Re: How to Fallback NT Domain incase of fail
- From: "Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx>
- Date: Thu, 4 May 2006 19:21:47 +0100
Hi
Ops...
Thanks Jorge for correcting me I was forgetting about the kerberos
authentication that Isn't supported in NT 4. In fact after the NT4 Upgrade
if your "new" Windows Server goes down, the clients that already had an
authentication with Kerberos can't authenticate with the "old" BDC.
Once again i'm sorry for the mistake (It has been some time that I don't use
NT 4 Domains).
--
I hop that helps
Good Luck
Jorge Silva
MCSA
Systems Administrator
"Jorge de Almeida Pinto [MVP]"
<SubstituteThisWithMyFullNameSeparatedByDots@xxxxxxxxx> wrote in message
news:O4V05U6bGHA.4896@xxxxxxxxxxxxxxxxxxxxxxx
correct and because of that you would need to rejoin all wxp/w2k/w2k3 that
have started using kerberos.
do it in steps...
first....
use the NT4Emulator key so that all w2k3 DCs emulate NT4. at this point
you w2k3 dcs and nt4 dcs....
test authentication by:
(1) shutting down NT4 DCs and using only w2k3 dcs
(2) shutting down w2k3 DCs and using only NT4 dcs
if things are not OK remove all w2k3 DCs and promote one NT4 DC to PDC.
(don't forget you also have a NT4 BDC "in the closed". you can use that
one the upgrade to AD screws your complete NT4 domain)
if everything is OK start by the NT4Emulator key and at that moment the
NT4 DCs will not be used after kerberos is being used. because of that you
can start removing the NT4 dcs.
in my experience I have NEVER seen this go wrong. however, make sure you
create a procedure to do this and make sure you test it!
--
Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto # MVP Windows Server - Directory Services
BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx
-----------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
-----------------------------------------------------------------------------
-----------------------------------------------------------------------------
"New User" <user@xxxxxxx> wrote in message
news:unvkIk5bGHA.1276@xxxxxxxxxxxxxxxxxxxxxxx
Jorge Silva wrote:
HiBut the Win2K & WinXP have change the Full name to the AD's name. I can't
If my memory serves me correctly the Windows 2000 machine can be taken
offline and the Windows NT 4.0 BDC can be promoted to a PDC in the NT
domain.
login with original NT Domain!
.
- Follow-Ups:
- Re: How to Fallback NT Domain incase of fail
- From: Jorge de Almeida Pinto [MVP]
- Re: How to Fallback NT Domain incase of fail
- References:
- How to Fallback NT Domain incase of fail
- From: New User
- Re: How to Fallback NT Domain incase of fail
- From: Jorge de Almeida Pinto [MVP]
- Re: How to Fallback NT Domain incase of fail
- From: New User
- Re: How to Fallback NT Domain incase of fail
- From: Jorge Silva
- Re: How to Fallback NT Domain incase of fail
- From: New User
- Re: How to Fallback NT Domain incase of fail
- From: Jorge de Almeida Pinto [MVP]
- How to Fallback NT Domain incase of fail
- Prev by Date: Re: How to Fallback NT Domain incase of fail
- Next by Date: Re: How to Fallback NT Domain incase of fail
- Previous by thread: Re: How to Fallback NT Domain incase of fail
- Next by thread: Re: How to Fallback NT Domain incase of fail
- Index(es):
Relevant Pages
|