?
Solved

difficulty in adding a second domain controller windows 2003 server

Posted on 2006-06-30
4
Medium Priority
?
308 Views
Last Modified: 2010-04-18
Hi Experts,
I have a DC running 2003 enterprise AD
i have 3 other servers, all on the same domain.
One of my servers is in the DMZ and serves as a Secure Gateway for a citrix server.
Some of the reading I have done suggests it is not a good idea to keep the SG server on the same domain as the rest.
How difficult is it to make that SG server a domain controller (probably using the wrong term)  

I would like the SG to have abc.com domain instead of the abc.net domain.

If you could give me a step by step on this I would appreciate it.  I'm not an expert.
0
Comment
Question by:Quadeeb2003
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 17021630
Is it necessary to even have the DMZ server be a DC?

You should be able to setup this server to host an IIS (web) front-end for the Citrix server and have clients connect using the ICA client.  This way only a very small hole needs to be open to the real domain.

0
 
LVL 1

Author Comment

by:Quadeeb2003
ID: 17021685
I have SG server hosting IIS and WI, but it is on the same domain.
A benefit of switching the server to its own domain is I can use an outside CA certificate for my server on that domain.  The FQDN of my internal network cannot have a outside CA certificate because the domain is public.  ABC.net for example.
If the SG server becomes a DC for a different domain, I make a few trusts from my DC, and I would imagine I would be in business.

It is a new server, there are no apps other than citrix, and reinstalling would be a snap.
0
 
LVL 51

Accepted Solution

by:
Netman66 earned 2000 total points
ID: 17021704
I suppose it would work although I'm not sure you really need it to be a DC.  You should be able to use ADAM for authentication and keep it entirely separate.

However, yes, I agree that a different domain would be proper - if the current domain was compromised then your entire AD would be exposed.

0
 
LVL 1

Author Comment

by:Quadeeb2003
ID: 17022207
So, any idea how to get it done?
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question