[Samba] Setting up Backup AD DC

Rowland penny rpenny at samba.org
Fri Oct 30 18:43:56 UTC 2020


On 30/10/2020 17:59, Michal Bruncko via samba wrote:
> hello
>
> out of curiosity as I wanted to achieve this some time before - i.e. 
> to performing automated backup od samba domain.
>
> now I've tried to use kerberos - for online backup (within script) I 
> have used:
>
> samba-tool domain backup online --targetdir=${BACKUPDIR} 
> --server=${DCSERVER} --krb5-ccache=${KRB5CCNAME}
>
> but seems this is not working as the backup process is interruped in 
> the middle and I am challenged to authenticate:
>
> samba-tool domain backup online --targetdir=/var/spool/backup/ 
> --server=DC1 --krb5-ccache=/tmp/samba-domain.cc

Yes, it appears that the kerberos creds either aren't being used or are 
insufficient when it comes to creating a tarball of Sysvol (it is 
created from the sysvol share). I have been toying with the idea of 
making the script only backup the DC it is running on and just create a 
tarball from what is on disk.

I also found that if you use an admin username and password, it works, 
so it looks very much like a kerberos problem.

Rowland





More information about the samba mailing list