PDA

View Full Version : Windows 2003 AD tombstoning


Burble
03-08-2009, 10:15
On July 10th we closed our office in Denmark and I was told that all the IT stuff there would be sent to the office in Sweden. It transpires that nobody can be arsed to do that so there are a couple of servers (one of which is a DC) sitting in the home office of one of the Danish salesmen.

To save a lot of hassle I want to get that DC (which is also a file server) over to Sweden and up and running again before it'll be tombstoned and that means I'll need to fly to Copenhagen, get the server and drive it to Uppsala. That in itself isn't a problem but finding the time to do it is a bit of a problem. Also finding someone else or some other way of doing it is a problem for mainly internal political reasons.

I always thought that the tombstone lifeline for a 2003 DC was 60 days but from reading this page (http://technet.microsoft.com/en-us/library/cc784932%28WS.10%29.aspx) it seems that if the forest was created on a 2003 SP1 or SP2 box then the period is 180 days.

Using adsiedit I checked the value for our forest and it is <not set>.

What I'm a bit confused about is what is the tombstone lifetime for an AD forest that was originally an NT 4 domain that was upgraded to AD on a 2003 (no SP) box. Logic says it should be 60 days since that box was pre SP1 but I can't find a definite statement to that fact.

Anyone got any ideas?

Daz
03-08-2009, 10:30
Hmm, good question, I would have thought your logic was correct though - afaik applying a service pack to a DC does nothing to the domain or forest schemas.

Not sure what you're worried about though - tombstoning only applies to deleted objects, so it can sit there off for a while and it'll come back up and replicate with no drama. Unless I'm mistaken or missing something :)

Burble
03-08-2009, 10:34
it'll come back up and replicate with no drama

It will? Cool, problem solved in that case.

Daz
03-08-2009, 10:43
Aye :) So long as it was contactable when it was taken down then it will just be out of date and get largely overwritten by DC's who know better.

You'll probably want to force replication (http://technet.microsoft.com/en-us/library/cc816926%28WS.10%29.aspx) as soon as it's up though, you wont want anyone hitting that DC being so out of date :)

Burble
03-08-2009, 10:44
Awesome! Cheers dude!

Feek
03-08-2009, 12:46
If you can wait a couple of weeks, I have a week off and I'll go move it for you. No charge, just expenses ;) ;D

Burble
03-08-2009, 14:16
Fancy installing a new rack while you're there Feekles? Nothing difficult, just a bog standard 42U rack with about 5 servers and the associated gubbins.

Fayshun
03-08-2009, 19:52
If you can wait a couple of weeks, I have a week off and I'll go move it for you. No charge, just expenses ;) ;D

Fancy installing a new rack while you're there Feekles? Nothing difficult, just a bog standard 42U rack with about 5 servers and the associated gubbins.
Need a tea boy/screwdriver holder?

Feek
03-08-2009, 21:12
Sure thing. Is the rack assembled? If not, I know a monkey with a screwdriver!