[Samba] Replace primary DC

Rowland Penny rpenny at samba.org
Mon Apr 28 16:56:29 UTC 2025


On Mon, 28 Apr 2025 17:22:47 +0200
"Adnan R. via samba" <samba at lists.samba.org> wrote:

> Following this thread:
> https://lists.samba.org/archive/samba/2025-April/251400.html
> 
> We currently have 3 Samba (dc2, dc3, dc4) currently installed as
> secondaries for dc1, they are installed from debian 12 backports while
> dc1 is from a Turnkey Linux using an old version of samba, webmin,
> etc...
> 

No you haven't got a primary DC, you have 4 AD DCs (dc1, dc2, dc3 and
dc4), they are all equal and there is no such thing as a primary DC
(though one of them could hold all the FSMO roles, but it could be any
of them).

However your suggested method is sound.

> I'm thinking about reinstalling to homogenize the infra. Is this the
> right way to do it:
> - Transfer FSMO from dc1 to dc2 (or another), backing up idmap.ldb
> and sysvol
> - Demote and shutdown dc1, removing any leftovers from dc1 in LDAP
> and DNS
> - Reinstall dc1
> - Put back sysvol and idmap.ldb

The following is optional:

> - Transfer back FSMO to dc1

There is no real need to do this, did I say that the FSMO roles could
be on any DC ?

Rowland





More information about the samba mailing list