Re: Samba AD DC Upgrade and IP address management

Jonathan Kreider via samba <[email protected]> Fri, 8 May 2026 17:15:19 -0400
Newsgroups gmane.network.samba.general
Message-ID <CAFGmKYpv_WUWNAZ-W=ThyrA3Fvk3YCdA9xm0bHpNWGwOBCRBag@mail.gmail.com>
Hi Luis,

Thanks for the confirmation and the clear steps. I have my DCs in
containers at this point. I can still snap shot them for backups.

This gives me the confidence to proceed.

- Jonathan

On Fri, May 8, 2026 at 2:34 PM Luis Peromarta via samba <
[email protected]> wrote:

> If you are using VMs, the task becomes much simpler because you can take
> snapshots and roll back at any stage if something goes wrong. That gives
> you a very safe migration path.
>
> My recommendation would be:
>
> 1. Identify the DC that does NOT hold the FSMO roles and demote that DC
> first.
> 2. Take a full backup and VM snapshot before starting.
> 3. Deploy a new Debian 13 VM.
> 4. Install Samba and join it to the existing domain as a DC. Use same name
> and same IP as previous DC
> 5. Verify replication, DNS, SYSVOL, and authentication are all working
> correctly.
>
>
> Once the first new Debian 13 DC is confirmed healthy:
>
> 7. Transfer the FSMO roles to the new Debian 13 DC.
> 8. Demote the remaining legacy DC.
> 9. Deploy a second Debian 13 VM and join it as an additional DC.
> 10. Verify replication and domain health again.
>
> The biggest advantage of using VMs is that snapshots and backups give you
> a proper safety net, If something breaks badly.
>
> I documented a very similar Samba AD migration and deployment approach
> here:
>
> samba.bigbird.es
> On 8 May 2026 at 14:15 +0100, Jonathan Kreider via samba <
> [email protected]>, wrote:
> > Greetings all,
> >
> > I've been a faithful reader of this list for about the last 5 years, but
> I
> > can't remember or find a post that answers my current question.
> >
> > I'm needing to upgrade my Samba AD DCs so I can join Windows 11 PCs to
> the
> > domain. Since my DCs are older versions 4.10.x, so I have started by
> > spinning up a Debian 13.4 instance with Samba 4.22.8 AD DC and joining
> that
> > to my existing domain. samba-tool drs showrepl indicates all is well.
> >
> > Now I need to upgrade or replace the two original AD DCs. I understand
> that
> > once I get all the servers replaced I will need to upgrade the schema to
> > 2016 to keep Windows 11 happy. Also, once I get that done, I intend to
> > setup debian backports so I can get the most recent versions of samba.
> >
> > Since my network is small - I have everything on a /24 subnet - and all
> my
> > PCs use the samba servers as their DNS servers, I'd like to continue
> using
> > the same IP addresses for the replacement AD DCs that I've been using. Is
> > that possible? I seem to recall some warnings about that.
> >
> > Can I demote a DC, delete the VM/container and replace it with a new one
> > with the same name and IP address and rejoin it to the domain? If so,
> what
> > precautions do I need to take.
> >
> > Thanks,
> > Jonathan Kreider
> > --
> > To unsubscribe from this list go to the following URL and read the
> > instructions: https://lists.samba.org/mailman/options/samba
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba