<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shariq Sheikh &#124; Port 389 &#187; RODC</title>
	<atom:link href="http://www.shariqsheikh.com/blog/index.php/base/rodc/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shariqsheikh.com/blog</link>
	<description>- activity of Active Directory and the rest</description>
	<lastBuildDate>Thu, 22 Jul 2010 17:01:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Is there an Active Directory Visual Illustration/Diagram ?</title>
		<link>http://www.shariqsheikh.com/blog/index.php/200909/is-there-an-active-directory-visual-illustrationdiagram/</link>
		<comments>http://www.shariqsheikh.com/blog/index.php/200909/is-there-an-active-directory-visual-illustrationdiagram/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 16:18:43 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Group Policy]]></category>
		<category><![CDATA[Hyper-V]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[RODC]]></category>
		<category><![CDATA[Server Core]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Posters]]></category>

		<guid isPermaLink="false">http://www.shariqsheikh.com/blog/index.php/200909/is-there-an-active-directory-visual-illustrationdiagram/</guid>
		<description><![CDATA[A question was raised on ActiveDir, and I learned about an old TechNet Jigsaw on AD’s interworking. &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; Along with that, there was a new Windows Server 2008 AD Feature Components which [...]]]></description>
			<content:encoded><![CDATA[<p>A question was raised on ActiveDir, and I learned about an old TechNet Jigsaw on AD’s interworking.</p>
<p style="text-align: center"><a href="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/09/adjigsaw.png"><img style="border-bottom: 0pt; border-left: 0pt; display: inline; margin-left: 0px; border-top: 0pt; margin-right: 0px; border-right: 0pt" class="aligncenter" title="ADjigsaw" border="0" alt="ADjigsaw" align="left" src="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/09/adjigsaw-thumb.png" width="709" height="772"/></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Along with that, there was a new Windows Server 2008 AD Feature Components which I received at Tech-Ed 2007 and it illustrates the new and improved AD pieces introduced with Windows Server 2008. This poster covers ADLDS, ADFS, ADRMS, and RODCs.</p>
<p>&nbsp;</p>
<p><a href="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/09/ad08features.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="AD08features" border="0" alt="AD08features" src="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/09/ad08features-thumb.png" width="944" height="613"/></a></p>
<p>And an additional poster on general new Windows Server 2008 Feature Components that covers TS, NAP, IIS 7.0, Virtualization, Server Core and BitLocker.</p>
<p><a href="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/09/08features.png"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="08features" border="0" alt="08features" src="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/09/08features-thumb.png" width="943" height="610"/></a></p>
<p>Both of the above illustrations and very good quality large size posters (30x20in) and are good to hang in your office/cube. Printing them on regular printer may distort the quality, so you may try the plotter <img src='http://www.shariqsheikh.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . All three can be downloaded from the following links :</p>
<h3><span style="font-size: x-small"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=C236336D-AB43-44B1-AD6F-A2F668FB8C02&amp;displaylang=en" target="_blank">TechNet Magazine Active Directory Component Jigsaw Poster</a></span></h3>
<h3><span style="font-size: x-small"><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=c2b9e44e-0bbd-47cb-bc09-b3d48be7f867&amp;displaylang=en" target="_blank">Windows Server 2008 Component Posters (both)</a></span></h3>
<p>P.S This is my first test post using <a href="http://download.live.com/writer" target="_blank">WLW</a>.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.shariqsheikh.com%2Fblog%2Findex.php%2F200909%2Fis-there-an-active-directory-visual-illustrationdiagram%2F&amp;linkname=Is%20there%20an%20Active%20Directory%20Visual%20Illustration%2FDiagram%20%3F">Share/Bookmark</a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shariqsheikh.com/blog/index.php/200909/is-there-an-active-directory-visual-illustrationdiagram/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>No RIDs for you (the RODC) !</title>
		<link>http://www.shariqsheikh.com/blog/index.php/200907/no-rids-for-you-the-rodc/</link>
		<comments>http://www.shariqsheikh.com/blog/index.php/200907/no-rids-for-you-the-rodc/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 00:52:16 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.shariqsheikh.com/blog/?p=553</guid>
		<description><![CDATA[Says the RID Master FSMO to a RODC. If you recall the RID Master&#8217;s sole job is to make sure that duplicate SIDs are not issued by domain controllers. Whenever a DC needs to create a SID, it takes the next available value from its own RID pool to create the SID with a unique [...]]]></description>
			<content:encoded><![CDATA[<p>Says the RID Master FSMO to a RODC. If you recall the RID Master&#8217;s sole job is to make sure that duplicate SIDs are not issued by domain controllers. Whenever a DC needs to create a SID, it takes the next available value from its own RID pool to create the SID with a unique value. The default pool size is 500 RIDs. When we run the RID pool test on a RODC, the test skips due to the DC being RODC and not having anything to do with the creation of the new objects.</p>
<blockquote><p>dcdiag /v /test:ridmanager</p>
</blockquote>
<p><a href="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/07/08rodc-2009-07-29-19-34-231.png"><img class="alignleft size-full wp-image-557" title="08rodc-2009-07-29-19-34-231" alt="08rodc-2009-07-29-19-34-231" src="http://www.shariqsheikh.com/blog/wp-content/uploads/2009/07/08rodc-2009-07-29-19-34-231.png" width="624" height="596"/></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://www.shariqsheikh.com/blog/index.php/200804/find-out-the-available-rids-on-your-dc/">Here is how the test is supposed to report back with the remaining pool of the allocated RIDs.</a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.shariqsheikh.com%2Fblog%2Findex.php%2F200907%2Fno-rids-for-you-the-rodc%2F&amp;linkname=No%20RIDs%20for%20you%20%28the%20RODC%29%20%21">Share/Bookmark</a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shariqsheikh.com/blog/index.php/200907/no-rids-for-you-the-rodc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Can a RODC also be a DHCP ?</title>
		<link>http://www.shariqsheikh.com/blog/index.php/200806/can-a-rodc-also-be-a-dhcp/</link>
		<comments>http://www.shariqsheikh.com/blog/index.php/200806/can-a-rodc-also-be-a-dhcp/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 01:40:47 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Server Core]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.shariqsheikh.com/blog/?p=72</guid>
		<description><![CDATA[Sounds like a no-brainer, but there is catch. I installed DHCP role on my Server Core that I had previously set up as Read-only Domain Controller, using this command. start /w ocsetup DHCPServerCore And then I went ahead and set the service configuration to &#8220;auto&#8221; with this command, sc config dhcpserver start= auto (note the [...]]]></description>
			<content:encoded><![CDATA[<p>Sounds like a no-brainer, but there is catch. I installed DHCP role on my Server Core that I had previously set up as Read-only Domain Controller, using this command.</p>
<blockquote><p><code>start /w ocsetup DHCPServerCore</code></p></blockquote>
<p>And then I went ahead and set the service configuration to &#8220;auto&#8221; with this command,</p>
<blockquote><p><code>sc config dhcpserver start= auto</code> (note the <em>space</em> between the equal sign and <em>auto)</em></p></blockquote>
<p>And then finally when I tried to start the DHCP service with the following command, it failed with these errors.</p>
<blockquote><p><code>net start dhcpserver</code></p>
<p><em>A system error has occured</em></p>
<p><em>System error 50 has occured</em></p>
<p><em>The request is not supported</em></p></blockquote>
<p>So the catch was, that since RODC can&#8217;t write back to the AD to create the needed DHCP security groups i.e DHCP Administrators and DHCP Users, the service would fail.</p>
<p>After creating those <em>domain local</em> security groups on another Windows Server 2008 RWDC, the service does run successfully and you can manage the DHCP Server (that is running on Server Core) from another server using RSAT.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.shariqsheikh.com%2Fblog%2Findex.php%2F200806%2Fcan-a-rodc-also-be-a-dhcp%2F&amp;linkname=Can%20a%20RODC%20also%20be%20a%20DHCP%20%3F">Share/Bookmark</a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shariqsheikh.com/blog/index.php/200806/can-a-rodc-also-be-a-dhcp/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>How to promote Server Core to be a RODC</title>
		<link>http://www.shariqsheikh.com/blog/index.php/200804/how-to-promote-server-core-to-be-a-rodc/</link>
		<comments>http://www.shariqsheikh.com/blog/index.php/200804/how-to-promote-server-core-to-be-a-rodc/#comments</comments>
		<pubDate>Sun, 20 Apr 2008 02:43:43 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Server Core]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.shariqsheikh.com/blog/?p=65</guid>
		<description><![CDATA[The Windows Server 2008 Server Core installation does support Read Only Domain Controllers (RODC). This support makes Server Core ideal for brance office scenarios. To make a Server Core part of your domain as RODC, you use the unattended answer file with the following text with your settings and passwords [DCInstall] InstallDNS=Yes ConfirmGC=Yes RebootOnCompletion=Yes ReplicaDomainDNSName=2008.lab [...]]]></description>
			<content:encoded><![CDATA[<p>The Windows Server 2008 Server Core installation does support Read Only Domain Controllers (RODC). This support makes Server Core ideal for brance office scenarios. To make a Server Core part of your domain as RODC, you use the unattended answer file with the following text <em>with your settings and passwords</em></p>
<blockquote><p><code>[DCInstall]<br />
InstallDNS=Yes<br />
ConfirmGC=Yes<br />
RebootOnCompletion=Yes<br />
ReplicaDomainDNSName=2008.lab<br />
ReplicaOrNewDomain=readonlyreplica<br />
ReplicationSourceDC=dc3.2008.lab<br />
SafeModeAdminPassword=<br />
SiteName=Default-First-Site-name<br />
UserDomain=2008.lab<br />
UserName=admin08<br />
Password=<br />
CreateDNSDelegation=No</code></p></blockquote>
<p>You can place the text file on the root of your C drive on the server core and run the following command</p>
<blockquote><p><code>dcpromo /unattend:unattend.txt</code> <em>where unattend.txt is the text file you created above</em></p></blockquote>
<p>Later on we will discuss other embedded command line structures and built-in programs such as OCSETUP which will allow you to add roles and features to your server core. Keep in mind that making the domain controller is the only setup you must not use OCSETUP for, and you must utilize DCPROMO for it, otherwise your server may not function properly.</p>
<p>After running the above process, you will notice that from a Windows Server 2008 full installation, using ADUC we can readily confirm that our DC is RODC.</p>
<p><a href="http://www.shariqsheikh.com/blog/wp-content/uploads/2008/04/rodc.jpg"><img class="alignnone size-medium wp-image-66" title="rodc" src="http://www.shariqsheikh.com/blog/wp-content/uploads/2008/04/rodc-300x50.jpg" alt="" width="300" height="50" /></a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.shariqsheikh.com%2Fblog%2Findex.php%2F200804%2Fhow-to-promote-server-core-to-be-a-rodc%2F&amp;linkname=How%20to%20promote%20Server%20Core%20to%20be%20a%20RODC">Share/Bookmark</a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shariqsheikh.com/blog/index.php/200804/how-to-promote-server-core-to-be-a-rodc/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WSUS 3.0 SP1 gets released</title>
		<link>http://www.shariqsheikh.com/blog/index.php/200802/wsus-30-sp1-gets-released/</link>
		<comments>http://www.shariqsheikh.com/blog/index.php/200802/wsus-30-sp1-gets-released/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 20:50:36 +0000</pubDate>
		<dc:creator>Rick</dc:creator>
				<category><![CDATA[Group Policy]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[RODC]]></category>

		<guid isPermaLink="false">http://www.shariqsheikh.com/blog/?p=15</guid>
		<description><![CDATA[WSUS 3.0 SP1 was released yesterday, following are the improvements that have been made from Version 3.0.6 The improvements that SP1 offers include: • Support for Windows Server 2008. • New Client Servicing API. • Support client registration. • Filter of updates by category and classification. • Provide applicability rule extension mechanism. • Obtain package [...]]]></description>
			<content:encoded><![CDATA[<p>WSUS 3.0 SP1 was released yesterday, following are the improvements that have been made from Version 3.0.6</p>
<p>The improvements that SP1 offers include:</p>
<p class="MsoNormal">• Support for Windows Server 2008.<br />
• New Client Servicing API.<br />
• Support client registration.<br />
• Filter of updates by category and classification.<br />
• Provide applicability rule extension mechanism.<br />
• Obtain package metadata and report update status for each client.</p>
<p>• Improvements for local publishing: supports publishing of drivers within the enterprise by using vendor provided catalogs. API include support for bundles and prerequisites.<br />
• All hotfixes: WSUS 3.0 SP1 includes all the changes and hotfixes that have been issued since the release of WSUS 3.0.<br />
• Support for Microsoft SQL Server 2005: WSUS 3.0 SP1 lets you use SQL Server 2005.</p>
<p><a title="WSUS SP1" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=F87B4C5E-4161-48AF-9FF8-A96993C688DF&amp;displaylang=en" target="_blank">You can get it here.. </a></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.shariqsheikh.com%2Fblog%2Findex.php%2F200802%2Fwsus-30-sp1-gets-released%2F&amp;linkname=WSUS%203.0%20SP1%20gets%20released">Share/Bookmark</a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.shariqsheikh.com/blog/index.php/200802/wsus-30-sp1-gets-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
