Re: Moving an ADAM instance



The proper way to do this is with a replicated instance. The problem you are having is that ADAM doesn't have its own account policy, it is entirely dependent on the machine's policy and it sounds like the two machines have different password policies. Your problem isn't in ADAM, it is in the configuration of the policy on the machines.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Chuck wrote:
Hello,

I am having some trouble moving an ADAM instance from one physica server to another.

The first method I tried was to set up the new server as a replication server. This worked in my trial environment, but like so many other times, not in production. The data all appeared to replicate fine, but users were unable to authenticate against the replicated server. When looking through the user properties, I noticed that ms-DS-UserPasswordExpired was set to TRUE in the replication instance, but not in the publishing instance. A quick bit of research told me that this is a constructed value. This is where my attempt with this method dead ended because I know little about password expiration rules in AD. I know even less when the server in question is not part of a domain. And I know absolutely nothing about how these features might relate to ADAM or how ADAM constructs this value and can not seem to find any information on such. This seems to be the easier approach and is also the approach recommended by Joe Kaplan, so if anyone has any ideas about this, thanks.

The second approach I took which once again worked in test but stumped me in production was to use ADSchemaAnalyzer to duplicate the schema to a new ADAM instance, then synchronize the data with adamsync. I got to the point of trying to install my synchronization configuration into the new instance, but received an error every time I tried. According to the boards, the error message I received was what I should expect if I had not loaded the MS-AdamSyncMetadata.LDF into the new repository, but we have a screen capture of the session and this was definately done. If there are no good ideas on how to solve the problem with my first approach, feel free to fire away with ideas on this one.

I would prefer to use the replication approach, but any help or new ideas would be welcome indeed. If you need any other information, please let me know.

Thanks much,

Chuck
.



Relevant Pages

  • Re: Creating a Computer Object in ADAM
    ... I've never replicated an ADAM ... Win 2003 server down to my instance, but fails from my XP instance ... 'The attempt to establish a replication link for the following writable ... Source directory service address: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Creating a Computer Object in ADAM
    ... Definitely have replication problems. ... The directory server has failed to update the host name and/or ports ... I can't seem to get connected to my local instance of ADAM running ... Running partition tests on: Schema ...
    (microsoft.public.windows.server.active_directory)
  • Re: Creating a Computer Object in ADAM
    ... ADAM, on Win2003, and one other instance, created as a replica of the ... Win 2003 server down to my instance, but fails from my XP instance ... 'The attempt to establish a replication link for the following writable ... Source directory service address: ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD/AM Replication Problem
    ... Server A is replicating to Server B with no ... The following errors are in the ADAM log on Server B that are happening ... Event Source: ADAM Replication ... collected (a tombstone lifetime or more has past since the object was ...
    (microsoft.public.windows.server.active_directory)
  • RE: Replication works off and on after upgrading to 2003 from 2000 server?
    ... Verify that the password policy has ... support incident via telephone so that a dedicated Support Professional can ... Replication works off and on after upgrading to 2003 from ... 2000 server? ...
    (microsoft.public.windows.server.migration)

Loading