[Samba] Upgrading samba DC with "DC Rejoin" fails "Failed to setup database for BIND, AD based DNS cannot be used"

Rowland Penny rpenny at samba.org
Wed Dec 8 19:32:01 UTC 2021


On Wed, 2021-12-08 at 20:09 +0100, Henning Kessler via samba wrote:
> Hello
> 
> I tried to upgrade one of my lab domain controlers running raspbian
> buster with samba (Version 4.9.5-Debian) to Raspbian Bullseye with
> samba Version 4.13.13-Debian. I tried to follow the wiki article (
> https://wiki.samba.org/index.php/Upgrading_a_Samba_AD_DC#Rejoining_the_upgraded_DC
> ) as close as possible and tried the "DC rejoin" approach as I am
> upgrading over several major releases. 
> 
> Unfortunately the rejoining failed 
> 
> sudo samba-tool domain join DOMAIN.int DC -U"DOMAIN\administrator" --
> dns-backend=BIND9_DLZ:
> 
> INFO 2021-12-08 16:55:22,835 pid:4874 /usr/lib/python3/dist-
> packages/samba/join.py #107: Finding a writeable DC for domain
> 'DOMAIN.int'
> INFO 2021-12-08 16:55:22,874 pid:4874 /usr/lib/python3/dist-
> packages/samba/join.py #109: Found DC dc01.DOMAIN.int
> Password for [DOMAIN\administrator]:
> INFO 2021-12-08 16:55:29,005 pid:4874 /usr/lib/python3/dist-
> packages/samba/join.py #1543: workgroup is DOMAIN
> INFO 2021-12-08 16:55:29,006 pid:4874 /usr/lib/python3/dist-
> packages/samba/join.py #1546: realm is DOMAIN.int
> Adding CN=DC02,OU=Domain Controllers,DC=DOMAIN,DC=de

You are using 'DOMAIN.int' as the dns domain, but your default naming
context is 'DC=DOMAIN,DC=de', which would mean a dns domain of
'DOMAIN.de', was this a typo ?

If it was, did you demote the old DC before trying to re-add it ?

Rowland





More information about the samba mailing list