Solved

Changing Domain Controller time

Posted on 2010-11-09
6
911 Views
Last Modified: 2012-05-10
Hi All,

I have a single forest single domain structure with 70 domain controllers throughout different locations. There are more than 10000 clients in the domain. It has been observed that the DC's are running 6 mins late than the usual time and due to which some critical application are facing problems. I need to achieve the below mentioned things.

1. Need to explain why the time is deffered to the management
2. Need to correct the issue but I think I cannot do it in one day because kerberos time skew issue might occur as it is more than 5 mins.

Thanks and Regards
0
Comment
Question by:Neo_78
6 Comments
 
LVL 57

Expert Comment

by:Mike Kline
Comment Utility
The first thing I'd do is go through the following blog entries on time
http://tigermatt.wordpress.com/2009/08/01/windows-time-for-active-directory/
 http://blogs.dirteam.com/blogs/jorge/archive/2010/09/27/configuring-and-managing-the-windows-time-service-part-1.aspx  This is a four part series so the other parts are there on Jorge's blog
Check to make sure your time is setup properly.  Since it is a single forest/domain your PDCe should be set to configure with an external/reliable source and then the time hiearchy shoudl take over from there.
Thanks
Mike
0
 
LVL 59

Expert Comment

by:Darius Ghassem
Comment Utility
You would need to setup your current PDC emulator to get it's time from an external time source.

TigerMatt has a great article on this. http://tigermatt.wordpress.com/2009/08/01/windows-time-for-active-directory/

Once you have this DC running with a proper external time source then your other DCs and clients will update through the domain hierarchy.
0
 

Author Comment

by:Neo_78
Comment Utility
We do not have option to sync with external time server at this time. PDC is configured to sync the time with hardware clock. I need to change the time manually in PDC but reducing 6 mins at a time might create problem.


Kindly suggest.
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 167 total points
Comment Utility
Could cause an issue since you are over 5 minutes. You could go to 4 minutes by changing the internal clock of the PDC server allow time to filter then you can setup a proper external time source.
0
 
LVL 12

Assisted Solution

by:Rant32
Rant32 earned 167 total points
Comment Utility
What exactly is your PDCe synchronizing with? Please give us this feedback, dependent on the server OS:

For 2003: net time /querysntp
For 2008: w32tm /query /peers

The computer's time will run out of sync, when it's not synchronizing with an external clock, simply because the server's hardware (realtime) clock is not a reliable time-keeper. The clock is not of high enough quality. It gets even worse in Virtual Machines.

Setting up to sync with a reliable time source should be a priority. As noted, that should be configured on the DC holding the PDC emulator role, and, important, the NTP peer list should be maintained when the PDC emulator role moves to another server.

I know there exist serial or networked GPS devices that can supply reliable time, if you don't want to use an external (untrusted) source. Or have another Windows/Linux host, with an internet connection, to proxy the time to your PDC. I have personally used the servers from pool.ntp.org for many years and found them very reliable.

It is also best practice to make sure that the PDCe cannot make huge time leaps (when retrieving time from another NTP server) by properly configuring the parameters for the W32Time service.

These articles probably have everything you want to know about the W32Time service:
Windows Time Service Technical Reference
How the Windows Time Service Works
Windows Time Service Tools and Settings

You obviously don't want a jump back in time (not even a minute). W32Time has provisions to slowly correct time instead of making the clock jump, but that will only work when synchronizing from an external time source.

Pay special attention to other operating systems: if your time-critical apps are running on non-Windows, then you have to take care of synchronizing them as well. Your internal stratum 2 or 3 servers (domain controllers) can act as an NTP server to ntpd and the likes.
0
 
LVL 6

Assisted Solution

by:JRoyse
JRoyse earned 166 total points
Comment Utility
If you can't sync time to the internet (For security reasons?) you can purchase a "time server" that has an outside antennae to grab accurate time from the GPS satellites.  Then you can point the AD servers there for time.  Works for the military.

just an example
http://www.spectracomcorp.com/ProductsServices/TimingSynchronization/NetworkTimeServers/tabid/112/Default.aspx
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now