Re: Unable to authenticate users in windows 2003 SP1 secondary DC



Yes.

Try sharing and in your script map to the %logonserver% instead of a
specific name. The %logonserver% variable is popluated with the name of the
server the user has logged on to.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"MS" <lmathew@xxxxxxxxxxxxxxxxxx> wrote in message
news:ukXxdOjPHHA.320@xxxxxxxxxxxxxxxxxxxxxxx
Hi Paul,
Thanks for the info. I have the DC's setup exactly as you have mentioned.
Single domain, both DC's are GC, both DC's are DNS AD Integrated and
client able to ping both servers using IP and hostname.
On a second thought, is it because my PDC hosts user folders and apps
folders mapped to drives names, whereas, BDC also do contain these
folders for redundacy purpose, however they are not shared and mapped.
Could this create authentication issues like not being able to map the
drives(since it is trying to map the the share on the failed PDC) from
netlogon script and eventually authentication failing
Regards
Liby

"Paul Bergson [MVP-DS]" <pbergson@xxxxxxxxxxxxxxxxx> wrote in message
news:ut99d3iPHHA.1604@xxxxxxxxxxxxxxxxxxxxxxx
In 2000/2003 there is no longer the destinction of of pdc/bdc, only a
fsmo role of the PDC emulation. You don't need to do much of anything as
long as you have the domain setup to handle in accessible servers. You
need to make sure that both DC's are GC's (I assume this is a single
domain in your forest) and that both dc's are dns servers for AD (The
simplest for this is AD Integrated dns). Then your clients need to pint
to both of the dns servers for dns services. So if a dc is down the
client may attempt to access the downed dc but there will enough
intelligence to contact the available dc w/o any intervention by anyone.
As long as the other dc comes back online with in the tombstone period
(Defualt is usually 90 days if I recall correctly) you can go on without
doing anything.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"MS" <lmathew@xxxxxxxxxxxxxxxxxx> wrote in message
news:u2GQHsiPHHA.4172@xxxxxxxxxxxxxxxxxxxxxxx
Hi,
I have a PDC & BDC. PDC holds all the FSMO role. How would I make the
users authenticate with BDC, if my PDC is brought down(for testing). Do
I have to transfer / sieze all FSMO to BDC. I have PDC as primary DNS
and BDC as secondary DNS configured.
Any thoughts appreciated.
Liby







.



Relevant Pages

  • Re: BDC DCDIAG Problem
    ... I am looking through my DNS entries and I am only able to find SRV records ... for the PDC and not the BDC. ... Are there supposed to be records for the BDC as ... server Security Configuration Wizard on this server perhaps? ...
    (microsoft.public.windows.server.sbs)
  • Re: BDC DCDIAG Problem
    ... PDC and BDC are obsolete terms, ... I am looking through my DNS entries and I am only able to find SRV records ... server Security Configuration Wizard on this server perhaps? ...
    (microsoft.public.windows.server.sbs)
  • Re: DNS Issues - After Upgrading to ADS
    ... When I promoted the new hardware to PDC, it demoted the existing PDC to BDC ... Existing internal DNS servers. ... Are the Win2k using the same DNS server as the Win2k3? ...
    (microsoft.public.windows.server.dns)
  • Re: Logon problems after beginning AD migration
    ... the machines that are logging into the non-2003 ... BDCs to the DNS servers in the 2003 domain, ... It was barely adequate for 2003 server, so after I had a BDC in place, I tried to transfer the FSMO roles to the BDC so I could demote and reload it. ...
    (microsoft.public.win2000.active_directory)
  • Re: Major HELP requested - PDC dead in middle of Win2K UPgrade...
    ... At the same time this is happening, my BDC just seemed to have burned out its embedded video card as I cannot get it to come up on screen thru my KVM - so I've got really limited access to that and I don't want to bring it down to install a new video ... what's the best route to getting my domain back up and running "IF" I cannot get a PDC into the picture? ... So the three 'other' Win2K servers were part of the NT domain and that had four NT servers, one of them PDC, other BDC and two that ... At any rate the BDC was all we had and from prior experience I was not really trusting that machine - we were going to rebuild it (old as these are they are still ATX based and all dual PentII or better and have a backplane for 10 drives... ...
    (microsoft.public.win2000.setup_upgrade)