Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Changing Domain Controller time

Posted on 2010-11-09
6
Medium Priority
?
920 Views
Last Modified: 2012-05-10
Hi All,

I have a single forest single domain structure with 70 domain controllers throughout different locations. There are more than 10000 clients in the domain. It has been observed that the DC's are running 6 mins late than the usual time and due to which some critical application are facing problems. I need to achieve the below mentioned things.

1. Need to explain why the time is deffered to the management
2. Need to correct the issue but I think I cannot do it in one day because kerberos time skew issue might occur as it is more than 5 mins.

Thanks and Regards
0
Comment
Question by:Neo_78
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 34095258
The first thing I'd do is go through the following blog entries on time
http://tigermatt.wordpress.com/2009/08/01/windows-time-for-active-directory/ 
 http://blogs.dirteam.com/blogs/jorge/archive/2010/09/27/configuring-and-managing-the-windows-time-service-part-1.aspx  This is a four part series so the other parts are there on Jorge's blog
Check to make sure your time is setup properly.  Since it is a single forest/domain your PDCe should be set to configure with an external/reliable source and then the time hiearchy shoudl take over from there.
Thanks
Mike
0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 34095261
You would need to setup your current PDC emulator to get it's time from an external time source.

TigerMatt has a great article on this. http://tigermatt.wordpress.com/2009/08/01/windows-time-for-active-directory/

Once you have this DC running with a proper external time source then your other DCs and clients will update through the domain hierarchy.
0
 

Author Comment

by:Neo_78
ID: 34095475
We do not have option to sync with external time server at this time. PDC is configured to sync the time with hardware clock. I need to change the time manually in PDC but reducing 6 mins at a time might create problem.


Kindly suggest.
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 59

Accepted Solution

by:
Darius Ghassem earned 668 total points
ID: 34095577
Could cause an issue since you are over 5 minutes. You could go to 4 minutes by changing the internal clock of the PDC server allow time to filter then you can setup a proper external time source.
0
 
LVL 12

Assisted Solution

by:Rant32
Rant32 earned 668 total points
ID: 34096014
What exactly is your PDCe synchronizing with? Please give us this feedback, dependent on the server OS:

For 2003: net time /querysntp
For 2008: w32tm /query /peers

The computer's time will run out of sync, when it's not synchronizing with an external clock, simply because the server's hardware (realtime) clock is not a reliable time-keeper. The clock is not of high enough quality. It gets even worse in Virtual Machines.

Setting up to sync with a reliable time source should be a priority. As noted, that should be configured on the DC holding the PDC emulator role, and, important, the NTP peer list should be maintained when the PDC emulator role moves to another server.

I know there exist serial or networked GPS devices that can supply reliable time, if you don't want to use an external (untrusted) source. Or have another Windows/Linux host, with an internet connection, to proxy the time to your PDC. I have personally used the servers from pool.ntp.org for many years and found them very reliable.

It is also best practice to make sure that the PDCe cannot make huge time leaps (when retrieving time from another NTP server) by properly configuring the parameters for the W32Time service.

These articles probably have everything you want to know about the W32Time service:
Windows Time Service Technical Reference
How the Windows Time Service Works
Windows Time Service Tools and Settings

You obviously don't want a jump back in time (not even a minute). W32Time has provisions to slowly correct time instead of making the clock jump, but that will only work when synchronizing from an external time source.

Pay special attention to other operating systems: if your time-critical apps are running on non-Windows, then you have to take care of synchronizing them as well. Your internal stratum 2 or 3 servers (domain controllers) can act as an NTP server to ntpd and the likes.
0
 
LVL 6

Assisted Solution

by:JRoyse
JRoyse earned 664 total points
ID: 34215385
If you can't sync time to the internet (For security reasons?) you can purchase a "time server" that has an outside antennae to grab accurate time from the GPS satellites.  Then you can point the AD servers there for time.  Works for the military.

just an example
http://www.spectracomcorp.com/ProductsServices/TimingSynchronization/NetworkTimeServers/tabid/112/Default.aspx
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
Suggested Courses

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question