Solved

RODC tombstone concerns

Posted on 2013-12-06
4
868 Views
Last Modified: 2013-12-11
2 DC's of Win 2008 in main office and 1 RODC in our remote office. The office will be shutdown in the winter for 6 months. Just worried about the tombstone problem, not sure though. Can someone confirm whether the RODC will be moved to tombstone after 6 months? or what else can I do to avoid this tombstone issue?"
0
Comment
Question by:wmbuchan2013
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 14

Expert Comment

by:Ram Balachandran
ID: 39702716
Default tombstone period for Windows 2008 DCs is 180 Days [ ie almost 6 months]
But you can always modify the tombstone period :

Find tombstonelifetime

dsquery * "cn=directory service,cn=windows nt,cn=services,cn=configuration,dc=<forestDN>" -scope base -attr tombstonelifetime

How to modify tombstone

http://technet.microsoft.com/en-us/library/dd378821(v=ws.10).aspx


----

Coming to your question,

If the DC is not available in the network more than specified by the tombstone lifetime attribute, following Error event may be logged in the Directory Service log:

Event ID: 2042
Source: NTDS Replication
Type: Error
Description: It has been too long since this machine last replicated with the named source machine. The time between replications with this source has exceeded the tombstone lifetime. Replication has been stopped with this source.

When this replication does not occur, you may experience an inconsistency in the contents of Active Directory databases on domain controllers in the forest. This inconsistency occurs because knowledge of deletes is persisted for tombstone lifetime number of days. Domain controllers that do not transitively inbound replicate Active Directory change in a rolling tombstone lifetime number of days cause lingering objects. Lingering objects are objects intentionally deleted by an administrator, service or operating system that incorrectly exists on destination DCs that did not perform timely replication.


Hence recommend you to either establish the connection before 6 months, or change the tombstone life period

Regards,
Ram
0
 

Accepted Solution

by:
wmbuchan2013 earned 0 total points
ID: 39702717
Thank you so much, perfect.
0
 

Author Closing Comment

by:wmbuchan2013
ID: 39710904
Perfect, great steps to resolution along with Microsoft's page for reference!
0
 
LVL 14

Expert Comment

by:Ram Balachandran
ID: 39710991
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

To effectively work with Diskpart on a Server Core, it is necessary to write some small batch script's, because you can't execute diskpart in a remote powershell session. To get startet, place the Diskpart batch script's into a share on your loca…
I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question