Re: worst case scenario - added DC
- From: Ryan Hanisco <RyanHanisco@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 31 Oct 2007 19:52:00 -0700
Hi Totoro,
As meinolf points out, Kerberos doesn't have issues until the DC is more
than 5 minutes off of the domain time. You shouldn't have an issue though as
the DC should synchronize with the DC holding the PDCe role.
You also mentioned that you were planning to run a DC on a VMWare box. Have
a look at the following article for the major considerations when looking to
host a DC in a VM environment.
http://support.microsoft.com/kb/888794
You should also note that Microsoft has limited support for software in a
non-microsoft virtualized environment.
http://support.microsoft.com/default.aspx/kb/897615/
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
http://www.techsterity.com
Chicago, IL
Remember: Marking helpful answers helps everyone find the info they need
quickly.
"Meinolf Weber" wrote:
Hello totoro,.
It should be added without any problem. Time difference from 5 minutes is
ok. Just set the clock as near as possible to one of your running dc's and
after joining the domain it get's automatically the domain time.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm
Happy Halloween
I have a server set up on VMware that I will promote to DC, it will
join 3
actual DC's already.
I need to synchronize clocks because right now its 2 minutes off the
rest of
the network.
If I went ahead and promted it now, and resolved the time issue later,
considering I have 3 other DCs, what problems might I see?
Thanks for your responses!!
- Prev by Date: Re: Trust Validation
- Next by Date: Re: Transitive Trusts.
- Previous by thread: Re: Trust Validation
- Next by thread: Re: Transitive Trusts.
- Index(es):