[ActiveDir] Smart array(OT)

2005-07-20 Thread Kern, Tom
I'm using Smart Array 6i to create a raid 0 +1 array with 4 drives. I'm using the web array config utlilty from hp to do this. It offers to create a raid 0+1 array but when i do, it turns out to be just raid 1(thats what it says in the bios bot up screen) also, i have another array with 2 drives

RE: [ActiveDir] WAY OT: Conflicting RAID terminiology (used to be Smart array(OT)

2005-07-20 Thread Kern, Tom
aid 10. If I recall, Adaptec and Dell coined the the Raid 10 term back in 1999. I always use the bios utility to create my drive raid arrays, what does that say? Jose -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Kern, Tom Sent: Wednesday, July 20, 2005 11:4

Re: [ActiveDir] WAY OT: Conflicting RAID terminiology (used to be Smart array(OT)

2005-07-20 Thread Kern, Tom
I want raid 0+1. Smart array as I stated let's me create a raid 0+1 with 2 drives which I know is just plain wrong. When I say smart array, I mean the web based Array Configuration Utlilty. In the bios of the system it says I have raid 1. In the ACU, it tells me raid 0+1. Just wondering if anyo

RE: [ActiveDir] WAY OT: Conflicting RAID terminiology (used to be Smart array(OT)

2005-07-21 Thread Kern, Tom
utility to create my drive raid arrays, what does that say? Jose -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Kern, Tom Sent: Wednesday, July 20, 2005 11:42 AM To: ActiveDir (E-mail) Subject: [ActiveDir] Smart array(OT) I'm using Smart Array 6i t

[ActiveDir] OT: new job

2005-07-23 Thread Kern, Tom
I just got offered a position with a consulting company where I would be consulting full time for a major financial corp in NYC as their AD/Exchange guy. I'm a little nervous and I was wondering if anyone here had experience with big financial corps and IT. Is it very different from doing IT for

Re: [ActiveDir] OT: new job

2005-07-23 Thread Kern, Tom
Thanks for all your replies. This really helps. As I told Al offlist, I'm gonna start asking you guys for relationship advice. Also as Al pointed out,I'm most def a generalist. I'm the only engineer at my current job with 400 users. I do the DNS(Win and BIND) as well as the routers/switches,firewa

Re: [ActiveDir] OT: new job

2005-07-24 Thread Kern, Tom
Thanks for your support, Robert and Rick. It means quite a lot. You guys are great. Thanks again. P.S.- I've been know to shoot a game or two of pool on the upper east side. -- Sent from my BlackBerry Wireless Handheld (www.BlackBerry.net) List info : http://www.activ

Re: [ActiveDir] OT: new job

2005-07-24 Thread Kern, Tom
Well, my fears are twofold. There is the fear of the unknown and my own insecurities as to my AD/Exchange knowldge. Also, I have a 2yr old son and another on the way. That makes things doubly scary. If this were 5 yrs ago, I wouldn't think twice about jumping. I wouldn't have even read the handbo

Re: [ActiveDir] OT: new job

2005-07-24 Thread Kern, Tom
I'm the latter. I have multiple networks running at home. If it weren't for VMware, my wife would throw me and my machines out already :) Before I had my current job about 4 years ago, I was running Netware 5 servers and NDS at home(why, I have no idea). I also have a couple of 1700 and 1900 cisco

RE: [ActiveDir] OT: new job

2005-07-25 Thread Kern, Tom
trategy. In your situation, if you find yourself spending 80 hours a week to migrate this company's data back home, is it worth it? Cause to me that is one hell of a change in my life, and I like to do more things than just work. /Psycho Babble off -Original Message- From: Kern, Tom [

Re: [ActiveDir] OT: new job

2005-07-25 Thread Kern, Tom
Aside from notes and drafts and config dumps, is there any formal way people keep and maintain changes and documentation? Or is this all done "on the fly" kinda thing usually? Thanks -- Sent from my BlackBerry Wireless Handheld (www.BlackBerry.net) List info : http://

RE: [ActiveDir] OT: new job

2005-07-26 Thread Kern, Tom
Title: RE: [ActiveDir] OT: new job exuse my ignorance, but what is the "AD Mapper Tool" and where can I get it? Is this a part of Visio?   Thanks and sorry for being so unaware. -Original Message-From: Myrick, Todd (NIH/CC/DNA) [mailto:[EMAIL PROTECTED]Sent: Tuesday, July 26, 2

RE: [ActiveDir] OT: empty network neighborhood

2005-07-26 Thread Kern, Tom
Go to that pc and open regedit and change the value of this key to "false"- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser\Parameters this will stop that machine from trying tp participate in browser elections and become a master browser for your subnet. Also, before doing this, i

[ActiveDir] exchange/dhcp/multihoming question(OT)

2005-07-26 Thread Kern, Tom
I set up an exchange 2k3 server. it had 2 nics. one had a static addy, the other was dhcp(it got all the dns info from dhcp as well). the dhcp lease was set for 3 days In this setup, mail was stuck in the queues for hours. sometimes days, but eventually delivered. the moment i disabled the dhcp

RE: [ActiveDir] OT: empty network neighborhood

2005-07-26 Thread Kern, Tom
Maybe I should see if I can reboot the machine in question. Any more ideas? Thanks,jb -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: Tuesday, July 26, 2005 10:50 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] OT: empty network

RE: [ActiveDir] exchange/dhcp/multihoming question(OT)

2005-07-26 Thread Kern, Tom
Title: [ActiveDir] exchange/dhcp/multihoming question(OT) no. i screwed up. both nic's are on the same network with the same default gateway -Original Message-From: Al Mulnick [mailto:[EMAIL PROTECTED]On Behalf Of Al MulnickSent: Tuesday, July 26, 2005 2:10 PMTo: Activ

RE: [ActiveDir] OT: empty network neighborhood

2005-07-26 Thread Kern, Tom
that subnet and browstat sta only list the one computer, no other computers are running as backups. I tried to force an election with browstat, but it didn't seem to do anything. Maybe I should see if I can reboot the machine in question. Any more ideas? Thanks,jb -Original Message- F

[ActiveDir] User to computer

2005-07-28 Thread Kern, Tom
Is there anyway via VBscript(or another way) to find out on a large scale which user is logged on to which desktop? The company I'm working at right now put all their computer objects in the computer folder and I want to move some user's(about 40) pc's to an ou so I can push out an msi via compu

RE: [ActiveDir] _gc and _ldap SRV records

2005-07-29 Thread Kern, Tom
Title: [ActiveDir] _gc and _ldap SRV records Whats the difference or adverse affects of just making a secondary copy of the root domain zone on every dns server in a multi domain forest as that zone contains the _MSDC. zone instead of partitioning just the _MSDC zone?   Also, how do you

[ActiveDir] Advice

2005-07-29 Thread Kern, Tom
I'm starting a new job in a week as a AD/Exchange engineer(I posted about my anxieties before on the list). This company used to outsource all their AD/Exchange infrastructure and now they want to take control of it. As it stands, their relationship with the outsourcing firm is rocky. While the D

Re: [ActiveDir] Advice

2005-07-30 Thread Kern, Tom
I haven't started there yet. What the head AD guy told me was that they had no DA/EA, Exchange Full Admin access. He was just hired a month ago. Until then, they completely outsourced the whole AD/Exchange infrastructure(whatever that means, exactly.). What he's been doing for a month, I have no

Re: [ActiveDir] Advice

2005-07-30 Thread Kern, Tom
Sorry. Point taken. I didn't mean I was going to give up the ghost on the company, so to speak. I just implied I would be asking you guys for help that would be AD specfic but not internal company related except for the brief info I've just given you. As in- company outsourced AD. No access. No

[ActiveDir] OT and silly

2005-08-01 Thread Kern, Tom
Ok, I'm trying to install office 2k on a winxp sp2 box and I keep getting the windows file protection warning to insert the winxp sp 2 cd. This drives me nuts because A. I only have a winxp sp1 cd which I installed the os with and later downloaded sp2. B. It doesn't let you browse to a share or

Re: [ActiveDir] OT and silly

2005-08-01 Thread Kern, Tom
I guess that means I'm screwed... Thanks. I really dig your MCSA/MCSE MS press book, btw. That and the others in the series got me my MCSE for 2003. Keep up the good work!! -- Sent from my BlackBerry Wireless Handheld (www.BlackBerry.net) List info : http://www.actived

[ActiveDir] Terribly OT

2005-08-01 Thread Kern, Tom
I know. I've been OTing all over the place. Sorry. One last question- How do you mget a bunch of folders and files via ftp without being prompted all the time? I'm using IIS 5.0 and I'm trying to get a folder with a bunch of subfolders and files and I don't feel like sitting here and hitting "Y

Re: [ActiveDir] Terribly OT

2005-08-01 Thread Kern, Tom
Forget it. Ftp -i ftp.site.tld Sorry. I'm getting stupid with the heat here in New York. -- Sent from my BlackBerry Wireless Handheld (www.BlackBerry.net) List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: ht

Re: [ActiveDir] Biggest AD Gripes

2005-08-02 Thread Kern, Tom
I know I'm gonna get hell for this, but what's wrong with the creator/owner SD? I'm gonna duck in a second -- Sent from my BlackBerry Wireless Handheld (www.BlackBerry.net) List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.

Re: [ActiveDir] Account lockout

2005-08-02 Thread Kern, Tom
-- Sent from my BlackBerry Wireless Handheld (www.BlackBerry.net) List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Re: [ActiveDir] Biggest AD Gripes

2005-08-02 Thread Kern, Tom
I think what a lot of the stuff people are asking for is to take some of the stuff that NDS and eDir already use. Rights and login scripts at ou's and divivding AD as an admin sees fit. As least that's what it seems like to me but I haven't worked with Novell in about 4yrs. --

RE: [ActiveDir] Biggest AD Gripes

2005-08-02 Thread Kern, Tom
I'm not qualified to gripe but i will throw my 2 cents in anyway(just to get an answer to this question)- Why do you need local system? At all? Ever? Why can't services just run under their own non-privilged accounts as they do on 'nix boxes? Why can't a service start with elevated privilges t

Re: [ActiveDir] Biggest AD Gripes

2005-08-03 Thread Kern, Tom
I've been going to Sunguard in Philly for 3 yrs now and I can confirm its a huge PITA. Right now we just put win2k on a laptop and dcpromo it then diconnect and remove the other dc metadata and vice versa and then take the laptop with us to Sunguard for the DR. Its worked pretty well so far. ---

[ActiveDir] Exchange issues again(ot)

2005-08-26 Thread Kern, Tom
I'm trying to install exchange 2k with the diasterrecovery switch. I have no connectivity to the Schema master FSMO at the moment and exchange keeps telling me it can't go forward because it can't contact the Schema master. Now, i'm not trying to run forestprep(this has already been done). I'm

RE: [ActiveDir] Exchange issues again(ot)

2005-08-26 Thread Kern, Tom
Can you tell me what setup needs to write to the schema? Isn't this kinda a bug or at the least a big annoyance that everytime you need to recover or install a new exchange server, you need connectivity to the schema master? What would a reinstall need to write, anyway? its already in AD. What

RE: [ActiveDir] Exchange issues again(ot)

2005-08-26 Thread Kern, Tom
second server in AD) would need to write to the schema? can someone please tell me before i pull my hair out? I would say this is not a "feature". Thanks -Original Message- From: Kern, Tom on behalf of Kern, Tom Sent: Fri 8/26/2005

RE: [ActiveDir] Exchange issues again(ot)

2005-08-26 Thread Kern, Tom
No, I already have an exchange org installed!!! I have 10 exchange servers in my AD. I'm just trying to recover one with the /disasterrecovery switch instead of restoring system state to dissimallar hardware. I'm not introducing exchange into AD for the first time. I have an exchange org a

RE: [ActiveDir] Exchange issues again(ot)

2005-08-26 Thread Kern, Tom
I have no rights nor connectivity. I ran adsiedit.msc as localsystem on a child dc and changed the fSMORoleHolder attrib on the schema NC to point to the child dc i do have connectivity to and it worked. Mind you- THIS IS A TEST FOREST. I WOULD NEVER DO THIS IN PRODUCTION. still, i'd like t

[ActiveDir] Exchange 2k hotfix issue(OT)

2005-08-29 Thread Kern, Tom
I reinstalled exchange 2k with the /diasterrecovery swtich. Did the same with sp3 for exchange. however when i try to install the post sp3 rollup, it tells me i'm not at sp 3. Also there is no M: drive created and when i try to do a db restore, the store won't mount with eventid 619. Event i

[ActiveDir] Mail journaling(OT)

2005-09-01 Thread Kern, Tom
What mail archving software do you guys use? My manager wants to use a product called Sector but it seems pretty ineifficent to me. You set up journaling mailbox on Exchange and then you set up a workstation with outlook to connect to the journaling mailbox and the Sector agents grab the mai

RE: [ActiveDir] Mail journaling(OT)

2005-09-01 Thread Kern, Tom
Sorry, I meant archiving. They want to archiving everything to a 3rd party firm and not deal with it. There has to be a better way than mapi to get the 3rd party all the emails. Thanks -Original Message- From: Phil Renouf [mailto:[EMAIL PROTECTED] Sent: Thu 9/

[ActiveDir] Precreating sites and subnets

2005-09-01 Thread Kern, Tom
I'm trying to run this script from MS to precreate site and subnet objects in a test forest from a csv file. That works fine but I also would like to add a descritpion for each subnet from the same csv file. How can I edit this script to do that? Thanks. Sorry for being lazy but i'm kinda u

RE: [ActiveDir] Precreating sites and subnets

2005-09-01 Thread Kern, Tom
Thanks. I don't want to set the descriptions of the subnets in the script but from a csv file which has a description for every subnet I'm having a problem reading the description from a file. The file is - Sitename,subnet,"descritpion" thanks again -Original Message- F

RE: [ActiveDir] hide an attribute

2005-09-06 Thread Kern, Tom
So if you have a mixed mode forest, what if you give perms directly to Global groups on Enterprise objects in AD and only use local groups for Domain local stuff? or are you just supposed to rely on Auth users or Everyone for stuff like that? What happens if your perms are checked against a G

[ActiveDir] disabling users

2005-09-21 Thread Kern, Tom
I'd like to script disabling users from a csv file. I think Joe's Oldcmp can disable users but i'd like to feed the users from a csv file since they are all over my AD. Also, as a backup, i'd like a simillar script to enable users from a csv file. Robbie Allen's AD Cookbook has a simillar scrip

RE: [ActiveDir] disabling users

2005-09-21 Thread Kern, Tom
I only have time to learn one scripting lang. i figured perl is the better way to go as i have to work with linux and solaris as well. know of any good docs,books,sites on perl and COM+ or adsi? something that will teach you both like the VBscript resources do? i really think there is a market

[ActiveDir] dns suffix search list

2005-09-22 Thread Kern, Tom
I know this was discussed on the list earlier(can't seem to find it), but is this article correct and are these the only ways to programmatically alter the dns suffix search list? http://support.microsoft.com/kb/q275553/ Is there an easy way to do this for many computers, say from a text file

RE: [ActiveDir] dns suffix search list

2005-09-22 Thread Kern, Tom
I'm only running win2k I'd like to make the script query a text file of client names, so i can just execute it from my desktop rather than a script. how would i go about doing that? Thanks -Original Message- From: Grillenmeier, Guido [mailto:[EMAIL PROTECTED] Sen

RE: [ActiveDir] dns suffix search list

2005-09-23 Thread Kern, Tom
uh, my options stop at # 76 on my win2k sp4 dhcp server. I don't even go as high as 135 i guess you have a special dhcp server. anyhoo, i've never seen being able to set this in dhcp and MS claims you can't here- http://support.microsoft.com/kb/q275553/ That article was last reviewed

[ActiveDir] 2 exchange public folder questions

2005-09-29 Thread Kern, Tom
1. When I attach a shortcut to a public folder item(word doc) as an attachment to an email, many users cannot open the attachement but just click on the shortcut and nothing happens. they all have appropriate rights to the folder. is this some OLE issue on the client? by what mechanism does this

[ActiveDir] message tracking

2005-10-12 Thread Kern, Tom
I'm running exchange 2k post sp3 rollup. when i try to do a search on certain users in message tracking, i get "one or more entries in the Recipients field are invalid and will not be used in the search. Each entry must be a valid email address or user" For other users it works. there is nothi

RE: [ActiveDir] Display in ADUC

2005-10-12 Thread Kern, Tom
ok, so the Common Name is created from the First and Last name and in ADUC, the name displayed is NOT the displayName but the CN yet in the GAL it is the displayNmae that you see? And how is the CN affected by the DisplaySpecifiers node in the config NC? And in ADUC? And the GAL? and changing t

[ActiveDir] Trust issue

2005-10-12 Thread Kern, Tom
I have an external 2 way trust between a child domain in a win2k3 forest (win2k3 FFL) and a child domain in a win2k native mode forest. I set up the trust thru netdom or the Domains and Trusts mmc and after a few minutes it fails coming from the win2k side. the win2k domain/dc stops trusting th

RE: [ActiveDir] Trust issue

2005-10-12 Thread Kern, Tom
two places? PDC emulators in particular? Thanks, Brian Desmond [EMAIL PROTECTED] c - 312.731.3132 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom

RE: [ActiveDir] Trust issue

2005-10-12 Thread Kern, Tom
but not the other? Thanks, Brian Desmond [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]> c - 312.731.3132 _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom

[ActiveDir] whats in a name?

2005-10-12 Thread Kern, Tom
It was bought up on the list earlier that the name displayed in ADUC is not the displayName but really the CN which is made up of the first name and last name. I guess this depends on the Display Specifiers node in the config NC. How does this relate to the GAL? How do names get built for that? is

RE: [ActiveDir] Trust issue

2005-10-12 Thread Kern, Tom
om: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: Wednesday, October 12, 2005 2:41 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] Trust issue Nope. also as an aside,what is pretty amusing(in a frus

RE: [ActiveDir] Display in ADUC

2005-10-13 Thread Kern, Tom
I know that. Thanks Dean Just wondering what affects what. Does changing that affect the creation of the name displayed(not to be confused with displayName) in ADUC ? Or just the GAL? How 'bout the CN? The CN is created from given name and surname so i assume it is affected by changing

RE: [ActiveDir] Display in ADUC

2005-10-13 Thread Kern, Tom
I think you misunderstand me. i know the diff between the lDAPDisplayName and the display name that you see in the gui and that ldap,adsi,and all apps use the former. i was just wondering what the relationship is between how the display name gets built, its relationship to the name displayed

[ActiveDir] finding computer objects

2005-10-13 Thread Kern, Tom
Whats the best utility to find computer objects of a certain OS type(server as opposed to workstation) AND are NOT disabled and spit them to a csv file? Do i have to use a bitwise filter on the userAccountControl attrib or is there a utlitly with a more user friendly way to find non disabled acco

RE: [ActiveDir] Integrate Linux with AD

2004-02-03 Thread Kern, Tom
this is the best link I know.- http://www.securityfocus.com/infocus/1563 -Original Message- From: Jennifer Fountain [mailto:[EMAIL PROTECTED] Sent: Tuesday, February 03, 2004 10:13 AM To: [EMAIL PROTECTED] Subject: [ActiveDir] Integrate Linux with AD Does anyone know where I can locate

RE: [ActiveDir] Change home profile path for entire AD

2004-02-04 Thread Kern, Tom
Use DFS. -Original Message- From: Rob [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 04, 2004 8:42 AM To: [EMAIL PROTECTED] Subject: [ActiveDir] Change home profile path for entire AD We are moving to a new server for everyone's home folder this weekend. Is there a way to change in

RE: [ActiveDir] MS04-004

2004-02-11 Thread Kern, Tom
Title: RE: [ActiveDir] MS04-004 According to russ cooper on ntbugtraq, it does.   -Original Message- From: Celone, Mike [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 11, 2004 3:36 PM To: '[EMAIL PROTECTED]' Subject: RE: [ActiveDir] MS04-004   Anyone know if this also app

RE: [ActiveDir] MS04-004

2004-02-11 Thread Kern, Tom
so does this have any affect on the dialog box IE shows you for basic auth? does that still work? -Original Message- From: Salandra, Justin A. [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 11, 2004 3:49 PM To: '[EMAIL PROTECTED]' Subject: RE: [ActiveDir] MS04-004 Is there anyway t

RE: [ActiveDir] MS04-004

2004-02-11 Thread Kern, Tom
just finished testing it. it works fine with the dialog box. -Original Message- From: Coleman, Hunter [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 11, 2004 4:04 PM To: '[EMAIL PROTECTED]' Subject: RE: [ActiveDir] MS04-004 It should only affect URLs that embed user names and passwor

RE: [ActiveDir] MS04-004

2004-02-11 Thread Kern, Tom
ubject: RE: [ActiveDir] MS04-004   If it applies to ftp they how are people going to FTP?   -Original Message----- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 11, 2004 3:43 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] MS04-004   According to russ cooper on ntb

RE: [ActiveDir] Extended Rights

2004-02-24 Thread Kern, Tom
Title: Extended Rights you want to edit a file called "dssec.dat" in notepad to make the rights you want visible. -Original Message- From: Kent Maxwell [mailto:[EMAIL PROTECTED] Sent: Tuesday, February 24, 2004 10:28 AM To: [EMAIL PROTECTED] Subject: [ActiveDir] Extended Rig

RE: [ActiveDir] Networks are great when they work

2004-03-12 Thread Kern, Tom
Or angry ip scanner at  http://www.angryziber.com/ipscan -Original Message-From: Thommes, Michael M. [mailto:[EMAIL PROTECTED]Sent: Friday, March 12, 2004 1:54 PMTo: [EMAIL PROTECTED]Subject: RE: [ActiveDir] Networks are great when they work Seems to me if the device is

RE: [ActiveDir] Exchange/AD bug or poor design?

2004-03-18 Thread Kern, Tom
Title: Message can't you just set up a expansion server in the DL properties and use a global DL? -Original Message-From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]Sent: Thursday, March 18, 2004 2:04 PMTo: [EMAIL PROTECTED]Subject: RE: [ActiveDir] Exchange/AD bug or poor d

[ActiveDir] AD disaster recovery

2004-03-22 Thread Kern, Tom
We're doing a DR test run of AD. We go to another location and try to restore our network from tape backup(Veritas 8.6). Each time we've run into serious issues when restoring AD to different hardware(this is all our DR site provides) and have never been able to get up and running. So this time,

RE: [ActiveDir] AD disaster recovery

2004-03-22 Thread Kern, Tom
al Message----- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: 22 March 2004 14:51 To: ActiveDir (E-mail) Subject: [ActiveDir] AD disaster recovery We're doing a DR test run of AD. We go to another location and try to restore our network from tape backup(Veritas 8.6). Each time we've run

RE: [ActiveDir] AD disaster recovery

2004-03-22 Thread Kern, Tom
bject: RE: [ActiveDir] AD disaster recovery I would guess that you'll still have to remove the previuosly existing DC's regardless but it's hard to tell what steps you're planning exactly. al -Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Monday,

RE: [ActiveDir] AD disaster recovery

2004-03-22 Thread Kern, Tom
documentation on the website. http://www.microsoft.com/exchange/library for some detailed information. Al -Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Monday, March 22, 2004 2:22 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] AD disaster recovery my steps are as fo

[ActiveDir] disaster recovery

2004-03-24 Thread Kern, Tom
I just restored AD. I had a test laptop, pulled it off the network, ran ntdsutil, seized all 3 roles,ran metadata cleanup and removed all my old dc's. deleted them with adsiedit and all dns records as well. then at the DR site, i set up new servers with the same names as the old one's, ran dcpro

RE: [ActiveDir] disaster recovery

2004-03-24 Thread Kern, Tom
on 2003/2000 Red Hat Certified Technician _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: quarta-feira, 24 de marÃo de 2004 16:03 To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] disa

RE: [ActiveDir] disaster recovery

2004-03-24 Thread Kern, Tom
: Subject: RE: [ActiveDir] disaster recovery You Zones is setting for Dynamic Updates = YES??? _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: quarta-feira, 24 de marÃo de 2004 16:47 To

RE: [ActiveDir] disaster recovery

2004-03-24 Thread Kern, Tom
to restore the root domain as well. I've found that doing this with a virtual server is sometimes easier but that just saves on hardware requirements. Al _ From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Wednesday, March 24, 2004 3

[ActiveDir] replication

2004-03-24 Thread Kern, Tom
when servers replicate within a site OR intrasite, in a multi domain enviorment, do they need to contact a GC to find each other? or for any reason. what is the role of the gc in AD replication, inter and intra site? thanks .+-Šwè†Ûiÿü0Á-Š÷+ƒùšŠYb²Øm˜¸¬´P†Ûiÿü0Á-Š÷+ƒùb²×Úf.+-j·!Š÷¡¶Úÿ 0™¨¥j·!Š

[ActiveDir] RESTORE

2004-03-25 Thread Kern, Tom
Anyone know of a way to restore a child domain for a DR test, without any connectivity to the root domain of the forest? I don't need the chema or domain naming roles. I just want to get up and functional enough for user access and basic everyday use. This also involves restoring Exchange 2000.

RE: [ActiveDir] disaster recovery

2004-03-25 Thread Kern, Tom
ff all the time; that way you are not surprised at 0200 when everything is down. Al _ From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Wednesday, March 24, 2004 5:01 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] disaster recovery

RE: [ActiveDir] disaster recovery

2004-03-27 Thread Kern, Tom
f administrators, it doesn't make a difference. /Guido _____ From: Kern, Tom [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: Donnerstag, 25. MÃrz 2004 18:56 To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] disaster recovery

[ActiveDir] Services script

2004-03-29 Thread Kern, Tom
Is there a vb or perl script I can run on my network to enumerate all the services that run under a specfic account on my servers? I'm running a win2k AD network. Thanks alot List info : http://www.activedir.org/mail_list.htm List FAQ: http://www.activedir.org/list_faq.htm List archive: http

[ActiveDir] windows 2003 domain

2004-03-31 Thread Kern, Tom
If i have a forest where one domain has upgraded to windows 2003 at the win2k functional forest and domain level, would this have an adverse effect on other domains which were running dc's with win2k sp2 or vice versa? do those dc's/gc's need to be at least sp3? thanks List info : http://www.ac

[ActiveDir] scripting admin

2004-04-13 Thread Kern, Tom
sorry for what is more of a personal advice question- i'm a perl guy and i was wondering if for proper windows scripting, should i learn VBscript or can i get away with most admining with perl and activestate. i run a couple of linux and unix servers, so perl makes sense, but would it behove me

RE: [ActiveDir] moving domain admins

2004-04-14 Thread Kern, Tom
tiveDir] moving domain admins Heck of a cross post, isn't it? Moving the domain administrators group is not something that should cause this type of issue. What else was done during those changes? -Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Wednesday, April

RE: [ActiveDir] moving domain admins

2004-04-14 Thread Kern, Tom
ors from/to? Just from cn=users to something else? Al -----Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Wednesday, April 14, 2004 2:01 PM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] moving domain admins another labyrinthine cross post(sorry)- Also, i fire up adsi ed

[ActiveDir] moving domain admins

2004-04-14 Thread Kern, Tom
I know moving the default exchange groups out of the users folder can screw things up as exchange expects to find them there, but will moving the domain admins from the users folder into another ou(no gpo applied) screw things up with exchange or any other services in ad? I only ask because some

[ActiveDir] re: domain move

2004-04-14 Thread Kern, Tom
Also, i fire up adsi edit from their domain and i can only get to the organization in the config partition. when on go to the security tab, there are no entries. how can they just lose permissions to certain parts of the config paritition? the only change made was the root domain of the forest in

RE: [ActiveDir] moving domain admins

2004-04-15 Thread Kern, Tom
03 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] moving domain admins Well, let's backup. Where and why did they move the domain admins group? Can you move it back and see if your issue gets resolved? -Original Message----- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Wednes

RE: [ActiveDir] moving domain admins

2004-04-15 Thread Kern, Tom
(sp level of Windows DC?) and were the child domains domain prepp'd? Were both child domains treated the same? -Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Thursday, April 15, 2004 9:13 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] moving domain admins

RE: [ActiveDir] moving domain admins

2004-04-15 Thread Kern, Tom
n terms of mixed mode and sp3/4 dc/gc's. any thoughts? thanks -----Original Message- From: Kern, Tom Sent: Thursday, April 15, 2004 10:42 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] moving domain admins child domains are at sp3 and sp4. exchange2k sp3 child domains were not

RE: [ActiveDir] moving domain admins

2004-04-15 Thread Kern, Tom
lized was made. Can you double check the permissions on the ORG and AG's? -Original Message----- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Thursday, April 15, 2004 10:42 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] moving domain admins child domains are at sp3 and sp4. exchan

RE: [ActiveDir] moving domain admins

2004-04-15 Thread Kern, Tom
;s tough to get a read on the situation over time :) Seems odd though. -Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Thursday, April 15, 2004 11:39 AM To: [EMAIL PROTECTED] Subject: RE: [ActiveDir] moving domain admins yes they are mixed with the latest hotfixes

RE: [ActiveDir] moving domain admins

2004-04-15 Thread Kern, Tom
Even in the config container, they shouldn't have too many rights unless you've granted them. -Original Message- From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Thursday, April 15, 2004 4:53 PM To: [EMAIL PROTECTED]

RE: [ActiveDir] moving domain admins

2004-04-16 Thread Kern, Tom
t.aspx?scid=kb;en-us;823018  It describes what permissions are granted for each of the Exchange levels.   -ajm From: Kern, Tom [mailto:[EMAIL PROTECTED] Sent: Thursday, April 15, 2004 7:28 PMTo: [EMAIL PROTECTED]Subject: RE: [ActiveDir] moving domain admins no. they

[ActiveDir] win98 and win2ksp4

2004-04-16 Thread Kern, Tom
I upgraded one win2k dc to sp4. my 2 other dc's are at sp3, this includes the 3 fsmo roles holder. since then, everytime i create a new user, if that user is logging in from a win98 box, they get a "network name cannot be found" error. the win98 box has the DSclient installed. the default domain

RE: [ActiveDir] win98 and win2ksp4

2004-04-16 Thread Kern, Tom
----- From: Kern, Tom Sent: Friday, April 16, 2004 11:03 AM To: ActiveDir (E-mail) Subject: [ActiveDir] win98 and win2ksp4 I upgraded one win2k dc to sp4. my 2 other dc's are at sp3, this includes the 3 fsmo roles holder. since then, everytime i create a new user, if that user is logging

[ActiveDir] Default printer logon script OT

2004-04-20 Thread Kern, Tom
Sorry for the off topic. I'm running a VBscript to set the default printer to always be the same printer on a workstation( we have a legacy Paradox dos app and it always prints to the default printer) regardless of the user. When i run it from the current session, it works fine. However, when I

[ActiveDir] group policy roaming profiles

2004-04-21 Thread Kern, Tom
My gpo roaming profiles question is- i set up roaming profiles via desktop and application data folder redirection( i also set the profile in the "profile path" part of dsa.msc. i have some downlevel clients as well). I assume this will redirect Outlook mapi profiles as well so when a user moves

[ActiveDir] A root dc question

2004-05-12 Thread Kern, Tom
My apologies if this seems basic and/or silly. Aside from creating new domains or modifying the schema, why would an admin need access to the root dc of a forest(the schema, domain namming master)? furthermore, why would an admin in a child domain need enterprise admin privilges? I only ask bec

RE: [ActiveDir] A root dc question

2004-05-13 Thread Kern, Tom
your DR testing or you should redesign into multiple forests. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: Wednesday, May 12, 2004 4:37 PM To: ActiveDir (E-mail) Subject: [ActiveDir] A root dc question My apologies if this seems

RE: [ActiveDir] A root dc question

2004-05-13 Thread Kern, Tom
R testing with just a child domain. 3. Either your corp IT has to be involved with your DR testing or you should redesign into multiple forests. -Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kern, Tom Sent: Wednesday, May 12, 2004 4:37 PM To: Activ

  1   2   3   4   5   6   >