[Samba] questions regarding the Demoting an Offline Domain Controller procedure

Jean-Louis Biasini jl.biasini at laposte.net
Wed Jul 6 12:15:44 UTC 2022

hi all,

I have questions regarding a DC that I had to demote following the 
Demoting an Offline Domain Controller procedure from here 

1. The procedure went well and no other problems occured, but since then 
I have the following popping up in the log of all the remaining DCs at 

dns_delete_tombstones: A tombstoned dnsNode has non-tombstoned records, 
which should not happen.

How can I find and delete those remaining record? I don’t see anything 
related to the demoted DC with rsat DNS tool nor with:

ldbsearch -H /usr/local/samba/private/sam.ldb '(invocationId=*)' --cross-ncs objectguid

2. the procedure states that I shouldn’t reconnect et demoted offline 
dc, does this apply only to that specific machine? Can I declare a new 
dc with the same name and/or ip and/or mac address (VM) or should this 
also be avoided?

samba is Version 4.15.8 on Centos7 with bind dlz as dns backend

many thanks


