Re: Samba AD DC Upgrade and IP address management
Luis Peromarta via samba <[email protected]> Fri, 8 May 2026 19:07:32 +0100
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <9a8343c7-2163-4373-b0e8-1f4570ed254d@Spark> |
If you are using VMs, the task becomes much simpler because you can take snapshots and roll back at any stage if something goes wrong. That gives you a very safe migration path. My recommendation would be: 1. Identify the DC that does NOT hold the FSMO roles and demote that DC first. 2. Take a full backup and VM snapshot before starting. 3. Deploy a new Debian 13 VM. 4. Install Samba and join it to the existing domain as a DC. Use same name and same IP as previous DC 5. Verify replication, DNS, SYSVOL, and authentication are all working correctly. Once the first new Debian 13 DC is confirmed healthy: 7. Transfer the FSMO roles to the new Debian 13 DC. 8. Demote the remaining legacy DC. 9. Deploy a second Debian 13 VM and join it as an additional DC. 10. Verify replication and domain health again. The biggest advantage of using VMs is that snapshots and backups give you a proper safety net, If something breaks badly. I documented a very similar Samba AD migration and deployment approach here: samba.bigbird.es On 8 May 2026 at 14:15 +0100, Jonathan Kreider via samba <[email protected]>, wrote: > Greetings all, > > I've been a faithful reader of this list for about the last 5 years, but I > can't remember or find a post that answers my current question. > > I'm needing to upgrade my Samba AD DCs so I can join Windows 11 PCs to the > domain. Since my DCs are older versions 4.10.x, so I have started by > spinning up a Debian 13.4 instance with Samba 4.22.8 AD DC and joining that > to my existing domain. samba-tool drs showrepl indicates all is well. > > Now I need to upgrade or replace the two original AD DCs. I understand that > once I get all the servers replaced I will need to upgrade the schema to > 2016 to keep Windows 11 happy. Also, once I get that done, I intend to > setup debian backports so I can get the most recent versions of samba. > > Since my network is small - I have everything on a /24 subnet - and all my > PCs use the samba servers as their DNS servers, I'd like to continue using > the same IP addresses for the replacement AD DCs that I've been using. Is > that possible? I seem to recall some warnings about that. > > Can I demote a DC, delete the VM/container and replace it with a new one > with the same name and IP address and rejoin it to the domain? If so, what > precautions do I need to take. > > Thanks, > Jonathan Kreider > -- > To unsubscribe from this list go to the following URL and read the > instructions: https://lists.samba.org/mailman/options/samba -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba