Hi,
Now, my functional level is 2008_R2.
samba-tool domain level show
Domain and forest function level for domain 'DC=empres,DC=com,DC=br'
Forest function level: (Windows) 2008 R2
Domain function level: (Windows) 2008 R2
Lowest function level of a DC: (Windows) 2008 R2
Everything looks fine, the replication, the consistency between the DCs,
however I have checked this information in /var/log/samba/log.samba which I
don't know if is normal:
Kerberos: Looking for PKINIT pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.965040, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Looking for ENC-TS pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.965075, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: No preauth found, returning PREAUTH-REQUIRED -- COMP0002$@
EMPRESA.COM.BR
[2019/08/30 13:16:56.966512, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'kdc_tcp_call_loop:
tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:16:56.969161, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: AS-REQ COMP0002$@EMPRESA.COM.BR from ipv4:192.168.8.12:55590
for krbtgt/EMPRESA.COM.BR at EMPRESA.COM.BR
[2019/08/30 13:16:56.972700, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Client sent patypes: encrypted-timestamp, 128
[2019/08/30 13:16:56.972736, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Looking for PKINIT pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.972758, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Looking for ENC-TS pa-data -- COMP0002$@EMPRESA.COM.BR
[2019/08/30 13:16:56.972830, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: ENC-TS Pre-authentication succeeded -- COMP0002$@EMPRESA.COM.BR
using aes256-cts-hmac-sha1-96
[2019/08/30 13:16:56.972875, 3]
../../auth/auth_log.c:647(log_authentication_event_human_readable)
Auth: [Kerberos KDC,ENC-TS Pre-authentication] user [(null)]\[COMP0002$@
EMPRESA.COM.BR] at [Fri, 30 Aug 2019 13:16:56.972857 -03] with
[aes256-cts-hmac-sha1-96] status [NT_STATUS_OK] workstation [(null)] remote
host [ipv4:192.168.8.12:55590] became [EMPRESA]\[COMP0002$]
[S-1-5-21-1712526294-259020848-313593124-7480]. local host [NULL]
{"timestamp": "2019-08-30T13:16:56.972930-0300",
"type":
"Authentication", "Authentication": {"version":
{"major": 1, "minor": 1},
"eventId": 4624, "logonType": 3, "status":
"NT_STATUS_OK", "localAddress":
null, "remoteAddress": "ipv4:192.168.8.12:55590",
"serviceDescription":
"Kerberos KDC", "authDescription": "ENC-TS
Pre-authentication",
"clientDomain": null, "clientAccount":
"COMP0002$@EMPRESA.COM.BR",
"workstation": null, "becameAccount": "COMP0002$",
"becameDomain":
"EMPRESA", "becameSid":
"S-1-5-21-1712526294-259020848-313593124-7480",
"mappedAccount": "COMP0002$", "mappedDomain":
"EMPRESA",
"netlogonComputer": null, "netlogonTrustAccount": null,
"netlogonNegotiateFlags": "0x00000000",
"netlogonSecureChannelType": 0,
"netlogonTrustAccountSid": null, "passwordType":
"aes256-cts-hmac-sha1-96",
"duration": 3822}}
[2019/08/30 13:16:57.025109, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: AS-REQ authtime: 2019-08-30T13:16:56 starttime: unset endtime:
2019-08-30T23:16:56 renew till: 2019-09-06T13:16:56
[2019/08/30 13:16:57.025190, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Client supported enctypes: aes256-cts-hmac-sha1-96,
arcfour-hmac-md5, -133, -128, 24, -135, using
aes256-cts-hmac-sha1-96/aes256-cts-hmac-sha1-96
[2019/08/30 13:16:57.025216, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: Requested flags: renewable-ok, canonicalize, renewable,
forwardable
[2019/08/30 13:16:57.031762, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'kdc_tcp_call_loop:
tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:16:57.035529, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: TGS-REQ COMP0002$@EMPRESA.COM.BR from ipv4:192.168.8.12:55591
for ajur0002$@EMPRESA.COM.BR [canonicalize, renewable, forwardable]
[2019/08/30 13:16:57.040500, 3]
../../source4/auth/kerberos/krb5_init_context.c:80(smb_krb5_debug_wrapper)
Kerberos: TGS-REQ authtime: 2019-08-30T13:16:56 starttime:
2019-08-30T13:16:57 endtime: 2019-08-30T23:16:56 renew till:
2019-09-06T13:16:56
[2019/08/30 13:16:57.042891, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'kdc_tcp_call_loop:
tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:04.113053, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:06.123652, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:12.796283, 3]
../../lib/ldb-samba/ldb_wrap.c:332(ldb_wrap_connect)
ldb_wrap open of secrets.ldb
[2019/08/30 13:17:12.796760, 3]
../../auth/gensec/schannel.c:618(schannel_update_internal)
Could not find session key for attempted schannel connection from
COMP0002: NT_STATUS_NOT_FOUND
[2019/08/30 13:17:12.797902, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:12.800680, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
[2019/08/30 13:17:16.935086, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_RESET'
[2019/08/30 13:17:24.112678, 3]
../../source4/smbd/service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'dcesrv:
NT_STATUS_CONNECTION_DISCONNECTED'
I have tested kerberos authentication and looks fine for me.
Regards,
M?rcio Bacci
Em sex, 30 de ago de 2019 ?s 12:17, L.P.H. van Belle <belle at bazuin.nl>
escreveu:
> ?
> P.s
>
> Im getting out of the office, so other question mail the list, Rowland
> will help further if needed.
>
> Greetz,
>
> Louis
>
>
> ------------------------------
> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
> *Verzonden:* vrijdag 30 augustus 2019 17:00
> *Aan:* L.P.H. van Belle
> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>
> Hi,
>
> I followed your directions and here are the results:
>
> samba-tool domain level show
> Domain and forest function level for domain
'DC=empresa,DC=com,DC=br'
>
> Forest function level: (Windows) 2003
> Domain function level: (Windows) 2008
> Lowest function level of a DC: (Windows) 2008 R2
>
> root at samba4-dc1:/var/log/samba# dpkg -l |egrep
> "talloc|tevent|ldb|tdb|wrapper"
> ii ldb-tools 2:1.5.5-1.1deb9~1 amd64
> LDAP-like embedded database - tools
> ii libgmpxx4ldbl:amd64 2:6.1.2+dfsg-1 amd64
> Multiprecision arithmetic library (C++ bindings)
> ii libgnutls-openssl27:amd64 3.5.8-5+deb9u4 amd64
> GNU TLS library - OpenSSL wrapper
> ii libldb1:amd64 2:1.5.5-1.1deb9~1 amd64
> LDAP-like embedded database - shared library
> ii libltdl-dev:amd64 2.4.6-2 amd64
> System independent dlopen wrapper for GNU libtool
> ii libltdl7:amd64 2.4.6-2 amd64
> System independent dlopen wrapper for GNU libtool
> ii libmldbm-perl 2.05-2 all
> module for storing multidimensional hash structures in perl tied
> hashes
> ii libtalloc2:amd64 2.1.16-0nmu1~deb9 amd64
> hierarchical pool based memory allocator
> ii libtdb1:amd64 1.3.18-0.1nmu0~deb9 amd64
> Trivial Database - shared library
> ii libtevent0:amd64 0.9.39-0.1nmu1~deb9 amd64
> talloc-based event loop library - shared library
> ii libwrap0:amd64 7.6.q-26 amd64
> Wietse Venema's TCP wrappers library
> ii python-gpgme 0.3-1.2 amd64
> python wrapper for the GPGME library
> ii python-talloc:amd64 2.1.16-0nmu1~deb9 amd64
> hierarchical pool based memory allocator - Python bindings
> ii python-tdb 1.3.18-0.1nmu0~deb9 amd64
> Python bindings for TDB
> ii python3-gpgme 0.3-1.2 amd64
> python wrapper for the GPGME library (Python 3)
> ii python3-ldb 2:1.5.5-1.1deb9~1 amd64
> Python 3 bindings for LDB
> ii python3-talloc 2.1.16-0nmu1~deb9 amd64
> hierarchical pool based memory allocator - Python3 bindings
> ii python3-tdb 1.3.18-0.1nmu0~deb9 amd64
> Python3 bindings for TDB
> ii ssl-cert 1.0.39 all
> simple debconf wrapper for OpenSSL
> ii tcpd 7.6.q-26 amd64
> Wietse Venema's TCP wrapper utilities
> ii tdb-tools 1.3.18-0.1nmu0~deb9 amd64
> Trivial Database - bundled binaries
> root at samba4-dc1:/var/log/samba#
>
> root at samba4-dc1:/var/log/samba# /etc/init.d/samba-ad-dc status
> ? samba-ad-dc.service - Samba AD Daemon
> Loaded: loaded (
>
]8;;file://samba4-dc1/lib/systemd/system/samba-ad-dc.service/lib/systemd/system/samba-ad-dc.service
> ]8;;; enabled; vendor preset: enabled)
> Active: active (running) since Fri 2019-08-30 11:54:12 -03; 9s ago
> Docs: ]8;;man:samba(8)man:samba(8) ]8;;
> ]8;;man:samba(7)man:samba(7) ]8;;
> ]8;;man:smb.conf(5)man:smb.conf(5) ]8;;
> Main PID: 1755 (samba)
> Status: "smbd: ready to serve connections..."
> Tasks: 27 (limit: 4720)
> CGroup: /system.slice/samba-ad-dc.service
> ??1755 samba: root process
> ??1756 samba: task[s3fs_parent]
> ??1757 samba: task[dcesrv]
> ??1758 samba: task[nbtd]
> ??1759 samba: tfork waiter process
> ??1760 samba: task[wrepl]
> ??1761 samba: task[ldapsrv]
> ??1762 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1763 samba: task[cldapd]
> ??1764 samba: conn[kdc_tcp] c[ipv4:* MailScanner heeft een
> e-mail met mogelijk een poging tot fraude gevonden van
> "192.168.94.63:62130" * *MailScanner warning: numerical links are
often
> malicious:* 192.168.94.63:62130 <http://192.168.94.63:62130>]
s[ipv4:*
> MailScanner heeft een e-mail met mogelijk een poging tot fraude gevonden
> van "192.168.1.20:88" * *MailScanner warning: numerical links are
often
> malicious:* 192.168.1.20:88 <http://192.168.1.20:88>]
server_id[1764.40]
> ??1765 samba: task[dreplsrv]
> ??1766 samba: task[winbindd_parent]
> ??1767 samba: task[ntp_signd]
> ??1768 samba: task[kccsrv]
> ??1769 samba: task[dnsupdate]
> ??1770 samba: conn[dns_tcp] c[ipv4:* MailScanner heeft een
> e-mail met mogelijk een poging tot fraude gevonden van
"192.168.6.24:59870"
> * *MailScanner warning: numerical links are often malicious:*
> 192.168.6.24:59870 <http://192.168.6.24:59870>] s[ipv4:* MailScanner
> heeft een e-mail met mogelijk een poging tot fraude gevonden van
> "192.168.1.20:53" * *MailScanner warning: numerical links are
often
> malicious:* 192.168.1.20:53 <http://192.168.1.20:53>]
server_id[1770.42]
> ??1771 samba: tfork waiter process
> ??1772 /usr/sbin/winbindd -D --option=server role
> check:inhibit=yes --foreground
> ??1797 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1798 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1799 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1804 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1805 samba: conn[rpc] c[ipv4:* MailScanner heeft een e-mail
> met mogelijk een poging tot fraude gevonden van
"10.67.92.134:53636" * *MailScanner
> warning: numerical links are often malicious:* 10.67.92.134:53636
> <http://10.67.92.134:53636>] s[ipv4:* MailScanner heeft een e-mail
met
> mogelijk een poging tot fraude gevonden van "192.168.1.20:49152"
* *MailScanner
> warning: numerical links are often malicious:* 192.168.1.20:49152
> <http://192.168.1.20:49152>] server_id[1805]
> ??1806 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1807 /usr/sbin/smbd -D --option=server role check:inhibit=yes
> --foreground
> ??1808 winbindd: domain child [EMPRESA]
> ??1809 winbindd: idmap child
>
> ago 30 11:54:12 samba4-dc1 samba[1755]: root process[1755]: Copyright
> Andrew Tridgell and the Samba Team 1992-2019
> ago 30 11:54:12 samba4-dc1 samba[1755]: root process[1755]: [2019/08/30
> 11:54:12.469019, 0] ../../source4/smbd/server.c:773(binary_smbd_main)
> ago 30 11:54:12 samba4-dc1 samba[1755]: root process[1755]:
> binary_smbd_main: samba: using 'standard' process model
> ago 30 11:54:12 samba4-dc1 winbindd[1772]: [2019/08/30 11:54:12.939861,
> 0] ../../source3/winbindd/winbindd_cache.c:3166(initialize_winbindd_cache)
> ago 30 11:54:12 samba4-dc1 winbindd[1772]: initialize_winbindd_cache:
> clearing cache and re-creating with version number 2
> ago 30 11:54:12 samba4-dc1 winbindd[1772]: [2019/08/30 11:54:12.942535,
> 0] ../../lib/util/become_daemon.c:136(daemon_ready)
> ago 30 11:54:12 samba4-dc1 winbindd[1772]: daemon_ready: daemon
> 'winbindd' finished starting up and ready to serve connections
> ago 30 11:54:12 samba4-dc1 systemd[1]: Started Samba AD Daemon.
> ago 30 11:54:12 samba4-dc1 smbd[1762]: [2019/08/30 11:54:12.993254, 0]
> ../../lib/util/become_daemon.c:136(daemon_ready)
> ago 30 11:54:12 samba4-dc1 smbd[1762]: daemon_ready: daemon
'smbd'
> finished starting up and ready to serve connections
>
> Regards,
>
> M?rcio Bacci
>
> Em sex, 30 de ago de 2019 ?s 11:40, L.P.H. van Belle <belle at
bazuin.nl>
> escreveu:
>
>> ?
>> Hai,
>>
>> No, its not automaticly raised.
>> that is shown here :
>> https://wiki.samba.org/index.php/Raising_the_Functional_Levels
>> samba-tool domain level show : show current level.
>> On every DC, run : samba-tool dbcheck --reindex
>> This was not always done in the past, should be done at upgrade, but i
>> always run if after major updates to be sure.
>>
>> Can you post the me this : dpkg -l |egrep
>> "talloc|tevent|ldb|tdb|wrapper"
>> asking that because of these you showed.
>> samba4-dc1 samba[17835]: task[dcesrv][17835]:
>> standard_child_pipe_handler: Child 18438 () terminated with signal 6
>>
>> im guessing that these are of the upgrade, simple to verify..
>> stop samba-ad
>>
>> clear the samba logs
>> start samba-ad
>>
>> Check the logs.
>>
>>
>> Greetz,
>>
>> Louis
>>
>>
>>
>>
>> ------------------------------
>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>> *Verzonden:* vrijdag 30 augustus 2019 16:31
>> *Aan:* L.P.H. van Belle
>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>
>> Hi,
>>
>> I was able to upgrade both DC to Samba 4.10.7. Apparently everything is
>> OK.
>>
>> root at samba4-dc1:~# /etc/init.d/samba-ad-dc status
>> ? samba-ad-dc.service - Samba AD Daemon
>> Loaded: loaded (
>>
]8;;file://samba4-dc1/lib/systemd/system/samba-ad-dc.service/lib/systemd/system/samba-ad-dc.service
>> ]8;;; enabled; vendor preset: enabled)
>> Active: active (running) since Fri 2019-08-30 10:50:23 -03; 28min
ago
>> Docs: ]8;;man:samba(8)man:samba(8) ]8;;
>> ]8;;man:samba(7)man:samba(7) ]8;;
>> ]8;;man:smb.conf(5)man:smb.conf(5) ]8;;
>> Main PID: 17833 (samba)
>> Status: "winbindd: ready to serve connections..."
>> Tasks: 31 (limit: 4720)
>> CGroup: /system.slice/samba-ad-dc.service
>> ??17833 samba: root process
>> ??17834 samba: task[s3fs_parent]
>> ??17835 samba: task[dcesrv]
>> ??17836 samba: task[nbtd]
>> ??17837 samba: task[wrepl]
>> ??17838 samba: tfork waiter process
>> ??17839 samba: task[ldapsrv]
>> ??17840 samba: task[cldapd]
>> ??17841 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??17842 samba: conn[kdc_tcp] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van
"192.168.3.37:54843"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.3.37:54843 <http://192.168.3.37:54843>] s[ipv4:*
MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:88" **MailScanner warning: numerical links are
often
>> malicious:* 192.168.1.20:88 <http://192.168.1.20:88>]
server_id[17842.40]
>> ??17843 samba: task[dreplsrv]
>> ??17844 samba: task[winbindd_parent]
>> ??17845 samba: task[ntp_signd]
>> ??17846 samba: task[kccsrv]
>> ??17847 samba: task[dnsupdate]
>> ??17848 samba: conn[dns_tcp] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van
"192.168.6.24:59744"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.6.24:59744 <http://192.168.6.24:59744>] s[ipv4:*
MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:53" **MailScanner warning: numerical links are
often
>> malicious:* 192.168.1.20:53 <http://192.168.1.20:53>]
server_id[17848.41]
>> ??17849 samba: tfork waiter process
>> ??17850 /usr/sbin/winbindd -D --option=server role
>> check:inhibit=yes --foreground
>> ??17858 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??17859 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??17860 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??17863 winbindd: domain child [EMPRESA]
>> ??17864 winbindd: idmap child
>> ??18052 winbindd: domain child [BUILTIN]
>> ??18134 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??18135 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??19037 samba: conn[ldap] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van
"192.168.1.17:43234"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.1.17:43234 <http://192.168.1.17:43234>] s[ipv4:*
MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:389" **MailScanner warning: numerical links are
often
>> malicious:* 192.168.1.20:389 <http://192.168.1.20:389>]
server_id[19037]
>> ??19112 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??19126 samba: conn[rpc] c[ipv4:* MailScanner heeft een
>> e-mail met mogelijk een poging tot fraude gevonden van
"192.168.1.76:60575"
>> **MailScanner warning: numerical links are often malicious:*
>> 192.168.1.76:60575 <http://192.168.1.76:60575>] s[ipv4:*
MailScanner
>> heeft een e-mail met mogelijk een poging tot fraude gevonden van
>> "192.168.1.20:49152" **MailScanner warning: numerical links
are often
>> malicious:* 192.168.1.20:49152 <http://192.168.1.20:49152>]
>> server_id[19126]
>> ??19129 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>> ??19131 /usr/sbin/smbd -D --option=server role
>> check:inhibit=yes --foreground
>>
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #13
>> /usr/lib/x86_64-linux-gnu/libtevent.so.0(tevent_common_loop_wait+0x1b)
>> [0x7f2e4e7e949b]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #14 /usr/lib/x86_64-linux-gnu/libtevent.so.0(+0xaf77)
>> [0x7f2e4e7edf77]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #15
>> /usr/lib/x86_64-linux-gnu/samba/process_model/standard.so(+0x2261)
>> [0x7f2e498f6261]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #16
>>
/usr/lib/x86_64-linux-gnu/samba/libservice.so.0(task_server_startup+0x5c)
>> [0x7f2e5ba90a0c]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #17
>>
/usr/lib/x86_64-linux-gnu/samba/libservice.so.0(server_service_startup+0x96)
>> [0x7f2e5ba8f386]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #18 samba: task[rpc] standard worker(+0x57ad)
>> [0x55e4060187ad]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #19
>> /lib/x86_64-linux-gnu/libc.so.6(__libc_start_main+0xf1)
[0x7f2e4d2702e1]
>> ago 30 11:03:11 samba4-dc1 samba[18438]: task[rpc] standard
>> worker[18438]: #20 samba: task[rpc] standard worker(_start+0x2a)
>> [0x55e406016e4a]
>> ago 30 11:03:11 samba4-dc1 samba[17835]: task[dcesrv][17835]:
[2019/08/30
>> 11:03:11.847514, 0]
>> ../../source4/smbd/process_standard.c:160(standard_child_pipe_handler)
>> ago 30 11:03:11 samba4-dc1 samba[17835]: task[dcesrv][17835]:
>> standard_child_pipe_handler: Child 18438 () terminated with signal 6
>>
>>
>> I thought the option to raise the Forest functional level to Windows
>> Server 2012 would now be available, but it isn't.
>>
>> Is this normal ?
>>
>> Regards,
>>
>> M?rcio Bacci
>>
>> Em sex, 30 de ago de 2019 ?s 09:23, L.P.H. van Belle <belle at
bazuin.nl>
>> escreveu:
>>
>>> ?
>>> Yes, you can transfer the roles, but personaly, i never do that.
>>> I upgrade as is, everything looks good atm, so i dont think moving
roles
>>> is really needed.
>>>
>>>
>>> Greetz,
>>>
>>> Louis
>>>
>>>
>>>
>>> ------------------------------
>>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>>> *Verzonden:* vrijdag 30 augustus 2019 14:07
>>> *Aan:* L.P.H. van Belle
>>> *CC:* samba at lists.samba.org
>>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>>
>>> Hi,
>>>
>>> I was able to update.
>>>
>>> Apparently everything is OK.
>>>
>>> Is it safe to transfer FSMO rols to DC2 (samba 4.10.7) to upgrade
DC1
>>> (Samba 4.5.16)?
>>>
>>> Below are the tests I did:
>>>
>>> Checking smb.conf with testparm
>>> Load smb config files from /etc/samba/smb.conf
>>> Loaded services file OK.
>>> Server role: ROLE_ACTIVE_DIRECTORY_DC
>>>
>>> Done
>>> Checking smb.conf with samba-tool
>>> INFO 2019-08-30 08:46:53,674 pid:6665
>>> /usr/lib/python3/dist-packages/samba/netcmd/testparm.py #96: Loaded
smb
>>> config files from /etc/samba/smb.conf
>>> INFO 2019-08-30 08:46:53,675 pid:6665
>>> /usr/lib/python3/dist-packages/samba/netcmd/testparm.py #97: Loaded
>>> services file OK.
>>> Done
>>> Setting up winbind (2: 4.10.7-0.1 ~ deb9) ...
>>> Samba is being run as an AD Domain Controller: Masking
winbind.service
>>> Please ignore the following error about deb-systemd-helper not
finding
>>> those services.
>>> (winbind.service already masked)
>>> Setting up samba (2: 4.10.7-0.1 ~ deb9) ...
>>> Samba is being run as an AD Domain Controller: Masking smbd.service
>>> nmbd.service
>>> Please ignore the following error about deb-systemd-helper not
finding
>>> those services.
>>> (smbd.service already masked)
>>> (nmbd.service already masked)
>>> Processing triggers for libc-bin (2.24-11 + deb9u4) ...
>>>
>>> root at samba4-dc2:~# samba -V
>>> Version 4.10.7-Debian
>>>
>>>
>>> root at samba4-dc2:~# systemctl status samba-ad-dc
>>> ? samba-ad-dc.service - Samba AD Daemon
>>> Loaded: loaded (/lib/systemd/system/samba-ad-dc.service;
enabled;
>>> vendor preset: enabled)
>>> Active: active (running) since Fri 2019-08-30 08:48:26 -03; 21s
ago
>>> Docs: man:samba(8)
>>> man:samba(7)
>>> man:smb.conf(5)
>>> Main PID: 6992 (samba)
>>> Status: "smbd: ready to serve connections..."
>>> Tasks: 23 (limit: 4915)
>>> CGroup: /system.slice/samba-ad-dc.service
>>> ??6992 samba: root process
>>> ??6993 samba: task[s3fs_parent]
>>> ??6994 samba: task[dcesrv]
>>> ??6995 samba: task[nbtd]
>>> ??6996 samba: task[wrepl]
>>> ??6997 samba: task[ldapsrv]
>>> ??6998 samba: tfork waiter process
>>> ??6999 samba: task[cldapd]
>>> ??7000 samba: conn[kdc_tcp] c[ipv4:* MailScanner heeft
een
>>> e-mail met mogelijk een poging tot fraude gevonden van
>>> "192.168.91.14:59442" **MailScanner warning: numerical
links are often
>>> malicious:* 192.168.91.14:59442 <http://192.168.91.14:59442>]
s[ipv4:*
>>> MailScanner heeft een e-mail met mogelijk een poging tot fraude
gevonden
>>> van "192.168.1.22:88" **MailScanner warning: numerical
links are often
>>> malicious:* 192.168.1.22:88 <http://192.168.1.22:88>]
server_id[7000.40]
>>> ??7001 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>> ??7002 samba: task[dreplsrv]
>>> ??7003 samba: task[winbindd_parent]
>>> ??7004 samba: task[ntp_signd]
>>> ??7005 samba: task[kccsrv]
>>> ??7006 samba: task[dnsupdate]
>>> ??7007 samba: task[dns]
>>> ??7008 samba: tfork waiter process
>>> ??7009 /usr/sbin/winbindd -D --option=server role
>>> check:inhibit=yes --foreground
>>> ??7017 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>> ??7018 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>> ??7019 /usr/sbin/smbd -D --option=server role
>>> check:inhibit=yes --foreground
>>> ??7022 winbindd: domain child [EMPRESA]
>>> ??7023 winbindd: idmap child
>>>
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873694, 0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'http_ntlm'
registered
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873741, 0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'http_negotiate'
registered
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873788, 0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend 'krb5' registered
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> [2019/08/30 08:48:26.873837, 0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:26 samba4-dc2 samba[7006]: task[dnsupdate][7006]:
>>> /usr/sbin/samba_dnsupdate: GENSEC backend
'fake_gssapi_krb5' registered
>>> ago 30 08:48:40 samba4-dc2 samba[7005]: task[kccsrv][7005]:
[2019/08/30
>>> 08:48:40.887442, 0]
>>> ../../lib/util/util_runcmd.c:327(samba_runcmd_io_handler)
>>> ago 30 08:48:40 samba4-dc2 samba[7005]: task[kccsrv][7005]:
>>> /usr/sbin/samba_kcc: ldb_wrap open of secrets.ldb
>>>
>>>
>>> root at samba4-dc2:~# samba-tool drs showrepl
>>> ldb_wrap open of secrets.ldb
>>> GENSEC backend 'gssapi_spnego' registered
>>> GENSEC backend 'gssapi_krb5' registered
>>> GENSEC backend 'gssapi_krb5_sasl' registered
>>> GENSEC backend 'spnego' registered
>>> GENSEC backend 'schannel' registered
>>> GENSEC backend 'naclrpc_as_system' registered
>>> GENSEC backend 'sasl-EXTERNAL' registered
>>> GENSEC backend 'ntlmssp' registered
>>> GENSEC backend 'ntlmssp_resume_ccache' registered
>>> GENSEC backend 'http_basic' registered
>>> GENSEC backend 'http_ntlm' registered
>>> GENSEC backend 'http_negotiate' registered
>>> GENSEC backend 'krb5' registered
>>> GENSEC backend 'fake_gssapi_krb5' registered
>>> Using binding ncacn_ip_tcp:samba4-dc2.empresa.com.br[,seal]
>>> resolve_lmhosts: Attempting lmhosts lookup for name
>>> samba4-dc2.empresa.com.br<0x20>
>>> resolve_lmhosts: Attempting lmhosts lookup for name
>>> samba4-dc2.empresa.com.br<0x20>
>>> resolve_lmhosts: Attempting lmhosts lookup for name
>>> samba4-dc2.empresa.com.br<0x20>
>>> Default-First-Site-Name\SAMBA4-DC2
>>> DSA Options: 0x00000001
>>> DSA object GUID: 45b5b534-9bcc-483c-8f6d-5bbc37dc35e9
>>> DSA invocationId: f621cfd8-7f92-48be-84d9-daa14ef20c05
>>>
>>> ==== INBOUND NEIGHBORS ===>>>
>>> DC=ForestDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:48:40 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:48:40 2019 -03
>>>
>>> CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:48:40 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:48:40 2019 -03
>>>
>>> DC=DomainDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:50:16 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:50:16 2019 -03
>>>
>>> CN=Schema,CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:48:40 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:48:40 2019 -03
>>>
>>> DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ Fri Aug 30 08:50:36 2019 -03 was successful
>>> 0 consecutive failure(s).
>>> Last success @ Fri Aug 30 08:50:36 2019 -03
>>>
>>> ==== OUTBOUND NEIGHBORS ===>>>
>>> DC=ForestDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> DC=DomainDnsZones,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> CN=Schema,CN=Configuration,DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> DC=empresa,DC=com,DC=br
>>> Default-First-Site-Name\SAMBA4-DC1 via RPC
>>> DSA object GUID: a1ab021c-0ef7-4fd3-a69d-28afc7c1260a
>>> Last attempt @ NTTIME(0) was successful
>>> 0 consecutive failure(s).
>>> Last success @ NTTIME(0)
>>>
>>> ==== KCC CONNECTION OBJECTS ===>>>
>>> Connection --
>>> Connection name: 3135cf0d-0109-4a40-be6f-44e1eca5b5d2
>>> Enabled : TRUE
>>> Server DNS name : samba4-dc1.empresa.com.br
>>> Server DN name : CN=NTDS
>>>
Settings,CN=SAMBA4-DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=empresa,DC=com,DC=br
>>> TransportType: RPC
>>> options: 0x00000001
>>> Warning: No NC replicated for Connection!
>>>
>>>
>>>
>>> root at samba4-dc2:~# samba-tool ldapcmp ldap://SAMBA4-DC1
>>> ldap://SAMBA4-DC2 -UAdministrator
>>> resolve_lmhosts: Attempting lmhosts lookup for name
SAMBA4-DC1<0x20>
>>> GENSEC backend 'gssapi_spnego' registered
>>> GENSEC backend 'gssapi_krb5' registered
>>> GENSEC backend 'gssapi_krb5_sasl' registered
>>> GENSEC backend 'spnego' registered
>>> GENSEC backend 'schannel' registered
>>> GENSEC backend 'naclrpc_as_system' registered
>>> GENSEC backend 'sasl-EXTERNAL' registered
>>> GENSEC backend 'ntlmssp' registered
>>> GENSEC backend 'ntlmssp_resume_ccache' registered
>>> GENSEC backend 'http_basic' registered
>>> GENSEC backend 'http_ntlm' registered
>>> GENSEC backend 'http_negotiate' registered
>>> GENSEC backend 'krb5' registered
>>> GENSEC backend 'fake_gssapi_krb5' registered
>>> Password for [EMPRESA\Administrador]:
>>> resolve_lmhosts: Attempting lmhosts lookup for name
SAMBA4-DC2<0x20>
>>>
>>> * Comparing [DOMAIN] context...
>>>
>>> * Objects to be compared: 1869
>>>
>>> * Result for [DOMAIN]: SUCCESS
>>>
>>> * Comparing [CONFIGURATION] context...
>>>
>>> * Objects to be compared: 1640
>>>
>>> * Result for [CONFIGURATION]: SUCCESS
>>>
>>> * Comparing [SCHEMA] context...
>>>
>>> * Objects to be compared: 1518
>>>
>>> * Result for [SCHEMA]: SUCCESS
>>>
>>> * Comparing [DNSDOMAIN] context...
>>>
>>> * Objects to be compared: 565
>>>
>>> * Result for [DNSDOMAIN]: SUCCESS
>>>
>>> * Comparing [DNSFOREST] context...
>>>
>>> * Objects to be compared: 31
>>>
>>> * Result for [DNSFOREST]: SUCCESS
>>>
>>> Regards,
>>>
>>> M?rcio Bacci
>>>
>>> Em sex, 30 de ago de 2019 ?s 08:44, L.P.H. van Belle <belle at
bazuin.nl>
>>> escreveu:
>>>
>>>> No, thats also correct.
>>>>
>>>> Because in 4.10 new packages are added and removed.
>>>>
>>>> you need to run : apt-get dist-upgrade
>>>>
>>>> Small note, i always run : apt-get dist-upgrade -y
>>>> -dy , download and yes.
>>>>
>>>> then run : apt-get dist-upgrade -y
>>>>
>>>> that makes sure you always have all the needed packages on you
server
>>>> before you upgrade.
>>>>
>>>> Greetz,
>>>>
>>>> Louis
>>>>
>>>>
>>>> ------------------------------
>>>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at gmail.com]
>>>> *Verzonden:* vrijdag 30 augustus 2019 13:40
>>>> *Aan:* L.P.H. van Belle
>>>> *CC:* samba at lists.samba.org
>>>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>>>
>>>> Hi,
>>>>
>>>> Really, version 4.9-12 solved the DBCHECK problem.
>>>>
>>>> Apparently, in version 4.9-12 everything is OK, just not being
able to
>>>> upgrade to version 4.10, as follows:
>>>>
>>>> Reading package lists ... Ready
>>>> Building dependency tree
>>>> Reading status info ... Ready
>>>> 10 packages can be upgraded. Run 'apt list
--upgradable' to see them.
>>>> Reading package lists ... Ready
>>>> Building dependency tree
>>>> Reading status info ... Ready
>>>> Calculating update ... Ready
>>>> The following packages have been installed automatically and
are no
>>>> longer required:
>>>> libfile-copy-recursive-perl update-inetd
>>>> Use 'apt autoremove' to remove them.
>>>> The following packages will be kept in their current versions:
>>>> libldb1 libwbclient0 samba samba common samba common bin
samba dsdb
>>>> modules samba libs samba vfs modules winbind
>>>> 0 updated packages, 0 new packages installed, 0 to be removed
and 9 not
>>>> updated.
>>>>
>>>> I'm using Debian 9.9.
>>>>
>>>> Regards,
>>>>
>>>> M?rcio Bacci
>>>>
>>>> Em sex, 30 de ago de 2019 ?s 06:51, L.P.H. van Belle <belle
at bazuin.nl>
>>>> escreveu:
>>>>
>>>>> Hai,
>>>>>
>>>>> You can safely ignore that mesage.
>>>>>
>>>>> If both servers are done and running 4.8. procede to 4.9
>>>>>
>>>>> >> ERROR(<type 'exceptions.KeyError'>):
uncaught exception - 'No such
>>>>> element'
>>>>> is fixed in later samba versions
>>>>>
>>>>> Greetz,
>>>>>
>>>>> Louis
>>>>>
>>>>>
>>>>>
>>>>>
>>>>> ------------------------------
>>>>> *Van:* Marcio Demetrio Bacci [mailto:marciobacci at
gmail.com]
>>>>> *Verzonden:* vrijdag 30 augustus 2019 11:39
>>>>> *Aan:* L.P.H. van Belle
>>>>> *CC:* samba at lists.samba.org
>>>>> *Onderwerp:* Re: [Samba] Upgrade Samba 4
>>>>>
>>>>> Hi,
>>>>>
>>>>> I upgraded to Samba 4.8-12 as follows:
>>>>>
>>>>> Checking smb.conf with testparm
>>>>> Load smb config files from /etc/samba/smb.conf
>>>>> Loaded services file OK.
>>>>> Server role: ROLE_ACTIVE_DIRECTORY_DC
>>>>>
>>>>> Done
>>>>> Checking smb.conf with samba-tool
>>>>> Done
>>>>> Configurando samba-dsdb-modules:amd64 (2:4.8.12-1~deb9) ...
>>>>> Configurando winbind (2:4.8.12-1~deb9) ...
>>>>> Instalando nova vers?o do arquivo de configura??o
/etc/init.d/winbind
>>>>> ...
>>>>> Instalando nova vers?o do arquivo de configura??o
>>>>> /etc/logrotate.d/winbind ...
>>>>> Samba is being run as an AD Domain Controller: Masking
winbind.service
>>>>> Please ignore the following error about deb-systemd-helper
not finding
>>>>> those services.
>>>>> (winbind.service masked)
>>>>> Removing obsolete conffile /etc/init/winbind.conf ...
>>>>> Configurando samba (2:4.8.12-1~deb9) ...
>>>>> Instalando nova vers?o do arquivo de configura??o
/etc/init.d/nmbd ...
>>>>> Instalando nova vers?o do arquivo de configura??o
>>>>> /etc/init.d/samba-ad-dc ...
>>>>> Instalando nova vers?o do arquivo de configura??o
/etc/init.d/smbd ...
>>>>> Instalando nova vers?o do arquivo de configura??o
>>>>> /etc/logrotate.d/samba ...
>>>>> Samba is being run as an AD Domain Controller: Masking
smbd.service
>>>>> nmbd.service
>>>>> Please ignore the following error about deb-systemd-helper
not finding
>>>>> those services.
>>>>> (smbd.service masked)
>>>>> (nmbd.service masked)
>>>>> Removing obsolete conffile /etc/init.d/samba ...
>>>>> Removing obsolete conffile /etc/init/nmbd.conf ...
>>>>> Removing obsolete conffile /etc/init/reload-smbd.conf ...
>>>>> Removing obsolete conffile /etc/init/samba-ad-dc.conf ...
>>>>> Removing obsolete conffile /etc/init/smbd.conf ...
>>>>> A processar 'triggers' para libc-bin
(2.24-11+deb9u4) ...
>>>>> A processar 'triggers' para systemd
(232-25+deb9u11) ...
>>>>>
>>>>> Replication looks OK (samba-tool drs showrepl), but dbcheck
does not.
>>>>>
>>>>> samba-tool dbcheck --cross-ncs
>>>>> ERROR(<type 'exceptions.KeyError'>): uncaught
exception - 'No such
>>>>> element'
>>>>> File
"/usr/lib/python2.7/dist-packages/samba/netcmd/__init__.py",
>>>>> line 177, in _run
>>>>> return self.run(*args, **kwargs)
>>>>> File
"/usr/lib/python2.7/dist-packages/samba/netcmd/dbcheck.py",
>>>>> line 142, in run
>>>>>
check_expired_tombstones=selftest_check_expired_tombstones)
>>>>> File
"/usr/lib/python2.7/dist-packages/samba/dbchecker.py", line
>>>>> 200, in __init__
>>>>> self.tombstoneLifetime =
int(res[0]["tombstoneLifetime"][0])
>>>>>
>>>>> Regards,
>>>>>
>>>>> M?rcio Bacci
>>>>>
>>>>> Em sex, 30 de ago de 2019 ?s 06:18, L.P.H. van Belle via
samba <
>>>>> samba at lists.samba.org> escreveu:
>>>>>
>>>>>> Hai,
>>>>>>
>>>>>> No, keep everything as is.
>>>>>>
>>>>>> Since your upgrading from 4.5 ( and this is probely why
your upgrade
>>>>>> to 4.7 broke )
>>>>>> Make sure you settings are respecting config
requirements of 4.8.
>>>>>>
>>>>>> If you do hit an error.
>>>>>> Read :
http://downloads.van-belle.nl/samba4/Upgrade-info.txt
>>>>>> And if needed mail the list, im buzy with some servers
atm, but i'll
>>>>>> keep an eye on the list.
>>>>>>
>>>>>>
>>>>>> Greetz,
>>>>>>
>>>>>> Louis
>>>>>>
>>>>>>
>>>>>>
>>>>>> > -----Oorspronkelijk bericht-----
>>>>>> > Van: samba [mailto:samba-bounces at
lists.samba.org] Namens
>>>>>> > Marcio Demetrio Bacci via samba
>>>>>> > Verzonden: vrijdag 30 augustus 2019 11:13
>>>>>> > Aan: sambalist
>>>>>> > Onderwerp: [Samba] Upgrade Samba 4
>>>>>> >
>>>>>> > Hi,
>>>>>> >
>>>>>> > To upgrade my secondary DC Samba 4.5-16 to 4.8
should I
>>>>>> > remove the smb.conf
>>>>>> > file in /etc/samba first? I remember I tried last
month to
>>>>>> > upgrade from
>>>>>> > 4.5-16 to 4.7 and broke the installation.
>>>>>> >
>>>>>> > Or are just the procedures below enough?
>>>>>> >
>>>>>> > Create this file repo file for apt.
>>>>>> > echo "deb http://apt.van-belle.nl/debian
stretch-samba48 main
>>>>>> contrib
>>>>>> > non-free" | sudo tee -a
/etc/apt/sources.list.d/van-belle.list
>>>>>> >
>>>>>> > Import my key.
>>>>>> > wget -O -
http://apt.van-belle.nl/louis-van-belle.gpg-key.asc
>>>>>> > | apt-key add
>>>>>> > -
>>>>>> >
>>>>>> > apt update -y && apt upgrade -y
>>>>>> > Remove the 4.8 line from the repo, enable 4.9
repeat apt update &&
>>>>>> apt
>>>>>> > upgrade
>>>>>> > systemctl stop samba-ad-dc && systemctl
start samba-ad-dc
>>>>>> >
>>>>>> > Then I will upgrade to 4.9 and 4.10.
>>>>>> >
>>>>>> > If all goes well, I'll do it for DC Samba 4
Master.
>>>>>> >
>>>>>> > Regards,
>>>>>> >
>>>>>> > M?rcio Bacci
>>>>>> > --
>>>>>> > To unsubscribe from this list go to the following
URL and read the
>>>>>> > instructions:
https://lists.samba.org/mailman/options/samba
>>>>>> >
>>>>>> >
>>>>>>
>>>>>>
>>>>>> --
>>>>>> To unsubscribe from this list go to the following URL
and read the
>>>>>> instructions:
https://lists.samba.org/mailman/options/samba
>>>>>>
>>>>>