The time service has stopped advertising as a time source because the local clock is not synchronized.

I asked a question via link

http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_28220247.html

resetup PDC of root domain to sync time with external time source.
net stop w32time
w32tm /config /syncfromflags:manual /manualpeerlist: "0.ntp.pool.org,0x1 1.ntp.pool.org,0x1 2.ntp.pool.org,0x1 3.ntp.pool.org,0x1" /reliable:yes /update
net start w32time
w32tm /resync /rediscover /nowait

On all other DCs.
I ran
w32tm /config /syncfromflags:domhier /reliable:no /update
net stop w32time
net start w32time
w32tm /resync /rediscover /nowait

I noticed on some Dcs that I get this error.

The time service has stopped advertising as a time source because the local clock is not synchronized.

Why am I getting this error?

w32tm /query /source shows the right DC = PDC

ran w32tm /stripchart /computer:dc01 /dataonly
and its 00.005

How do I get rid of these errors on the Dcs.
And still getting "AD Replication Monitoring - Time skew detected" in SCOM
LVL 5
IndyrbAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

peter197911Commented:
Can you try:

w32tm /query /configuration
w32tm /query /status

On your PDC?

Can you verify that the w32tm setting is actually syncing with external servers?

I remember trying to setup this w32tm thing on a server, but it didnt work since the ntp servers were not reachable (firewall setting).  The command although, did not display an error.
0
SandeshdubeySenior Server EngineerCommented:
Take the backup of w32time and run below commands.

ON PDC role holder server.

net stop w32time
w32tm /unregister
w32tm /register
net start w32time
net time /setsntp:
net stop w32time & net start w32time
w32tm /config /manualpeerlist:pool.ntp.org /syncfromflags:manual /reliable:yes /update
w32tm /resync /rediscover
net stop w32time & net start w32time

NON PDC Server.

net stop w32time
w32tm /unregister
w32tm /register
net start w32time
net time /setsntp:
Net stop w32time & net start w32time
w32tm /config /syncfromflags:domhier /update
W32tm /resync /rediscover
net stop w32time & net start w32time

Please also make sure that udp port 123 which as direction the chosen NTP server is not blocked.

For other domain computers / servers, make sure that they are using NT5DS for time sync. More here: http://support.microsoft.com/kb/223184

Configuring the time service on the PDC Emulator FSMO role holder
http://msmvps.com/blogs/acefekay/archive/2009/09/18/configuring-the-windows-time-service-for-windows-server.aspx

If the server is configured as VM you need to disable time sync from host to VM.

Time Sync Recommendations For Virtual DCs On Hyper-V – Change In Recommendations:http://jorgequestforknowledge.wordpress.com/2011/09/14/time-sync-recommendations-for-virtual-dcs-on-hyper-v-change-in-recommendations/Disable time

Sync Recommendations For Virtual DCs On VMwarehttp://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1189

Hope this helps
0
IndyrbAuthor Commented:
On non PDC servers do you run

w32tm /config /syncfromflags:domhier /update

or

w32tm /config /syncfromflags:domhier  /reliable:no /update
"reliable"

Not sure if other DCs are suppose to be set to reliable or not.
0
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

SandeshdubeySenior Server EngineerCommented:
Juts run below commands on non PDC servers
w32tm /config /syncfromflags:domhier /update
W32tm /resync /rediscover
Restart the time service: net stop w32time && net start w32time
0
IndyrbAuthor Commented:
all appears to have worked, except on one windows 2003 server.
its time slips and then it will be minutes off.
a w32tm /resync /rediscover doesn't work.
I fix the problem by running net time \\dc01.domain.com /set

But then in a few hours it slips again.

Any ideas on how to permenately fix this issue.
I even unregister, and register.
0
SandeshdubeySenior Server EngineerCommented:
Have you checked the GPO whcih may be apply locally or from domain if any remove the same.Run rsop.msc and check the same.Also ensure that there is no third party time sync software installed like Dimention4 which may be causing the issue.

If you have not prefromed unregister/register of w32time perfrom the same.
0
IndyrbAuthor Commented:
I did find a GPO with the Administrative Computer Policy set as follows, which runs on all computers in the domain, including DCs.

Are any of these settings / concerns and should they be edited?

System/Windows Time Service

Global Configuration Settings Enabled  
Clock Discipline Parameters
FrequencyCorrectRate 4
HoldPeriod 5
LargePhaseOffset 1280000
MaxAllowedPhaseOffset 300
MaxNegPhaseCorrection 54000
MaxPosPhaseCorrection 54000
PhaseCorrectRate 1
PollAdjustFactor 5
SpikeWatchPeriod 90
UpdateInterval 30000
General Parameters
AnnounceFlags 10
EventLogFlags 2
LocalClockDispersion 10
MaxPollInterval 15
MinPollInterval 10
ChainEntryTimeout  
ChainMaxEntries  
ChainMaxHostEntries  
ChainDisable  
ChainLoggingRate  
 

System/Windows Time Service/Time Providers

Enable Windows NTP Client Enabled  

Extra Registry Settings
Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.

Setting State
Software\Policies\Microsoft\Windows NT\CurrentVersion\MYS\DisableShowAtLogon
0
SandeshdubeySenior Server EngineerCommented:
I will recommend to disable the time GPO as this may be conflicting.Remove the GPO and reboot the DCs for setting to take effect assuming you have configured authorative time server role as per this http://support.microsoft.com/kb/223184 on PDC server.Once server is online run the diagnosis test and check.
0
IndyrbAuthor Commented:
Man I am confused.

At the root domain there is a GPO that serves another purpose, but has the following, and applies to all workstations, servers, and Dcs.

The Dc container has another GPO which is shared and has the same entries (duplication)

First, does these settings make ssense for clients, dcs, and member servers.
Botice it sets all NTP client as enabled, and annouceflags to 10.
Since this GPO is applied to my PDC emulator - will it cause issues with syncing with external time source (announce flags and etc)
and will clients still get time from PDC emulator.





Enable Windows NTP Client Enabled  


Global Configuration Settings Enabled  
Clock Discipline Parameters
FrequencyCorrectRate 4
HoldPeriod 5
LargePhaseOffset 1280000
MaxAllowedPhaseOffset 300
MaxNegPhaseCorrection 54000
MaxPosPhaseCorrection 54000
PhaseCorrectRate 1
PollAdjustFactor 5
SpikeWatchPeriod 90
UpdateInterval 30000
General Parameters
AnnounceFlags 10
EventLogFlags 2
LocalClockDispersion 10
MaxPollInterval 15
MinPollInterval 10
ChainEntryTimeout  
ChainMaxEntries  
ChainMaxHostEntries  
ChainDisable  
ChainLoggingRate
0
IndyrbAuthor Commented:
Does the GPO for w32time apply to clients or only servers\domain controllers.

If configuring gpo for clients.
would you make announce flags 10??
type: NT5DS or NTP
NTPServer?   dc.domain.local,0x1? or leave blank
Windows NTP Server = disabled

For secondary domain controllers:
announce flags 10?
type: NT5DS or NTP
NTPServer?   dc.domain.local,0x1? or leave blank
Windows NTP Server = enabled

For Primary domain controllers:
announce flags 5
type: NTP
NTPServer?   us.pool.ntp.org
Windows NTP Server = enabled
0
SandeshdubeySenior Server EngineerCommented:
There is no GP required for server and clients.Just configure authorative time server role on PDC role holder server,client will sync the time from DC.It depends upon the type registry value set in HLMC\SYSTEM\Currentcontrolset\Services\W32time\Parameters on client PC.By default the value is set to Nt5DS hence it will sync time from DC.

Nt5DS = synchronize to domain hierarchy [default]
NTP = synchronize to manually configured source
NoSync = do not synchronize time

Reference KB:http://support.microsoft.com/kb/223184

On PDC server
Announce flags 5
type: NTP
NTPServer- to external source e.g  pool.ntp.org

For client and other DCs
type: NT5DS
announce flags 10
NTPServer key is irreleveant leave as it is.

Hope this helps
0
IndyrbAuthor Commented:
So If a GPO was already inplace with the configuration that I mentioned, should I remove it?
Will it keep the settings from the GPO or reset back to default and sync with Domain using proper DS architecture.

Wasn't sure since the GPO already has been given explicit settings.

Or should I just edit the current GPO, even though you mentioned its not required to make it sync right, and if so, based on above settings what should I set for the clients. which for member servers. which for DC.
and which for PDC emulator.
Looks like they all get the GPO applied to them.

Thanks for your assistance.

Something is not right, as a few DCs still slip on time.
0
SandeshdubeySenior Server EngineerCommented:
As suggested ealier remove the GPO for clients/servers and just configure authorative time server role on PDC role holder server.Once configured reboot the server and clients for setting to take effect.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.