Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1433
  • Last Modified:

force all domain controllers to register NTP SRV records

I have a mixed environment, and have a need for several clients to be able to dynamically find NTP services within thier active directory site.  Is there a way that I can have all of my domain controllers dynamically register these SRV records? I am trying to avoid creating them all manually so that my environment stays fluid as I grow it.
0
intlfcs_krismortensen
Asked:
intlfcs_krismortensen
1 Solution
 
SandeshdubeySenior Server EngineerCommented:
Configure authorative time server on the PDC role holder server below is the KB article for the same.http://support.microsoft.com/kb/816042

Please also make sure that udp port 123 which as direction the chosen NTP server is not blocked.

By default client machine and servers will sync time from PDC server.More here: http://support.microsoft.com/kb/223184


Jorge's Time Service blogs:
Configuring and Managing the Windows Time Service, Parts 1 to 4:
http://blogs.dirteam.com/blogs/jorge/archive/2010/09/26/configuring-and-managing-the-windows-time-service-part-1.aspx
http://blogs.dirteam.com/blogs/jorge/archive/2010/09/26/configuring-and-managing-the-windows-time-service-part-2.aspx
http://blogs.dirteam.com/blogs/jorge/archive/2010/09/26/configuring-and-managing-the-windows-time-service-part-3.aspx
http://blogs.dirteam.com/blogs/jorge/archive/2010/09/26/configuring-and-managing-the-windows-time-service-part-4.aspx
0
 
intlfcs_krismortensenAuthor Commented:
Sandeshdubey-
thanks for the links, however, this doesn't answer my question at all. I already have my PDC Emulator configured as an authoritative time server, udp port 123 is already allowed, and yes, by default WINDOWS clients will automatically sync time from the various domain controllers which are synced by the PDC emulator. The key to my question is that I have NON WINDOWS clients looking for NTP services. they are currently configured to look for those services by querying "internaldomain.com", and domain controllers do not register NTP SRV records in DNS by default... I want to change things so that each of my domain controllers automatically registers an NTP SRV record for my NON WINDOWS clients to find.
0
 
footechCommented:
I've never seen or heard of a setting that will create these automatically for you.  The closest you could come is scripting their creation.  DHCP options may also be of help to you depending on if the clients will use them.
0
What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

 
Netman66Commented:
Most non-windows clients have time services of their own.  It would only be a matter of pointing those services to the PDCE.

I know of no way other than manually to create DNS records for NTP - and even then, clients don't normally query for time servers using SRV records.

Is this a custom service you have created?
0
 
intlfcs_krismortensenAuthor Commented:
Netman66-
This is not a custom service; in this case, it is actually NetApp storage controllers, which ends up being a very heavily modified version of freebsd. I manually created SRV records for now, and as you noted, the storage controllers don't seem to be looking for those SRV records though.
0
 
Netman66Commented:
Ok, that gives me more info.

So using System Administrator under Ontap5/Configuration/System Tools/{date/time/timezone} - select Edit (top left) and enable Timed and set the Time Servers by IP - best to use the PDC Emulator.

If you prefer the commandline then:

> options timed
> options timed.servers {IP address of the PDCE}
> options timed.enable on

That should do the trick.

Let me know.
0
 
intlfcs_krismortensenAuthor Commented:
While the solution does work, it doesnt really provide for the dynamic environment that I am looking for; at this point I am not confident that it is possible to have that kind of dynamic environment though.
0
 
Netman66Commented:
You can use the PDCE name instead, it will use the DNS settings to resolve.

NTP is not a dynamic service in an AD environment as the PDCE is always the authoritative time source for the infrastructure.  Changing the PDCE role holder will always require changing NTP settings - whether using DNS or static IP, there is no getting around that.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Tackle projects and never again get stuck behind a technical roadblock.
Join Now