Re: Backing up a Windows AD DC with samba-tool
Rowland Penny via samba <[email protected]> Wed, 8 Apr 2026 11:25:38 +0100
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 8 Apr 2026 09:42:41 +0000 itdept_head via samba <[email protected]> wrote: > I should clarify a few things: > > "master" is where we generally make changes: No, I think you mean the DC that holds the FSMO roles and you can make changes on any DC. > "slave" is satellite offices. Again, I think you mean additional DCs and if the offices are in different locations, you may want to investigate 'sites'. > This is VM's Doesn't really matter if they are VMs or actual PCs, you should treat them the same. > > Going to disagree about the backup at any location. Why ? If the DCs are in sync (replication is working correctly), you can make changes on any DC, what RID the object gets will tell you what DC the object was created on. > > The AD's are not perfectly synced in the real world, we can see > delays of upto 5-10 minutes for changes to propagate... That is normal, accepted AD replication. > or in several cases... days. That isn't, I think you need to investigate this. > We have offices in some really distant > locations with really flaky connections, and very strict government > rules about what you can connect to (NTP) or equipment for time sync > (GPS), No satellite ,no starlink... AD relies on good replication, in my opinion, you really need to fix this. > > Tried just doing the database, and it always lead to problems, > specifically because , we found it does not deal with all aspects of > the complete AD. GPO's etc. 'samba-tool domain backup' should backup everything required, but there is nothing stopping you also backing up various conf files, however, as they should be virtually the same on all DCs, there isn't really a need to do this, you could just use templates. > > As regards "AD" all being the "same", only in a zero latency mind , > yes they all have the same rights, and they can all do the same > things, and in the ideal world they are identical but It's like > saying all the identical twins called "bob" in different geolocated > environments are the same. Depends if they are identical or fraternal twins, in AD terms, identical twins are the same, but one is holding a flag, fraternal twins just happened to be born at the same time, but are different. You should be aiming for identical twins. > > We don't have the luxury of cloud systems for storing the AD's nor > the guaranteed uptime of connections, we operate in an environment > where many things most people consider normal are considered > outright illegal by the governments plus some farmer digging up a > network connection can take 3 days to fix... So in our specific > situation we require a very structured way of working, communication > and systems are critical, because down time at a single location > costs tens of thousands a day. If you want to do it your way, I cannot stop you, all I can do is to point out the recommended Samba way of doing things. The thing about 'cloud systems' is, it is just another way of saying a server that isn't this server, it could be a server stood next to the AD server or it could be thousands of miles away. > > Sadly...sometimes you cannot always get exactly what you want and you > have to consider alternatives. Amen to that :-( Rowland -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba