apt
>>>>>> > upgrade
>>>>>> > systemctl stop samba-ad-dc && systemctl start samba-ad-dc
>>>>>> >
>>>>>> > Then I will upgrade to 4.9 and 4.10.
>>>>>> >
>>>>>> > If all goes well, I'll do it for DC Samba 4 Master.
>>>>>> >
>>>>>> > Regards,
>>>>>> >
>>>>>> > Márcio Bacci
>>>>>> > --
>>>>>> > To unsubscribe from this list go to the following URL and read the
>>>>>> > instructions:  https://lists.samba.org/mailman/options/samba
>>>>>> >
>>>>>> >
>>>>>>
>>>>>>
>>>>>> --
>>>>>> To unsubscribe from this list go to the following URL and read the
>>>>>> instructions:  https://lists.samba.org/mailman/options/samba
>>>>>>
>>>>>


More information about the samba mailing list