[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Additional domain controller server 2003

Posted on 2011-10-17
11
Medium Priority
?
213 Views
Last Modified: 2012-05-12
I have a client that has a 2003 DC and 4 member servers. One of the member servers is running DNS also. If I run DCPROMO on the member server running DNS it says that I need to remove the certificate services first. Can I assume that it is not a secondary DC? If I promote another member server as a DC will it give me logon redundancy if DC1 goes down or will I have to manually tell DC2 to assume that role?
0
Comment
Question by:jeffreychorba
  • 4
  • 4
  • 2
  • +1
11 Comments
 
LVL 5

Accepted Solution

by:
mrklaxon earned 2000 total points
ID: 36979228
Logon redundancy is automatic.  You may want to research other roles like Global Catalog to consider how redundant you want to be.

Look in Active Directory Users and Computers under Domain Controllers for a list of current DCs.
0
 
LVL 13

Expert Comment

by:Govvy
ID: 36979232
On first DC run 'netdom query dc' to confirm your current domain controllers

The member server which runs certificate services excludes it from being a DC - you can check your PKI configuration via ADSIEDIT>Configuration>Services>Public Key Services

If you promote another member server to a DC it will provide logon redundancy
0
 
LVL 27

Expert Comment

by:Jason Watkins
ID: 36979445
Once Certificate Services is installed on a server, it cannot be changed and should not. Find another machine to be a DC.

0
Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

 

Author Comment

by:jeffreychorba
ID: 36979605
Thanks everyone, I think I have my answers. The only other question is do I need to make any changes to the dns server on dc1 in order for it to propagate to dc2?
0
 
LVL 27

Expert Comment

by:Jason Watkins
ID: 36979632
I would make sure the DNS zone can be transferred to another server. In '03 DNS zones are set to not be transferred by default. I would place DNS replication in with Active Directory, which will now be a factor with 2+ DC's in operation.

0
 

Author Comment

by:jeffreychorba
ID: 36979682
Firebar, are there any docs that describe step by step this process or can you click me through it?
0
 
LVL 27

Expert Comment

by:Jason Watkins
ID: 36979700


http://technet.microsoft.com/en-us/library/cc782181(WS.10).aspx#BKMK_ui

On step 4, I would go with option three and just list the new DC's IP address.
0
 

Author Comment

by:jeffreychorba
ID: 36980483
Do I need to do the same on the new DC and list the main dc ip also for transfers back?
0
 
LVL 27

Expert Comment

by:Jason Watkins
ID: 36980575
I dont think so. Once AD/Dns replication are together, you're fine
0
 

Author Comment

by:jeffreychorba
ID: 36980588
ok I am going to do this later today
0
 
LVL 5

Expert Comment

by:mrklaxon
ID: 36986326
If it's AD integrated DNS (and it should be) replication is setup.  Zone transfer settings aren't needed.
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question