Re: Trouble transferring FSMO roles

Rowland Penny via samba <[email protected]> Wed, 8 Jul 2026 19:16:42 +0100
Newsgroups gmane.network.samba.general
Message-ID <[email protected]>
On Wed, 8 Jul 2026 19:26:32 +0200
Andrea Venturoli via samba <[email protected]> wrote:

> Hello.
> 
> At a customer's site, there's a Windows 2008 server acting as the
> only AD DC.
> Of course I want to get rid of this ASAP.
> 
> I set up a new Samba 4.23.8 AD DC which has been working for a couple
> of days.
> Now I'm trying to transfer FSMO roles and I was able to transfer the 
> first five (SchemaMasterRole, InfrastructureMasterRole, 
> RidAllocationMasterRole, PdcEmulationMasterRole and
> DomainNamingMasterRole).
> 
> However, when I try:
> > samba-tool fsmo transfer --role=forestdns -U administrator
> or
> > samba-tool fsmo transfer --role=domaindns -U administrator
> I get:
> > ERROR: Failed to add role 'domaindns': LDAP error 53
> > LDAP_UNWILLING_TO_PERFORM -  <000020AE: SvcErr: DSID-03152965,
> > problem 5003 (WILL_NOT_PERFORM), data 0
> >> <>
> 
> I read on the wiki:
> > Early versions of samba-tool had a bug that prevented the seizure
> > of the Domain Naming Master role. If you encounter this problem in
> > your version, add the "--force" parameter as a temporary
> > workaround. You should upgrade to a supported Samba version as soon
> > as possible.
> 
> Does this still apply to 4.23, which should be still a "supported"
> version?

Probably, When you seize a role, it first tries to transfer it and
generally fails, using '--force' just goes directly to attempting to
seize the role.

> 
> Also, before I try this, does this mean I should demote the old DC 
> immediately thereafter?
> (I'd like to keep it working for a few other days).

If you 'seize' any FSMO role, you should demote the old DC, it probably
still thinks it owns the role just seized.

Rowland

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/options/samba