time in domain controlers

i have 2 dc in my network ,i want one of them to be authoritative time server for the domain
i did it on the server how holds the pdc by pointing to external ntp server by inserting parameter to be "time.windows.com,0x9"
how do i check and configure the second dc to be synchronize  with my ntp server?
for my workstation i configured gpo that points to the pdc server
LVL 2
ywainbergAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Scott AndersonPrincipal Support EngineerCommented:
As long as the computers are in the same domain, they should all time synch with the PDC in the domain, which is responsible for Domain Timekeeping.  Kerberos security for the domain is dependent on systems being relatively in synch (plus/minus 5 mins).  The PDC will be an external NTP Client to time.windows.com    and be an internal NT5DS time server for your domain.

You can check time synch on the 2nd server by checking the Event Viewer:System and look for w32time entries.  Believe it tries to synch/update the local time against the PDC every 3 hrs, as long as the server hasn't be pointed to some other time source (externally).  By default it should be using NT5DS  for it's time protocol, check in the registry:  HKLM\system\currentcontrolset\services\w32time\parameters   under the "Type" key.  It'll either be NT5DS or NTP.  NTP will configure it to use an external time source noted under the NtpServer registry key.

You can force a time synch by issuing:   net time /DOMAIN:{yourdomain} /SET

Hope this helps.
ywainbergAuthor Commented:
in ntp server parameter in the registry of the dc that is not pdc ,should it be the pdc server ip/dns name or should it be the "time.windows.com,0x9 ?
Scott AndersonPrincipal Support EngineerCommented:
If the "Type" key above is set to NT5DS, it will ignore the NTP Server entry and query time synch against the PDC emulator in your domain.

Take a look here for explanation of the registry entries for w32time:
http://technet.microsoft.com/en-us/library/cc773263(WS.10).aspx
10 Tips to Protect Your Business from Ransomware

Did you know that ransomware is the most widespread, destructive malware in the world today? It accounts for 39% of all security breaches, with ransomware gangsters projected to make $11.5B in profits from online extortion by 2019.

Scott AndersonPrincipal Support EngineerCommented:
Specifically:
---------------------------------------------------------------------------------
Type
Registry path:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
Version

Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008

This entry Indicates which peers to accept synchronization from:

    * NoSync. The time service does not synchronize with other sources.

    * NTP. The time service synchronizes from the servers specified in the NtpServer registry entry.

    * NT5DS. The time service synchronizes from the domain hierarchy.

    * AllSync. The time service uses all the available synchronization mechanisms.

The default value on domain members is NT5DS. The default value on stand-alone clients and servers is NTP.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
ywainbergAuthor Commented:
so,if version parameter is set to NT5DS ,it doesn't matter what is configured in the ntp server parameter because it will get it time sync from the pdc?did i understand correctly?
Scott AndersonPrincipal Support EngineerCommented:
Yessir!  Just curious, is your client currently in synch with your domain?
ywainbergAuthor Commented:
yes, i configured gpo for that
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.