Univention Corporate Server

Extended Windows integration documentation

1.1. Operating Samba 4 as a read-only domain controller

Active Directory offers an operating mode called read-only domain controller (RODC) with the following properties:

  • The data are only stored in read-only format; all write changes must be performed on another domain controller.

  • Consequently, replication is only performed in one direction.

A comprehensive description can be found in the Microsoft TechNet Library [technet-rodc].

A Samba 4 domain controller can be operated in RODC mode (on a slave domain controller for example). Prior to the installation of univention-samba4, the Univention Configuration Registry variable samba4/role must be set to RODC:

ucr set samba4/role=RODC
univention-install univention-samba4


