[Samba] accidentally upgraded DC to 4.17.3 ... didn't work

Stefan G. Weichinger lists at xunil.at
Thu Nov 24 10:12:39 UTC 2022

Am 24.11.22 um 10:32 schrieb Stefan G. Weichinger via samba:

> I might have to restart samba-ad-dc.service, but wait for feedback ...

couldn't wait anymore

restarting didn't help

decided to stop, demote adc1 from adc2 (offline demote) because online 
demoting fails:

root at adc1:~# samba-tool domain demote -U Administrator
Using adc2.arbeitsgruppe.my.tld as partner server for the demotion
Password for [ARBEITSGRUPPE\Administrator]:
Deactivating inbound replication
Asking partner server adc2.arbeitsgruppe.my.tld to synchronize from us
Error while replicating out last local changes from 
'CN=Schema,CN=Configuration,DC=arbeitsgruppe,DC=ikw-amstetten,DC=at' for 
demotion, re-enabling inbound replication
ERROR(<class 'samba.WERRORError'>): Error while sending a DsReplicaSync 
for partition 
'CN=Schema,CN=Configuration,DC=arbeitsgruppe,DC=ikw-amstetten,DC=at' - 
   File "/usr/lib/python3/dist-packages/samba/netcmd/domain.py", line 
860, in run
     drsuapiBind.DsReplicaSync(drsuapi_handle, 1, req1)

join succeeded, winbind still failing after that.

initally replication seems to work but fails soon after starting adc1

Maybe I have something wrong in AD now, some wrong objects or so?

"dbcheck" lists old components for ADC1, but no errors.

Help appreciated ...

More information about the samba mailing list