Tuesday, April 7, 2009

Tombstone, Deleting AD objects , Deleting DNS objects

When an Active Directory object is deleted, a small portion of the object remains for a specified period of time so that other domain controllers that are replicating changes will become aware of the deletion. This period of time is referred to as the "tombstone lifetime" and is configurable.
http://support.microsoft.com/default.aspx?scid=KB;EN-US;258310
http://dnsfunda.blogspot.com/2006_10_01_archive.html

What to do if a DC server die and tombstone life (60 days) ? it is because you will start to get a lot of replication errors. See follow link.
http://www.servernewsgroups.net/group/microsoft.public.windows.server.active_directory/topic18887.aspx
The options are:
1. dcpromo /forceremoval
2. reset the secure channel on the servers
3. restore from the tape and demote the server

We still need WINS even we are in windows 2003 environmnet, see this
http://www.informit.com/articles/article.aspx?p=102617&seqNum=8

No comments:

Post a Comment