[Samba] Migrate and Update (Samba 4.1 ADDC to Samba Latest Version on different Server).

Rowland Penny rpenny at samba.org
Thu Dec 1 18:12:14 UTC 2022

On 01/12/2022 17:28, Juan Ignacio wrote:
> Another thing I wonder about demoting the Original DC.
> The smb.conf files look different on the original DC than the new one.
> I would appreciate it if we could take a look before to know if there is 
> anything missing on the new DC, 

Doesn't look like it.

> I don't remember installing kerberos on 
> the new one which is now primary.

Will you please STOP referring to 'primary', there is no such thing as a 
primary DC, there are just AD DC's

  I don't know if it's necessary either.
> Looks like the smb.conf does not have all the services who are in the 
> original?

Your problem is that you waited too long between updates, 16 (if you are 
using the latest version of Samba) is a bit much, you should upgrade on 
a more regular basis.

If you run this command on the new DC:

testparm -vs 2>/dev/null | grep 'server services'

You should get this:

server services = s3fs, rpc, nbt, wrepl, ldap, cldap, kdc, drepl, 
winbindd, ntp_signd, kcc, dnsupdate, dns

The lack of the 'server services' line is the same as setting them all, 
this is because they are the defaults on a DC.

> Neither the idmap_ldb:use rfc2307 = yes

You have to explicitly add that line yourself, but it is only needed if 
you are using the 'ad' idmap backend on your Unix domain members and 
wish to have the same Unix ID's everywhere.


More information about the samba mailing list