Solved

net time returns a DC in an alternate site that's not the PDC Emulator

Posted on 2004-08-31
6
271 Views
Last Modified: 2010-04-14
Why does the "net time" command run on an XP or W2K workstation (that are joined to a W2K native mode AD) return a domain controller in another site that does not hold the PDC Emulator role ?

The XP workstation, W2K workstation and the PDC Emulator are in different subnets bound to the same site.

Also, W2K domain controllers in a third site also return the same value.

It seems to me, these machines should be returning the value of the PDC Emulator for the domain.

0
Comment
Question by:kevinbeamer
6 Comments
 
LVL 25

Accepted Solution

by:
mikeleebrla earned 125 total points
ID: 11945978
if your workstation in question is XP and your domain is 2000 native  then the PDC emulator role is irrelivant.... as the PDC Emulator role is for backward compatibility with NT 4.0 DCs ...  the net time command will return the value of the autoritative time server for your domain, NOT the PDC emulator.  below is a link that explains how to set up the authoritative time server for your domain.  which site they are in is 100% irrelivant,,, as the time is set for the domain,,, not the site


http://support.microsoft.com/default.aspx?scid=216734
0
 

Author Comment

by:kevinbeamer
ID: 11948110
i think i've stumbled onto a microsoft undocumented feature :)

workstations, member servers and dc's in the same domain use the domain controller that comes first in the alphabet

even the pdc emulators themselves...

i know this sounds silly, but try it for yourself...

add a dc with an alphabetical name thats "higher" on the list and watch the output of "net time" shift to the new server.

i've tested this in all 5 domains in our forest and each time the result was predictable
0
 
LVL 16

Assisted Solution

by:JamesDS
JamesDS earned 125 total points
ID: 11949531
A few problems here !

The windows time service will sync workstations with the local DC and DCs will sync with the PDC emulator for the domain and then up through the forest to the root PDCE.

The PDCEmulator IS NOT IRRELEVANT ON AN AD DOMAIN. It is used (among many other things) for the timesynch and for "urgent" replication and password checking on recent change.

The NET TIME command WILL NOT NECESSARILY RETURN THE VALUE OF THE AUTHORITATIVE TIME SERVER FOR YOUR DOMAIN, it will return the time at the DC you authenticated against when you last booted up and logged on. If you run it at a DC it will return the time from the PDCEmulator for your domain.

The reason you seem to be getting the "highest" DC returning time is that all your DCs being tested are probably in the same site as you are and when DNS is queried for a local DC, it will return the IP of the DC first in the list - very possibly alphabetically.

If you had multiple sites and subnets and these were setup correctly then the DC returned would be the local one for your site.


Cheers

JamesDS
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Shell script to create broker configuration file using current broker Configuration, solely for purpose of backup on Linux. Script may need to be modified depending on OS-installation. Please deploy and verify the script in a test environment.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question