Ubuntu Xenial下Samba 4.3.11 AD架构版本升级方法咨询
Hey Peter, let's break down exactly how to get your AD schema upgraded since you're running Samba 4.3.11 as your sole AD-DC (migrated from a single Win2k3 server). First, critical note: schema upgrades are irreversible, so let's start with a rock-solid backup to cover our bases.
Step 1: Back Up Your Samba AD Data
Run this command to create a full backup of your domain data—store it somewhere safe, not on the same server:
samba-tool domain backup --targetdir /path/to/secure/backup/location
Step 2: Verify Current Schema Version
First, confirm your current schema version to know where we're starting from:
samba-tool schema show | grep -i "objectVersion"
You mentioned your current objectVersion is 30, which maps to the Windows Server 2003 schema. Samba 4.3.11 supports upgrading up to the Windows Server 2012 R2 schema (version 69), but you can stop at intermediate versions like 44 (2008) or 47 (2008 R2) if you prefer.
Step 3: Run the Schema Upgrade
Samba has a built-in tool to handle schema upgrades—no need for the Windows adprep utility here. To upgrade to the highest supported schema version for your Samba release, run:
samba-tool domain schemaupgrade
If you want to target a specific schema version (say, 47 for Windows Server 2008 R2), add the --target-version flag:
samba-tool domain schemaupgrade --target-version=47
This command will automatically update the schema across your ForestDnsZones, DomainDnsZones, and default site partitions.
Step 4: Confirm the Upgrade Worked
After the command finishes, double-check that the schema version updated correctly:
samba-tool schema show | grep -i "objectVersion"
You should see your target version number here (e.g., 47 or 69) instead of the original 30.
Optional: Raise Domain/Forest Functional Levels
Now that your schema is upgraded, you can optionally raise your domain and forest functional levels to match (since you're currently at 2008_R2 domain and 2008 forest). For example, to jump to 2012_R2 levels:
# Raise domain functional level samba-tool domain level raise --domain-level=2012_R2 # Raise forest functional level samba-tool domain level raise --forest-level=2012_R2
Just like schema upgrades, functional level raises are irreversible—make sure your Samba version supports the target level (4.3.11 does support 2012_R2).
Quick Tips to Avoid Issues
- Make sure the Samba service is running smoothly before starting the upgrade—no interruptions mid-process.
- Shut down any apps or services that might modify AD data during the upgrade to prevent conflicts.
- If you hit errors, check the Samba logs at
/var/log/samba/samba.logfor details. If things go sideways, restore from your backup immediately.
内容的提问来源于stack exchange,提问作者Peter

