[Samba] Upgrade old infrastructure running 4.3 (and 4.13)

Lorenzo Milesi lorenzo.milesi at yetopen.com
Wed Sep 1 15:16:56 UTC 2021


> I hope this helps you out.

Thank you very much for the detailed explaination!

I'm just wondering, what's the purpose of seizing fsmo roles and then do step upgrades of Samba? Once it's cut off, I can delete everything, install 4.14 straight and join it back as suggested here[1].

As per OS I need to remain on Ubuntu 18.04 as there's another application which doesn't support 20.04. So I was going to use LinuxSchools PPA [2].

What concerns me the most is the head note of the upgrade page, given I'm currently on 4.3:
You should only consider using this method if you are running a modern Samba installation (i.e. v4.7 release or later, with a minimum 2008R2 base schema). It is better to use this method for major Samba version upgrades (e.g. v4.10 to v4.11).
My schema is ok (47), but the version is not.

Two further notes:
1. dbcheck returns no error on 4.3, while on 4.13 shows:
root at landc:~# samba-tool dbcheck --cross-ncs
Checking 3534 objects
NOTE: old (due to rename or delete) DN string component for fromServer in object CN=5ba66c59-f19c-4b5d-b565-3ff8d03c6562,CN=NTDS Settings,CN=LANDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=lan - CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=lan
Not fixing old string component
NOTE: old (due to rename or delete) DN string component for fSMORoleOwner in object CN=Infrastructure,DC=DomainDnsZones,DC=contoso,DC=lan - CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=lan
Not fixing old string component
NOTE: old (due to rename or delete) DN string component for fSMORoleOwner in object CN=Infrastructure,DC=ForestDnsZones,DC=contoso,DC=lan - CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=lan
Not fixing old string component
Checked 3534 objects (0 errors)
2. transfering roles throws an error (as I wrote in the first email), is seizing them "safer"? :)

Thanks again

[1] https://wiki.samba.org/index.php/Upgrading_a_Samba_AD_DC
[2] https://launchpad.net/~linux-schools/+archive/ubuntu/samba-latest
-- 
Lorenzo Milesi - lorenzo.milesi at yetopen.com 
CTO @ YetOpen Srl

YetOpen - https://www.yetopen.com/

Via Salerno 18 - 23900 Lecco - ITALY -      | 4801 Glenwood Avenue - Suite 200 - Raleigh, NC 27612 - USA -
Tel +39 0341 220 205 - info.it at yetopen.com  | Phone +1 919-817-8106 - info.us at yetopen.com

Think green - Non stampare questa e-mail se non necessario / Don't print this email unless necessary

-------- D.Lgs. 196/2003 e GDPR 679/2016 --------
Tutte le informazioni contenute in questo messaggio sono riservate ed a uso esclusivo del destinatario.
Tutte le informazioni ivi contenute, compresi eventuali allegati, sono da ritenere confidenziali e riservate secondo i termini
del vigente D.Lgs. 196/2003 in materia di privacy e del Regolamento europeo 679/2016 - GDPR - e quindi ne e' proibita l'utilizzazione ulteriore non autorizzata.
Nel caso in cui questo messaggio Le fosse pervenuto per errore, La invitiamo ad eliminarlo senza copiarlo, stamparlo, a non inoltrarlo a terzi e ad avvertirci non appena possibile.
Grazie.

Confidentiality notice: this email message including any attachment is for the sole use of the intended recipient and may contain confidential and privileged information;
pursuant to Legislative Decree 196/2003 and the European General Data Protection Regulation 679/2016 - GDPR - any unauthorized review, use, disclosure or distribution
is prohibited. If you are not the intended recepient please delete this message without copying, printing or forwarding it to others, and alert us as soon as possible.
Thank you.




More information about the samba mailing list