Re: Stuck with NT4 DC?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Your point is well taken Joe, but I have talked to them about this until I'm
blue in the face. They just cannot justify the cost of upgrading the Citrix
box, and they cannot stop giving remote sales people access to their DB. I
was able to talk them into a CheckPoint NG/AI FW, and that helps a lot,
but...

I will try out Upromote today, and hope it doesn't break the Citrix.
Meantime, we can all pray for a system board malfunction. (I pray for that
all the time on this box)

"Joe Richards [MVP]" wrote:

Yes currently, but there is no guarantee as we move further and further
from NT4 it will continue working, especially with the push on security
and disabling all of the older protocols which are all quite insecure.
There are quite a few holes in NT4 now that are not in the later Windows
products because Microsoft is no longer patching NT4. I wouldn't even
start to consider to allow an NT4 BDC in a domain right now. It is
possible to compromise the entire forest with it.

It is quite important that you tell the customer to start working now to
move that app or else they will eventually hit a dead end.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


NewsGr wrote:
Yes, I have 2 (old pdc and old bdc) NT4 servers that are running as member
servers in 2003 domain.
All of their services are still running.
craig
"LoneWolf" <LoneWolf@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5FA7E600-FB1B-4568-9B9C-7FB7D91A0639@xxxxxxxxxxxxxxxx
And this ancient beast will still be able to run as a server in a 2003
domain?

"NewsGr" wrote:

I once used a program called Upromote. it saved me from hours-maybe
days
of work. It demoted my old NT4 PDC and BDC to
member servers in the 2003 AD. Did the both in about 15 minutes. No
complications.

Craig

"LoneWolf" <LoneWolf@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:470414F6-741C-4195-A892-0CC0B53E5721@xxxxxxxxxxxxxxxx
I have a customer who has an old NT4 BDC in a Win2k AD. The NT server
is
running Citrix, and it is critical to opps. Now they want 2003 style
DFS
etc, but they aren't willing to pay to upgrade the Citrix box. Can I
upgrade
the other DC's without breaking the NT4/Citrix server? Is there any
way
to
demote the NT4 beast and still run the Citrix?

Thanks.





.



Relevant Pages

  • Exchange 2007 - migrating away from old NT4 domain controller? Citrix?
    ... Since then, we install a Windows 2000-based server, migrated the domain to Windows 2000 Active Directory, and now run Exchange 2000. ... the domain is configured in Mixed Mode and we allowed the old NT4 server to remain as a backup domain controller. ... We aren't quite ready to retire this old NT4 server or our old Citrix server. ...
    (microsoft.public.exchange.admin)
  • Re: Stuck with NT4 DC?
    ... Yes currently, but there is no guarantee as we move further and further from NT4 it will continue working, especially with the push on security and disabling all of the older protocols which are all quite insecure. ... Joe Richards Microsoft MVP Windows Server Directory Services ... but they aren't willing to pay to upgrade the Citrix box. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Failed to create a trust relationship between NT4 and 2003 AD
    ... For Windows 2000 and 2003 these settings may be applied/configured via ... Digitally sign communications (if server ... With NT4 the only way to verify the settings is with the Regedt32 tool. ... Failed to create a trust relationship between NT4 and 2003 AD ...
    (microsoft.public.windows.server.migration)
  • RE: Failed to create a trust relationship between NT4 and 2003 AD
    ... Ping -a IP -- work and resolve the NT4 server name ... security policy in Administrative tools, go to local policies / security ... For Windows 2000 and 2003 these settings may be applied/configured via ...
    (microsoft.public.windows.server.migration)
  • RE: Failed to create a trust relationship between NT4 and 2003 AD
    ... is that a must to do for all setting when NT4 ... For Windows 2000 and 2003 these settings may be applied/configured via ... minutes in Windows 2003 Server ... Failed to create a trust relationship between NT4 and 2003 AD ...
    (microsoft.public.windows.server.migration)