Click here to get back home

Re: Upgrading of 2003 domain to 2008 domain, checklist, questions?

 HomeNewsGroups | Search

microsoft.public.windows.server.security - Supporting MS Windows network? Read here before it's too late! 

get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re: Upgrading of 2003 domain to 2008 domain, checklist, questions? Meinolf Weber [MVP-DS] 01-01-2009
Posted by Meinolf Weber [MVP-DS] on January 1, 2009, 6:43 am
Please log in for more thread options
Hello markm75g,

Again, please WAIT for starting anything new until we hopefully get fixed
the domain to a running state before the demoting of the DC/CA started.

Just to get you correct, except from the CA on the DC there was NOT another
application running on one of them???

If i read some FAQ from DPM 2007 is t should be possible to restore an entire
server. So check the product documentation if you did the correct backup
for this.

If it is only the VM file, you will run in USN rollback, because the saved
file of the demoted DC ofcourse is older then the running DC.

What you can try for this case is, to restore the VM, hopefully no that old
from the actual state. Then shut down the running DC VM and startup the restored
VM, so that only ONE DC is running. That one with the old status including
the CA. Then you can start a test with the domain members to see if every
service/application/CA is running as expected.

If everything works, you have to recreate all accounts/groups/policies etc.
to an actual state, have to rejoin all computers again to the domain when
they are not in AD UC listed to get AD back to the actual date. Then you
have to cleanup AD database from ALL other DC's listed there. Then you should
be able to start again with the installation of 2008 and go on again.

For the CA i am not an expert, so BEFORE starting let someone in the
microsoft.public.windows.server.security
NG read/check this posting about restoring a CA on DC from a backup done
with DPM 2007 on a VM. I will crosspost this there.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


show/hide quoted text



Posted by markm75g on January 1, 2009, 11:11 am
Please log in for more thread options


"Meinolf Weber [MVP-DS]" wrote:

show/hide quoted text
restored
show/hide quoted text
microsoft.public.windows.server.security
show/hide quoted text

I guess that is true, i probably could have done the USN rollback, as yes,
it did restore the whole VM when i first tried it.

At this point i think i'm ok actually.

As I had transfered the roles over to my other DC..

Even though the upgrade to 2008 was failing on VSDC02, i just went ahead and
created two fresh boxes that were 2008, calling them VSDCA and VSDCB and
dcpromo'ing both of these.

Since only one main app was affected by the CA thing, i just created a new
CA on VSDCA.. I requested a new cert via the Communication VM and it is fine
now.

I also created a DNS on VSDCA and VSDCB and DHCP I recreated on VSDCA (it
was formerly on VSDC01, which was demoted and is now offline).

So at this point i have the following:

VSDCA - 2008 server/ CA/ DC/ All 5 roles (not a GC) / DHCP/ DNS

VSDCB - 2008 server/DC/GC/ DNS

VSDC02 - 2003 server, DC/GC

I think the only thing left to do is demote VSDC02, which at that point i'll
have everything at 2008 level and since there will be no 2003 DCs, it can be
native.


*Down the road i will take your advice and make one physical machine a DC,
with all 5 roles (not a GC).. the only thing, was I was planning on making
this physical machine a MOM machine, as i figured MOM was best suited on a
physical machine, but i dont think MOM and DC mix, i may have to adjust this
plan.


Thanks again for the help


Posted by Meinolf Weber [MVP-DS] on January 1, 2009, 11:28 am
Please log in for more thread options
Hello markm75g,

Make all DC's Global catalog server and aslso use AD integrated zones for
DNS. Hopefully the old certificates from the not longer existing CA will
not create a problem. To make sure you have no problems run the diagnostic
tools replmon from the run line or repadmin /showrepl, dcdiag and netdiag
from the command prompt on the old machine to check for errors, if you have
some post the complete output from the command here or solve them first.
For this tools you have to install the support\tools\suptools.msi from the
2003 installation disk.

2008 includes repadmin and dcdiag. For netdiag you can copy the version form
the 2003 suuport tools to 2008, runs also there.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


show/hide quoted text



Posted by markm75g on January 1, 2009, 12:26 pm
Please log in for more thread options


"Meinolf Weber [MVP-DS]" wrote:

show/hide quoted text


Thanks again,

You mention making all DC's GCs, but what about the infrastructure rule,
where if the one DC has all 5 roles inclusive of Infrastructure, it should
not be a GC as well.. or does this not really matter.



Posted by Meinolf Weber [MVP-DS] on January 1, 2009, 12:45 pm
Please log in for more thread options
Hello markm75g,

In a single forest domain like yours you can make all DC's GC as stated also
in the article:
http://support.microsoft.com/kb/223346/en-us

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


show/hide quoted text



Similar ThreadsPosted
Automatic certificate enrollment for local system failed after upgrading member server to domain controller August 25, 2005, 6:11 pm
Windows 2008 CA in a Windows 2003 domain July 31, 2009, 8:06 am
Windows 2003 - Child domain cannot request certificate from root domain January 11, 2008, 11:41 am
Re: server 2008 questions March 5, 2009, 8:37 pm
2003/R2 certificate server questions March 13, 2007, 10:27 am
2003/R2 certificate server questions March 12, 2007, 10:24 pm
Questions about the artical "DCOM Security Enhancements" for Windows Server 2003 SP1 January 15, 2006, 9:47 pm
Re: 2003 CA in 2000 Domain September 4, 2008, 4:07 pm
How To Get Username and Domain Name in Windows 2003? June 10, 2005, 5:03 pm
Windows 2003 Domain Security July 14, 2005, 11:06 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Driving a better car - Fuelzilla.com

Cabling site for homeowners and pros alike - Cabling-Design.com

Friends:

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap
Privacy Policy