sparkeh Posted January 25, 2010 Posted January 25, 2010 I still Sysprep machines, plus it's great when deploying an image. I always specify the computer name manually, but then it joins the domain automatically, then restarts ready to use. It saves a lot of time! Oh you positively *have* to use sysprep when imaging as it does a hell of a lot more than just change SIDs. Don't sysprep and you will feel the pain. The retirement of NewSid is down to the fact that after investigation, Mark Russinovich found that there was no case where two machine machines having the same SID caused any issues.
sparkeh Posted January 25, 2010 Posted January 25, 2010 Perhaps, than why all the fuss coming from Microsoft regarding the practice? Why does Sysprep ensure this is done? I find it hard to believe that software was just created to resolve an issue that doesn't exist, wouldn't you research the issue before writing the software? I can only assume this was done, and they wrote the software to combat this. Alot of sysinternals stuff has been "cleared up" by Microsoft. I remember watching a speech from the last DEF CON Conference how and why these tools were bought up Read the blog, NewSid was written purely on the faith that it was neccessary for two machines on a network to have different SIDs. After investigation it was found not to be the case. If you read all the comments under the blog you will see one by one peoples concerns about different scenarios are addressed .
mattx Posted January 25, 2010 Posted January 25, 2010 Just wondering what the outcome was of the server re-boots......!!
srochford Posted January 25, 2010 Posted January 25, 2010 It's your post, no such thing as off topic Anywho, Duplicate SID's will do this. I do believe sysinternals made a program called "NewSID" which is discontinued (as Microsoft now own the company), however I'm sure someone somewhere has the software. Just run it on your machines and see if this alleviates the problems you are experiencing, saves you having to sysprep the machines, less work = better in my opinion. I'd be very surprised if it's anything at all to do with the SID. The reason that NewSID is being (has been?) discontinued is because it's not necessary - Mark Russinovich (who write NewSID) has a blog post about this - Mark's Blog : The Machine SID Duplication Myth Given that replication isn't working properly between the 2 DCs I think you need to establish which of the DCs are holding which FSMO roles. Move them all to the machine you want to be "correct" and once that's done wait an hour or so for things to settle down (not needed if the FSMO roles are all on your main DC) Once you've got that sorted, run dcpromo on the other server; this will stop it being a DC and leave the first server as the only DC. That may fix all the problems - if machines are trying to authenticate against DC2 but for some reason it's not being found or its database is not in sync then moving to a single DC will fix the problems. Check that your one DC points to itself for DNS - the network card properties MUST NOT refer to any DNS other than itself (you resolve external names by setting the DNS service itself to either use root hints or to forward to your ISP DNS). Do another dcdiag - you may well still see frs errors but check the times - they should be before you wiped the other DC settings (nothing to replicate in a single DC setup!) Once you're confident that your one DC is running OK you can promote the other one. First of all, make sure that it is pointing to your other DC for DNS; again, there must be no reference to external DNS Run dcpromo and follow the prompts to make it a DC in an existing domain. Finally, check the DHCP settings - again, they must not give out any DNS other than that of your main DC. (It's a really common mistake to have clients getting 2 DNS addresses, one is the internal DNS, the second is external. It looks like a good idea but IT'S WRONG!!) (apologies for shouting; it's just such a common mistake!!) 1
Kitkatninja Posted January 25, 2010 Posted January 25, 2010 Just double checking, have you checked your switches (assuming that they are managed ones) to see if there are any excessive broadcasts or loops in your network. Also have you made sure that there aren't any rouge DHCP/DNS servers on your network? Eg external print servers, something along the lines of these that are mis-configured. -Ken
IanT Posted January 25, 2010 Posted January 25, 2010 I don't suppose the workstations were cloned (ghosted) without sysprep being run? Duplicate SID's? Try running Sysprep and select reseal then rename the workstation (delete the COMPUTER account in AD BEFORE renaming PC... or just run the handy MS Sysinternal tool called NewSID
sparkeh Posted January 25, 2010 Posted January 25, 2010 or just run the handy MS Sysinternal tool called NewSID Does nobody read an entire thread now? This has already been brought up a few times.
powdarrmonkey Posted January 25, 2010 Posted January 25, 2010 Does nobody read an entire thread now? This has already been brought up a few times. Nope, just lately it seems acceptable to judge a thread on the three latest posts, or if you were involved in the thread earlier on but missed a load of posts, the last one is authoritative.
Rydra Posted January 26, 2010 Author Posted January 26, 2010 ok, sorry I got tracked on (as we all do!) onto other problems.... never a quiet day! The server reboot did the trick, and replication kicked back in. I can now add things to the domain again, so that part is solved. Part of the printers issue is also solved by this. I missed something blatant in the networked printer... It's a networked printer on a domain, being accessed by laptops that are not on the domain (They will be soon, new network etc....) For those who haven't had their coffee yet, to access anything on a domain server, you need credentials on that domain to access it. I will need to setup a startup batchfile that maps a drive with domain credentials, which will give it the credentials to access the printer! Apparently it used to work before, but somehow I doubt it, as I don't see how you can ignore domain authentication. The only remaining problem now, is sporadic domain workstations being unable to connect to the domain. I strongly suspect this is something to do with either the DNS being screwy, which I'm ignoring as will getting a brand new managed network with all the trimmings in 3 weeks time, so to put effort into fixing that now would be a waste of my time. OR, it's something to do with the SID's. I cannot see the images they used to build the workstations with at the moment, as they were stored on the NAS, which is dead...... BUT having met one of my predecessors, and read the CV of the other one (silly silly man.... network manager with 5 years experience, and forgot to clean out his personal files from his workstation.....) I strongly suspect they didn't use Sysprep. How could the SID's cause this trouble? I'm still stuck with Winsuite, and due to the age of winsuite, it's a fair bet to say it uses SID's to identify the stations. Cannot be 100% sure, but it's a fair guess.
ahuxham Posted January 26, 2010 Posted January 26, 2010 How could the SID's cause this trouble? I'm still stuck with Winsuite, and due to the age of winsuite, it's a fair bet to say it uses SID's to identify the stations. Cannot be 100% sure, but it's a fair guess. As Sparkeh has pointed out, SID's mean nothing, the won't be identified by Winsuite, and shouldn't cause any problems on the domain. Just run NewSID just to be sure, Edugeek admin bar by "mattx" has NewSID bundled, just find his signature on the forums, shouldn't be hard, he's everywhere.
HodgeHi Posted January 26, 2010 Posted January 26, 2010 Are you going to be using the same clients on this new network? If so you may be able to set up and configure RIS on the 2nd DC and create an image of one of the clients (if they are mostly the same type). You can then deploy your new image, just the way you want it but also utilise the image after the infrastructure is rebuilt since the image will still be current. This would also alleviate potential viruses (you mentioned AV being out of date) on the clients and bring your clients machines bang up to date with updates, but should also remove the duplicate SIDs. Pre-Stage the machines and the naming will also be sorted.
Firefox Posted January 26, 2010 Posted January 26, 2010 ok, sorry I got tracked on (as we all do!) onto other problems.... never a quiet day! The server reboot did the trick, and replication kicked back in. I can now add things to the domain again, so that part is solved. Part of the printers issue is also solved by this. I missed something blatant in the networked printer... It's a networked printer on a domain, being accessed by laptops that are not on the domain (They will be soon, new network etc....) For those who haven't had their coffee yet, to access anything on a domain server, you need credentials on that domain to access it. I will need to setup a startup batchfile that maps a drive with domain credentials, which will give it the credentials to access the printer! Apparently it used to work before, but somehow I doubt it, as I don't see how you can ignore domain authentication. The only remaining problem now, is sporadic domain workstations being unable to connect to the domain. I strongly suspect this is something to do with either the DNS being screwy, which I'm ignoring as will getting a brand new managed network with all the trimmings in 3 weeks time, so to put effort into fixing that now would be a waste of my time. OR, it's something to do with the SID's. I cannot see the images they used to build the workstations with at the moment, as they were stored on the NAS, which is dead...... BUT having met one of my predecessors, and read the CV of the other one (silly silly man.... network manager with 5 years experience, and forgot to clean out his personal files from his workstation.....) I strongly suspect they didn't use Sysprep. How could the SID's cause this trouble? I'm still stuck with Winsuite, and due to the age of winsuite, it's a fair bet to say it uses SID's to identify the stations. Cannot be 100% sure, but it's a fair guess. Now you appear to have your DC's reconnected I'd take the time to try to push one of them out the domain for a rebuild. (make sure to do a system state backup first). If the reboot had failed you could have tried a Non Authoritative Restore. This is done by changing the Burflags key in the registry. (plenty of internet articles about it) Also might be worth checking that you have sites and services setup correctly. Are your 2 DC's listed under the same site? If not what sort of replication time do they have?
2097 Posted January 26, 2010 Posted January 26, 2010 Actually quite easy to add Domain Printers to Workgroup laptops Boot up Laptop Printers > add local Port > Insert Printer IP > Point to drivers .. Jobs a gooden
mattx Posted January 26, 2010 Posted January 26, 2010 As Sparkeh has pointed out, SID's mean nothing, the won't be identified by Winsuite, and shouldn't cause any problems on the domain. Just run NewSID just to be sure, Edugeek admin bar by "mattx" has NewSID bundled, just find his signature on the forums, shouldn't be hard, he's everywhere. What are you saying ? I get about a bit.....?
ahuxham Posted January 26, 2010 Posted January 26, 2010 What are you saying ? I get about a bit.....? You're reminding me of David Cameron everyday, everywhere I turn you're/he's there (somewhere)
mattx Posted January 26, 2010 Posted January 26, 2010 You're reminding me of David Cameron everyday, everywhere I turn you're/he's there (somewhere) But he's an Eton Boy !! I'm your common type.....
Rydra Posted January 26, 2010 Author Posted January 26, 2010 another little update.... I'll need to leave it a couple days, but it looks like it was all down to a borked AD replication. Since rebooting both servers, the domain workstations have started behaving themselves. All is well again! Just need to get my NAS up and running again.
srochford Posted January 26, 2010 Posted January 26, 2010 Actually quite easy to add Domain Printers to Workgroup laptops Boot up Laptop Printers > add local Port > Insert Printer IP > Point to drivers .. Jobs a gooden Well, for some values of "good" ... At minimum, I'd want you to use the DNS name for the printer - that makes it possible to change the IP at some time in the future without having to revisit every laptop. It also means you lose any kind of queue control on the printer - if 2 people try to print at the same time then one will lose and there's no nice tidy way of queuing jobs for later. You've also got no way of charging users - the job is going straight to the printer and bypassing any quota software etc. If none of those things is an issue then it's a good way to work :-)
Rydra Posted January 26, 2010 Author Posted January 26, 2010 custom drivers. It's a large networked photocopier with some funky drivers, so would involve going round and installing them all again on every individual laptop. and I'm not sure it's one of those printers you want to install on 40 odd different machines.
2097 Posted January 26, 2010 Posted January 26, 2010 Well, for some values of "good" ... At minimum, I'd want you to use the DNS name for the printer - that makes it possible to change the IP at some time in the future without having to revisit every laptop. It also means you lose any kind of queue control on the printer - if 2 people try to print at the same time then one will lose and there's no nice tidy way of queuing jobs for later. You've also got no way of charging users - the job is going straight to the printer and bypassing any quota software etc. If none of those things is an issue then it's a good way to work :-) he never said it was a issue , Hence my Reply.
glennda Posted January 26, 2010 Posted January 26, 2010 Well, for some values of "good" ... At minimum, I'd want you to use the DNS name for the printer - that makes it possible to change the IP at some time in the future without having to revisit every laptop. It also means you lose any kind of queue control on the printer - if 2 people try to print at the same time then one will lose and there's no nice tidy way of queuing jobs for later. You've also got no way of charging users - the job is going straight to the printer and bypassing any quota software etc. If none of those things is an issue then it's a good way to work :-) but make sure you give the printer a static address as they tend not to update the DNS when they get a new DHCP address
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now