Good day guys,
I hope all is well on your side.
We are looking at implementing Samba4 on NethServer 7 to function as a (secondary) domain controller in an existing Active Directory environment currently managed by an existing single Windows Server 2016 server.
Aside from fairly easily-addressed sysvol replication challenges - looking at the official Samba documentation, it seems that nothing higher than a Domain/Forest Function Level of 2008r2 is supported, if Samba4 is to function as Domain Controller in an existing (Windows Server controlled) Active Directory environment?
The information available seems to indicate that the reason for this is due to changes within the Windows Server Kerberos services, that are possibly not available within MIT or Heimdal Kerberos?
Has anyone within the community had experience with this?
References:
https://wiki.samba.org/index.php/Raising_the_Functional_Levels
https://groups.google.com/forum/#!topic/linux.samba/kAbGkR4CGLg
https://docs.microsoft.com/cs-cz/windows-server/identity/ad-ds/active-directory-functional-levels
I would be most grateful for any guidance and feedback, if possible please.
Many thanks!