Solved

RODC tombstone concerns

Posted on 2013-12-06
4
843 Views
Last Modified: 2013-12-11
2 DC's of Win 2008 in main office and 1 RODC in our remote office. The office will be shutdown in the winter for 6 months. Just worried about the tombstone problem, not sure though. Can someone confirm whether the RODC will be moved to tombstone after 6 months? or what else can I do to avoid this tombstone issue?"
0
Comment
Question by:wmbuchan2013
  • 2
  • 2
4 Comments
 
LVL 14

Expert Comment

by:Ram Balachandran
ID: 39702716
Default tombstone period for Windows 2008 DCs is 180 Days [ ie almost 6 months]
But you can always modify the tombstone period :

Find tombstonelifetime

dsquery * "cn=directory service,cn=windows nt,cn=services,cn=configuration,dc=<forestDN>" -scope base -attr tombstonelifetime

How to modify tombstone

http://technet.microsoft.com/en-us/library/dd378821(v=ws.10).aspx


----

Coming to your question,

If the DC is not available in the network more than specified by the tombstone lifetime attribute, following Error event may be logged in the Directory Service log:

Event ID: 2042
Source: NTDS Replication
Type: Error
Description: It has been too long since this machine last replicated with the named source machine. The time between replications with this source has exceeded the tombstone lifetime. Replication has been stopped with this source.

When this replication does not occur, you may experience an inconsistency in the contents of Active Directory databases on domain controllers in the forest. This inconsistency occurs because knowledge of deletes is persisted for tombstone lifetime number of days. Domain controllers that do not transitively inbound replicate Active Directory change in a rolling tombstone lifetime number of days cause lingering objects. Lingering objects are objects intentionally deleted by an administrator, service or operating system that incorrectly exists on destination DCs that did not perform timely replication.


Hence recommend you to either establish the connection before 6 months, or change the tombstone life period

Regards,
Ram
0
 

Accepted Solution

by:
wmbuchan2013 earned 0 total points
ID: 39702717
Thank you so much, perfect.
0
 

Author Closing Comment

by:wmbuchan2013
ID: 39710904
Perfect, great steps to resolution along with Microsoft's page for reference!
0
 
LVL 14

Expert Comment

by:Ram Balachandran
ID: 39710991
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We recently had an issue where out of nowhere, end users started indicating that their logins to our terminal server were just showing a "blank screen." After checking the usual suspects -- profiles, shell=explorer.exe in the registry, userinit.exe,…
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question