Samba AD DC & BIND

Directory & DNS operations

samba-tool domain provision
Create a new AD DC (danger: destructive)
samba-tool domain provision --use-rfc2307 --realm EXAMPLE.COM --domain EXAMPLE --server-role dc
sambaad-dcinit
systemctl status samba-ad-dc
Check AD DC service
systemctl status samba-ad-dc
systemdsamba
samba_upgradedns
Convert/bind9 DLZ or internal DNS
samba_upgradedns --dns-backend=BIND9_DLZ
dnsmigration
kinit / kvno
Get Kerberos ticket / verify SPN
kinit Administrator
kvno DNS/host.example.com
kerberos
nsupdate -g
Dynamic DNS update using GSS-TSIG
nsupdate -g <<'EOF'
server 127.0.0.1
zone example.com.
update add host.example.com. 300 A 192.0.2.10
send
EOF
dnsgss-tsig
rndc flush / reload
Control Bind9
rndc status
rndc reload
rndc flush
bind9
samba-tool spn add
Add service principal name
samba-tool spn add DNS/host.example.com HOSTNAME$
spn
samba-tool user setpassword
Reset machine/user password
samba-tool user setpassword HOSTNAME$
account
samba-tool dns query
Query zone via RPC
samba-tool dns query 127.0.0.1 example.com @ ALL -UAdministrator
dnsrpc