Solved

RODC tombstone concerns

Posted on 2013-12-06
4
796 Views
Last Modified: 2013-12-11
2 DC's of Win 2008 in main office and 1 RODC in our remote office. The office will be shutdown in the winter for 6 months. Just worried about the tombstone problem, not sure though. Can someone confirm whether the RODC will be moved to tombstone after 6 months? or what else can I do to avoid this tombstone issue?"
0
Comment
Question by:wmbuchan2013
  • 2
  • 2
4 Comments
 
LVL 14

Expert Comment

by:Ram Balachandran
Comment Utility
Default tombstone period for Windows 2008 DCs is 180 Days [ ie almost 6 months]
But you can always modify the tombstone period :

Find tombstonelifetime

dsquery * "cn=directory service,cn=windows nt,cn=services,cn=configuration,dc=<forestDN>" -scope base -attr tombstonelifetime

How to modify tombstone

http://technet.microsoft.com/en-us/library/dd378821(v=ws.10).aspx


----

Coming to your question,

If the DC is not available in the network more than specified by the tombstone lifetime attribute, following Error event may be logged in the Directory Service log:

Event ID: 2042
Source: NTDS Replication
Type: Error
Description: It has been too long since this machine last replicated with the named source machine. The time between replications with this source has exceeded the tombstone lifetime. Replication has been stopped with this source.

When this replication does not occur, you may experience an inconsistency in the contents of Active Directory databases on domain controllers in the forest. This inconsistency occurs because knowledge of deletes is persisted for tombstone lifetime number of days. Domain controllers that do not transitively inbound replicate Active Directory change in a rolling tombstone lifetime number of days cause lingering objects. Lingering objects are objects intentionally deleted by an administrator, service or operating system that incorrectly exists on destination DCs that did not perform timely replication.


Hence recommend you to either establish the connection before 6 months, or change the tombstone life period

Regards,
Ram
0
 

Accepted Solution

by:
wmbuchan2013 earned 0 total points
Comment Utility
Thank you so much, perfect.
0
 

Author Closing Comment

by:wmbuchan2013
Comment Utility
Perfect, great steps to resolution along with Microsoft's page for reference!
0
 
LVL 14

Expert Comment

by:Ram Balachandran
Comment Utility
0

Featured Post

Wish Marketing would stop bothering you?

Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

Join & Write a Comment

We recently had an issue where out of nowhere, end users started indicating that their logins to our terminal server were just showing a "blank screen." After checking the usual suspects -- profiles, shell=explorer.exe in the registry, userinit.exe,…
I had a question today where the user wanted to know how to delete an SSL Certificate, so I thought that I would quickly add this How to! Article for your reference. WHY WOULD YOU WANT TO DELETE A CERTIFICATE? 1. If an incorrect certificate was …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now