Trouble transferring FSMO roles

Andrea Venturoli via samba <[email protected]> Wed, 8 Jul 2026 19:26:32 +0200
Newsgroups gmane.network.samba.general
Message-ID <[email protected]>
Hello.

At a customer's site, there's a Windows 2008 server acting as the only 
AD DC.
Of course I want to get rid of this ASAP.

I set up a new Samba 4.23.8 AD DC which has been working for a couple of 
days.
Now I'm trying to transfer FSMO roles and I was able to transfer the 
first five (SchemaMasterRole, InfrastructureMasterRole, 
RidAllocationMasterRole, PdcEmulationMasterRole and DomainNamingMasterRole).

However, when I try:
> samba-tool fsmo transfer --role=forestdns -U administrator
or
> samba-tool fsmo transfer --role=domaindns -U administrator
I get:
> ERROR: Failed to add role 'domaindns': LDAP error 53 LDAP_UNWILLING_TO_PERFORM -  <000020AE: SvcErr: DSID-03152965, problem 5003 (WILL_NOT_PERFORM), data 0
>> <>

I read on the wiki:
> Early versions of samba-tool had a bug that prevented the seizure of the Domain Naming Master role.
> If you encounter this problem in your version, add the "--force" parameter as a temporary workaround.
> You should upgrade to a supported Samba version as soon as possible.

Does this still apply to 4.23, which should be still a "supported" version?

Also, before I try this, does this mean I should demote the old DC 
immediately thereafter?
(I'd like to keep it working for a few other days).

  bye & Thanks
	av.

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba