[Samba] Transferring fsmo roles to new DC2

Rowland Penny rpenny at samba.org
Mon Jan 16 10:43:40 UTC 2023



On 16/01/2023 10:16, Callum G. MacEwan via samba wrote:
> Hi Team
> 
> I am transferring to a new AD DC
> 
> So I started transferring the fsmo roles the first five transferred fine 
> the domaindns and forestdns had the following error!
> 
> root at DC2:/etc/sudoers.d#  samba-tool fsmo transfer --role=forestdns 
> -UAdministrator
> Password for [BALEWAN\Administrator]:
> ERROR: Failed to add role 'forestdns': LDAP error 16 
> LDAP_NO_SUCH_ATTRIBUTE -  <attribute 'fSMORoleOwner': no matching 
> attribute value while deleting attribute on 
> 'CN=Infrastructure,DC=ForestDnsZones,DC=balewan,DC=pegasusnz,DC=com'> <>
> 
> What's the best thing to resolve this? seize the roles perhaps?
> 
> Thanks
> 
> Callum
> 

Yes, probably, but why are they not there ?
I think you need to give us a bit more info:
What OS
What version of Samba
Are you using Bind9
How was the domain provisioned

If you run this on the DC:

ldbsearch --cross-ncs -H /var/lib/samba/private/sam.ldb -b 
DC=DomainDnsZones,DC=balewan,DC=pegasusnz,DC=com '(cn=Infrastructure)'

Does it shown the 'fSMORoleOwner' attribute ?

Rowland



More information about the samba mailing list