You are here
sgp - Sat, 2025/06/07 - 09:34
I had TKDC as AD for a while. So far so good. Now I want to deploy a second TKDC as a read-only domain controller. Is there any guide/doc on this? I was stuck at
kinit: Cannot find KDC for realm "MY.DOMAIN" while getting initial credentials when trying to simply add a second instance to the domain. Perhaps I could resolve this issue, but that leaves me with a question: "Am I even on the right way?" Will there be an option for RODC later? So here I am, looking for help/advice.Forum:
Tags:
Unfortunately, we have no doc on setting up an RODC
Unfortunately, we have no doc on setting up an RODC. Hopefully I can give some guidance, but I'm a Linux guy. I have played with Samba4 and ADDCs a bit but have never administered a Samba4 ADDC in production.
There is a Samba wiki RODC page but it looks like the last update was 2017. I haven't tested it, but looking over that my guess is that the process/commands is/are the same. However, I imagine that more recent Samba4 versions would have addressed some of the noted TODOs and short comings of the Samba RODC implementation.
Having said that, the error message you are getting sounds more like a DNS issue. Have you configured your new server to get it's DNS from your other DC? If not, that would be the first step.
If you continue to have issues, then post back and I'll have a closer look.
As to your question/suggestion re a TurnKey RODC appliance, I think that's a cool idea. I think that the best way for us to go would be to update the current appliance to offer RODC config as an option on first boot. I.e. where you choose whether to create a new domain or link to an existing domain, have a 3rd option to join an existing domain as a RODC. I've opened a new issue to track that (although no promises when we might include it).
Assuming that you can get it working, sharing your experience would be a great help to push that forward.
Add new comment