Re: Trouble transferring FSMO roles
Rowland Penny via samba <[email protected]> Wed, 8 Jul 2026 19:16:42 +0100
| Newsgroups | gmane.network.samba.general |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 8 Jul 2026 19:26:32 +0200 Andrea Venturoli via samba <[email protected]> wrote: > Hello. > > At a customer's site, there's a Windows 2008 server acting as the > only AD DC. > Of course I want to get rid of this ASAP. > > I set up a new Samba 4.23.8 AD DC which has been working for a couple > of days. > Now I'm trying to transfer FSMO roles and I was able to transfer the > first five (SchemaMasterRole, InfrastructureMasterRole, > RidAllocationMasterRole, PdcEmulationMasterRole and > DomainNamingMasterRole). > > However, when I try: > > samba-tool fsmo transfer --role=forestdns -U administrator > or > > samba-tool fsmo transfer --role=domaindns -U administrator > I get: > > ERROR: Failed to add role 'domaindns': LDAP error 53 > > LDAP_UNWILLING_TO_PERFORM - <000020AE: SvcErr: DSID-03152965, > > problem 5003 (WILL_NOT_PERFORM), data 0 > >> <> > > I read on the wiki: > > Early versions of samba-tool had a bug that prevented the seizure > > of the Domain Naming Master role. If you encounter this problem in > > your version, add the "--force" parameter as a temporary > > workaround. You should upgrade to a supported Samba version as soon > > as possible. > > Does this still apply to 4.23, which should be still a "supported" > version? Probably, When you seize a role, it first tries to transfer it and generally fails, using '--force' just goes directly to attempting to seize the role. > > Also, before I try this, does this mean I should demote the old DC > immediately thereafter? > (I'd like to keep it working for a few other days). If you 'seize' any FSMO role, you should demote the old DC, it probably still thinks it owns the role just seized. Rowland -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba