sidewinder Posted April 10, 2012 Posted April 10, 2012 (edited) I'm not actually sure how this has happened, but I've just noticed that all clocks, on servers and all clients are half an hour slow. I imagine because they are ALL wrong then we're not getting any issues with Kerberos (hence why I've only just noticed it) but how do I go about getting it set correctly? Just change the clocks on the DC's? Edited April 10, 2012 by sidewinder
gshaw Posted April 10, 2012 Posted April 10, 2012 In the long run best bet would be to sync your DCs with an NTP source then everything will be fully accurate as the clients sync with the PDC
RichB Posted April 10, 2012 Posted April 10, 2012 Just change the time on your primary DC and this should solve it for you!
Guest TheLibrarian Posted April 10, 2012 Posted April 10, 2012 DC's (and VMWare hypervisors) are pick about their time source, IIRC it has to be a stratum 1 or the DC won't sync. Just changing the time on the primary DC could cause authentication issues; be careful. @sister_annex set time services up; we take a stratum 16 time sync from the local authority and then pass it on as a stratum 1 using Meinberg's Time Server Monitor. I'm sure there was more to it than just this and I'm pretty sure @sister_annex will pipe up soon if anyone wants to ask him about it.
sidewinder Posted April 10, 2012 Author Posted April 10, 2012 (edited) Are you using any virtualisation? Yes...and it was only last week I was reading a thread where someone warned not to let the virtual DC's sync from the host and I thought 'ah, I better change that' I actually added a physical DC last week, whether that has anything to do with it I don't know, it's probably more down to the virtual DCs I would guess Edit: actually yes, because a virtual one was still the PDC emulator. I've now changed that to the physical DC Edited April 10, 2012 by sidewinder
Mr.Ben Posted April 10, 2012 Posted April 10, 2012 Yes...and it was only last week I was reading a thread where someone warned not to let the virtual DC's sync from the host and I thought 'ah, I better change that' I actually added a physical DC last week, whether that has anything to do with it I don't know, it's probably more down to the virtual DCs I would guess That what I was thinking - I managed to set up a loop where the host would ask the virtual DC for the time, and then sync it back to the virtual DC - we were losing around 20 minutes per week, which was then propagated around the network. If you have done that changing the time on the first DC, then forcing the other DC's to sync should be enough to start the process off. use: w32tm /resync at the command prompt to force a resync on the other controllers.
sidewinder Posted April 11, 2012 Author Posted April 11, 2012 All sorted now....I did it in 5 minute chunks, re-synched DC's and checked a few clients had updated before I did the next change - seemed a bit risky doing it all at once since I assume there would be authentication problems if the clocks got too far apart.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now