Solved

Time Skew Vs. Synchronization

Posted on 2011-03-17
8
1,115 Views
Last Modified: 2012-06-21
In a Windows 2003 AD domain

Is there a time skew range between which a computer will/will not synchronize its clock?

I know Kerberos Authentication, by default, will not occur if the skew is >5min.

(I.E. If workstation time differs from server time by ____ minutes time synchronization fails?)

0
Comment
Question by:alexianit
  • 2
  • 2
  • 2
  • +1
8 Comments
 
LVL 5

Expert Comment

by:BatchV
ID: 35156542
Hi Have a look at this link, it explains in detail your question

http://support.microsoft.com/?kbid=224799
0
 
LVL 27

Expert Comment

by:michko
ID: 35156718
the referenced article above refers to windows 2000 specifically.  some of the information is still applicable to a server 2003 domain, but not all.

From my understanding, there is not a time skew range between which a computer will not synchronize its clock.  

there is a time skew range of 5 minutes on 2003 domain where things actions differ.

if the time skew is less than 5 minutes ahead, then the computer will slow its clock until it matches the synchronizing server time.

If the time skew is more than 5 minutes ahead, the computer will immediately match to the synchronizing server time.

If the time skew is behind the server time, then the computer will immediately match to the synchronizing server time.

Note that in windows 2000 the actions are the same, but the time skew is 3 minutes instead of 5.

technical reference for Windows Server 2003 and later if you're interested:
http://technet.microsoft.com/en-us/library/cc773061%28WS.10%29.aspx#w2k3tr_times_intro

0
 
LVL 24

Accepted Solution

by:
Dr. Klahn earned 125 total points
ID: 35156869
Yes, there are time difference adjustement limits for some systems.  Microsoft discusses this in KB884776.

"The Windows 32 time service supports two registry entries, the MaxPosPhaseCorrection and the MaxNegPhaseCorrection."

For Windows XP and Server 2003, "The default value of these two registry entries is 0xFFFFFFFF. This default value means 'Accept any time change.'"  In my experience this is not correct; XP systems out of the box do have limits.

For standalone systems, "The MaxPosPhaseCorrection and MaxNegPhaseCorrection registry entries have a default value of 54,000 (15 hours). As a security best practice, we recommend that you reduce this default value. We also recommend that you set the value to 3600 (1 hour) or an even smaller value, depending on time source, on network condition, on poll interval, and on security requirements."
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 24

Expert Comment

by:Dr. Klahn
ID: 35156890
As a side issue, the MaxPosPhaseCorrection and MaxNegPhaseCorrection limits do not affect changes to and from Daylight Saving Time.
0
 
LVL 5

Expert Comment

by:BatchV
ID: 35157125
If workstation can logon to domain it will always correct time automatically however if the time difference is too great than the workstation will fail to logon to domain and you will get an error message warning you about this. I believe this is where the default value of 15hours comes in.
0
 

Author Comment

by:alexianit
ID: 35393740
Objecting to accept answers.
0
 

Author Closing Comment

by:alexianit
ID: 35393748
Good answer!
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now