Re: Samba AD DC Upgrade and IP address management

Luis Peromarta via samba <[email protected]> Fri, 8 May 2026 23:31:01 +0100
Newsgroups gmane.network.samba.general
Message-ID <00f4a879-ced1-4cc8-b9bd-e9e1d21afac2@Spark>
When you snapshot make sure both DCs are powered off at the same time to avoid replication problems
On 8 May 2026 at 22:15 +0100, Jonathan Kreider via samba <[email protected]>, wrote:
> Hi Luis,
>
> Thanks for the confirmation and the clear steps. I have my DCs in
> containers at this point. I can still snap shot them for backups.
>
> This gives me the confidence to proceed.
>
> - Jonathan
>
> On Fri, May 8, 2026 at 2:34 PM Luis Peromarta via samba <
> [email protected]> wrote:
>
> > If you are using VMs, the task becomes much simpler because you can take
> > snapshots and roll back at any stage if something goes wrong. That gives
> > you a very safe migration path.
> >
> > My recommendation would be:
> >
> > 1. Identify the DC that does NOT hold the FSMO roles and demote that DC
> > first.
> > 2. Take a full backup and VM snapshot before starting.
> > 3. Deploy a new Debian 13 VM.
> > 4. Install Samba and join it to the existing domain as a DC. Use same name
> > and same IP as previous DC
> > 5. Verify replication, DNS, SYSVOL, and authentication are all working
> > correctly.
> >
> >
> > Once the first new Debian 13 DC is confirmed healthy:
> >
> > 7. Transfer the FSMO roles to the new Debian 13 DC.
> > 8. Demote the remaining legacy DC.
> > 9. Deploy a second Debian 13 VM and join it as an additional DC.
> > 10. Verify replication and domain health again.
> >
> > The biggest advantage of using VMs is that snapshots and backups give you
> > a proper safety net, If something breaks badly.
> >
> > I documented a very similar Samba AD migration and deployment approach
> > here:
> >
> > samba.bigbird.es
> > On 8 May 2026 at 14:15 +0100, Jonathan Kreider via samba <
> > [email protected]>, wrote:
> > > > Greetings all,
> > > >
> > > > I've been a faithful reader of this list for about the last 5 years, but
> > I
> > > > can't remember or find a post that answers my current question.
> > > >
> > > > I'm needing to upgrade my Samba AD DCs so I can join Windows 11 PCs to
> > the
> > > > domain. Since my DCs are older versions 4.10.x, so I have started by
> > > > spinning up a Debian 13.4 instance with Samba 4.22.8 AD DC and joining
> > that
> > > > to my existing domain. samba-tool drs showrepl indicates all is well.
> > > >
> > > > Now I need to upgrade or replace the two original AD DCs. I understand
> > that
> > > > once I get all the servers replaced I will need to upgrade the schema to
> > > > 2016 to keep Windows 11 happy. Also, once I get that done, I intend to
> > > > setup debian backports so I can get the most recent versions of samba.
> > > >
> > > > Since my network is small - I have everything on a /24 subnet - and all
> > my
> > > > PCs use the samba servers as their DNS servers, I'd like to continue
> > using
> > > > the same IP addresses for the replacement AD DCs that I've been using. Is
> > > > that possible? I seem to recall some warnings about that.
> > > >
> > > > Can I demote a DC, delete the VM/container and replace it with a new one
> > > > with the same name and IP address and rejoin it to the domain? If so,
> > what
> > > > precautions do I need to take.
> > > >
> > > > Thanks,
> > > > Jonathan Kreider
> > > > --
> > > > To unsubscribe from this list go to the following URL and read the
> > > > instructions: https://lists.samba.org/mailman/options/samba
> > --
> > To unsubscribe from this list go to the following URL and read the
> > instructions: https://lists.samba.org/mailman/options/samba
> >
> --
> To unsubscribe from this list go to the following URL and read the
> instructions: https://lists.samba.org/mailman/options/samba
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba