Configure Windows Time on Win Server 2003 Root Domain Controller



Hi All

I have reviewed all the documentation that I have located on the Windows
Time Service in Windows Server 2003. However, I still feel somewhat shaky
about this topic, so I would appreciate your help to make sure that I have
configured both the server and the clients correctly.

GENERAL INFORMATION
1) We have a small client/server network. The Root Domain Controller has THE
WinDOWS Server 2003 SP1 Op Sys, & there are 5 clients using either Win XP Pro
SP2 or Win2000 Pro. Just to confirm, there is only 1 DC in this network.

2) The Root Domain Controller is the network's reliable time server so the
following entries are in its registry:

-HKEY_LOCAL-MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Config has
AnnounceFlags set to (5).

-In W32Time\Parameters Type is set to NTP.

-In W32Time\TimeProviders\NtpServer has Enabled set to (1)

3) In W32Time\Parameters,the entry in NtpServer is:

0.north-america.pool.ntp.org,0x1 1.north-america.pool.ntp.org,0x1
2.north-america.pool.ntp.org,0x1 time-a.nist.gov,0x1


QUESTIONS:
(a) In point 3) above, how is the manualpeerlist entry used?

-Does Windows Time Service try to connect to the first entry in the list,
0.north-america.pool.ntp.org,0x1, and then if that fails does it then try the
second location in the list?

-Or does it contact each address in the list, and then average the times
before synching the DC's time?

-Or does it rotate sequentially through each address in the list as each
new time check is made?

(b) In W32time\Paramters, I appended the 0x1 switch to the end of each
address entry. Please note that I did not place a space between the end of
the address name (time-a.nist.gov,0x1) and the comma before the 0x1 switch.
Is the lack of a space correct?

(c) In W32Time\Parameters, I think that appending the 0x1 switch to an
address means that Windows Time Service in the Root Domain Controller will
connect to the internet-based time server(s) every ??-seconds where
(??-seconds) is the number entered in the W32Time\TimeProviders\NtpClient
entry for SpecialPollInterval. I have 3600 entered here, so I believe that
means that the RDC tries to contact 0.north-america.pool.ntp.org0x1 every 1
hour. Is this correct? If it is not, then how does one control how frequently
the RDC contacts the time server(s)?

(d) All of the client computers were joined to the network and then were set
to their default w32time settings using the following procedure from the
command line:

-w32tm /unregister <Enter Key>
-w32tm /register <Enter Key>
-net start w32time <Enter Key>
-w32tm /resync <Enter Key>

Will this procedure set the clients to automatically use the RDC as their
time source? Please advise Which setting controls how frequently that they
will automatically connect to the RDC to synchronize their time?

Thanks for your help!!
.



Relevant Pages

  • Re: Lsasrv Event ID 40960
    ... I have checked with Nslookup both my forward and recursive zones and get the correct answer every time... ... The Security System detected an authentication error for the server ... The thing is on my other windows 2003 member servers I don't get this ... Usually creating a reverse zone for your subnetand insuring all DCs have a PTR entry to eliminate this error. ...
    (microsoft.public.win2000.active_directory)
  • Re: nt 4 upgrade to windows 2003 server question
    ... The following procedure describes how to safely rename a Windows NT domain. ... Stop all BackOffice services such as Microsoft Exchange Server, ... This will cause the entry for the new domain to ... necessary for each BDC to successfully change to the new domain name. ...
    (microsoft.public.windows.server.general)
  • Re: Use DNS Server to block IPs of bad sites
    ... > Since all the PCs use the Windows 2000 Server for DNS ... For the www entry and the entry, ... Please direct all replies ONLY to the Microsoft public newsgroups ...
    (microsoft.public.win2000.dns)
  • Tiny Personal Firewall 3!!!!
    ... windows 2000 server and has done the job of preventing unauthorized ... entry after a recent security breach. ... as the updates are still denyed. ...
    (comp.security.firewalls)
  • Tiny Personal Firewall 3!!!!
    ... windows 2000 server and has done the job of preventing unauthorized ... entry after a recent security breach. ... as the updates are still denyed. ...
    (comp.security.firewalls)