|
53 |
</programlisting> |
53 |
</programlisting> |
54 |
|
54 |
|
55 |
</section> |
55 |
</section> |
|
|
56 |
|
57 |
<section> |
58 |
<title>Uninstallation of a Samba 4 domain controller</title> |
59 |
<para> |
60 |
The removal of an Samba 4 DC (Active Directory-compatible domain controller) is a |
61 |
far-reaching configuration step and should be prepared thoroughly. |
62 |
</para> |
63 |
|
64 |
<para> |
65 |
At least on one DC master or DC backup must be the samba 4 packages installed in case |
66 |
the domain should be Active Directory-compatible. |
67 |
</para> |
68 |
|
69 |
<para> |
70 |
Before uninstalling the packages the domain controller must be removed from Samba 4. |
71 |
That can be done with the helper script purge_s4_computer.py. It must be run on a DC |
72 |
master or DC backup system. |
73 |
The question 'Really remove master from Samba 4?' must be answered with Yes and |
74 |
the question 'Really remove master from UDM as well?' must be answered with No, |
75 |
e.g: |
76 |
</para> |
77 |
|
78 |
<programlisting language="sh"> |
79 |
root@backup:~# /usr/share/univention-samba4/scripts/purge_s4_computer.py --computername=master |
80 |
Really remove master from Samba 4? [y/N]: Yes |
81 |
If you are really sure type YES and hit enter: YES |
82 |
Ok, continuing as requested. |
83 |
|
84 |
[...] |
85 |
Removing CN=MASTER,CN=Computers,$ldap_BASE from SAM database. |
86 |
Really remove master from UDM as well? [y/N]: No |
87 |
Ok, stopping as requested. |
88 |
|
89 |
root@backup:~# |
90 |
</programlisting> |
91 |
|
92 |
<para> |
93 |
The S4 connector must be run on one DC master or DC backup in the domain. If samba4 |
94 |
was uninstalled on a DC master or DC backup the S4 connector join |
95 |
(97univention-s4-connector) script should be re-executed on another system. That can |
96 |
be done via the UMC module 'Domain join', see <xref linkend="s4connector-rejoin"/>. |
97 |
</para> |
98 |
|
99 |
<figure id="s4connector-rejoin"> |
100 |
<title>Re-execute S4 connector join</title> |
101 |
<graphic scalefit="1" width="80%" fileref="illustrations/s4connector-re-execute.png"/> |
102 |
</figure> |
103 |
|
104 |
<para> |
105 |
The FSMO (Flexible Single Master Operations) roles should be checked. In case the |
106 |
roles are used by the removed DC, they should be transfered, for example: |
107 |
</para> |
108 |
<programlisting language="sh"> |
109 |
root@backup:~# samba-tool fsmo show |
110 |
InfrastructureMasterRole owner: CN=NTDS Settings,CN=MASTER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dom,DC=local |
111 |
RidAllocationMasterRole owner: CN=NTDS Settings,CN=MASTER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dom,DC=local |
112 |
PdcEmulationMasterRole owner: CN=NTDS Settings,CN=MASTER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dom,DC=local |
113 |
DomainNamingMasterRole owner: CN=NTDS Settings,CN=MASTER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dom,DC=local |
114 |
SchemaMasterRole owner: CN=NTDS Settings,CN=MASTER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=dom,DC=local |
115 |
|
116 |
root@backup:~# samba-tool fsmo seize --role=all --force |
117 |
Will not attempt transfer, seizing... |
118 |
FSMO transfer of 'rid' role successful |
119 |
Will not attempt transfer, seizing... |
120 |
FSMO transfer of 'pdc' role successful |
121 |
Will not attempt transfer, seizing... |
122 |
FSMO transfer of 'naming' role successful |
123 |
Will not attempt transfer, seizing... |
124 |
FSMO transfer of 'infrastructure' role successful |
125 |
Will not attempt transfer, seizing... |
126 |
FSMO transfer of 'schema' role successful |
127 |
root@backup:~# |
128 |
</programlisting> |
129 |
|
130 |
|
131 |
</section> |
56 |
</chapter> |
132 |
</chapter> |
57 |
|
133 |
|
58 |
<bibliography> |
134 |
<bibliography> |