RE: Adding 2008 DC's... (revisited)

2010-02-10 Thread Michael B. Smith
Great stuff. Thanks. Regards, Michael B. Smith Consultant and Exchange MVP http://TheEssentialExchange.com -Original Message- From: Free, Bob [mailto:r...@pge.com] Sent: Tuesday, February 09, 2010 8:04 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Th

RE: Adding 2008 DC's... (revisited)

2010-02-09 Thread Free, Bob
Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Whoa. They've done some serious updating to those articles in the last couple of months. I've not seen those mentioned in any of the other lists I read - where did you get those Bob? From your PFE or TAM? Or someplace more public

RE: Adding 2008 DC's... (revisited)

2010-02-09 Thread Brian Desmond
m: Ken Schaefer [...@adopenstatic.com] Sent: Tuesday, February 09, 2010 5:11 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) I think Brian means that environments that already have problems (e.g. in replication) may experience issues when you propagate schema changes, or

RE: Adding 2008 DC's... (revisited)

2010-02-09 Thread Michael B. Smith
e MVP http://TheEssentialExchange.com -Original Message- From: Free, Bob [mailto:r...@pge.com] Sent: Tuesday, February 09, 2010 5:07 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) >I'm assuming you mean multiple domains/forests/trusts? It *could* h

RE: Adding 2008 DC's... (revisited)

2010-02-09 Thread Free, Bob
2010 2:55 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Can you expand on that? I don’t see how a schema change in itself causes problems. I'm assuming you mean multiple domains/forests/trusts? (Our site is W2K3 D/FFL - One domain/forest, lots of pretty W2K

RE: Adding 2008 DC's... (revisited)

2010-02-09 Thread Ken Schaefer
: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Can you expand on that? I don’t see how a schema change in itself causes problems. I'm assuming you mean multiple domains/forests/trusts? (Our site is W2K3 D/FFL - One domain/forest, lots of pretty W2K3 boxes :) ---

RE: Adding 2008 DC's... (revisited)

2010-02-09 Thread Palmer, Neal
d.com] Sent: 08 February 2010 19:00 To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Sort of. I've seen this cause issues in large (and messy) customer environments before. Thanks, Brian Desmond br...@briandesmond.com c – 312.731.3132 > -Original Message-

RE: Adding 2008 DC's... (revisited)

2010-02-08 Thread Brian Desmond
gt; To: NT System Admin Issues > Subject: RE: Adding 2008 DC's... (revisited) > > Nit picker. :-) > > Regards, > > Michael B. Smith > Consultant and Exchange MVP > http://TheEssentialExchange.com > > > -Original Message- > From: Brian Desmon

RE: Adding 2008 DC's... (revisited)

2010-02-08 Thread Michael B. Smith
Nit picker. :-) Regards, Michael B. Smith Consultant and Exchange MVP http://TheEssentialExchange.com -Original Message- From: Brian Desmond [mailto:br...@briandesmond.com] Sent: Monday, February 08, 2010 12:55 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revi

RE: Adding 2008 DC's... (revisited)

2010-02-08 Thread Brian Desmond
d.com c – 312.731.3132 > -Original Message- > From: Michael B. Smith [mailto:mich...@smithcons.com] > Sent: Monday, February 08, 2010 8:04 AM > To: NT System Admin Issues > Subject: RE: Adding 2008 DC's... (revisited) > > Adprep adds the schema changes. &g

RE: Adding 2008 DC's... (revisited)

2010-02-08 Thread Palmer, Neal
Ok! Thanks Michael. (trawling through this stuff can sometimes cloud the mind) -Original Message- From: Michael B. Smith [mailto:mich...@smithcons.com] Sent: 08 February 2010 14:04 To: NT System Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Adprep adds the schema ch

RE: Adding 2008 DC's... (revisited)

2010-02-08 Thread Michael B. Smith
Admin Issues Subject: RE: Adding 2008 DC's... (revisited) Hi all, (Apologies for the long unwieldy sentences!) (D/FL = Domain/Forest Functional Level) I just wondered if anyone can confirm that the AD DS updates/Schema changes and features are all performed during the Adprep before you in

RE: Adding 2008 DC's... (revisited)

2010-02-08 Thread Palmer, Neal
ing info/requirements to start moving to W2K8. First stage is to get one W2K8 DC in... Thanks Neal From: Brian Desmond [mailto:br...@briandesmond.com] Sent: 27 January 2010 06:16 To: NT System Admin Issues Subject: RE: Adding 2008 DC's... The particular issue Bob noted is o

RE: Adding 2008 DC's...

2010-01-26 Thread Brian Desmond
January 25, 2010 5:05 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... Hi from a lurker :) Can I just thank you guys for this heads and your post Bob... Im tasked with investigating a 2003>2008 domain raise this year and this is an awesome starting poi

RE: Adding 2008 DC's...

2010-01-25 Thread Palmer, Neal
mer Senior Technical Support Officer UWIC, Cardiff, Wales... ___ From: Brian Desmond [mailto:br...@briandesmond.com] Sent: 09 January 2010 02:55 To: NT System Admin Issues Subject: RE: Adding 2008 DC's... It

RE: Adding 2008 DC's...

2010-01-11 Thread Erik Goldoff
27; _ From: David Lum [mailto:david@nwea.org] Sent: Friday, January 08, 2010 11:00 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... Yeah, intellectually I get that. It's frustrating to me because it goes from someone who actually _likes_ to pay atte

Re: Adding 2008 DC's...

2010-01-10 Thread asbzone
8 Jan 2010 08:00:05 To: NT System Admin Issues Subject: RE: Adding 2008 DC's... Yeah, intellectually I get that. It's frustrating to me because it goes from someone who actually_likes_ to pay attention to that stuff to a team that couldn't care less about it and will do the minim

RE: Adding 2008 DC's...

2010-01-08 Thread Brian Desmond
Issues Subject: RE: Adding 2008 DC's... Michael- I'm probably further in your debt than the other way around :) One thing this conversation did stir up in my addled old brain that is actually germane to the "what happens when I flip the bit" question is that when you switch D

RE: Adding 2008 DC's...

2010-01-08 Thread Free, Bob
iday, January 08, 2010 3:35 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... Thanks Bob! Let me buy you one (or a few) at TEC... From: Free, Bob [mailto:r...@pge.com] Sent: Friday, January 08, 2010 6:22 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's..

RE: Adding 2008 DC's...

2010-01-08 Thread Michael B. Smith
Thanks Bob! Let me buy you one (or a few) at TEC... From: Free, Bob [mailto:r...@pge.com] Sent: Friday, January 08, 2010 6:22 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... > I haven't seen anything documented about raising the DFL/FFL causing security > cha

RE: Adding 2008 DC's...

2010-01-08 Thread Free, Bob
.@umn.edu] Sent: Friday, January 08, 2010 6:29 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... I haven't seen anything documented about raising the DFL/FFL causing security changes. Do you have anything about this that you can share? I have seen the 2008 DCs remov

Re: Adding 2008 DC's...

2010-01-08 Thread James Rankin
TGIF…I think. > > *David Lum** **// *SYSTEMS ENGINEER BUT MAYBE SHOULD BE HELP DESK TECH > > NORTHWEST EVALUATION ASSOCIATION > (Desk) 971.222.1025 > *// *(Cell) 503.267.9764 > > > > > > > > *From:* Michael B. Smith [mailto:mich...@smithcons.com] > *Sent:* Th

RE: Adding 2008 DC's...

2010-01-08 Thread Ziots, Edward
: RE: Adding 2008 DC's... Yeah, intellectually I get that. It's frustrating to me because it goes from someone who actually _likes_ to pay attention to that stuff to a team that couldn't care less about it and will do the minimum necessary to roll it out, they'll do it

Re: Adding 2008 DC's...

2010-01-08 Thread Jon Harris
de, that blows. > > > > Carefully document your “I told you so’s” for when it explodes > spectacularly! > > > > -sc > > > > *From:* David Lum [mailto:david@nwea.org] > *Sent:* Friday, January 08, 2010 9:16 AM > > *To:* NT System Admin Issues >

RE: Adding 2008 DC's...

2010-01-08 Thread David Lum
, January 08, 2010 8:29 AM To: NT System Admin Issues Subject: Re: Adding 2008 DC's... Was there any explanation as to why they chose the other team to handle this particular task? If not, I would discuss it with one of the decision makers before thinking the worst. It sounds like you

Re: Adding 2008 DC's...

2010-01-08 Thread Sean Martin
d actually get proficient at one of ‘em. > > > > *From:* Kim Longenbaugh [mailto:k...@colonialsavings.com] > *Sent:* Friday, January 08, 2010 6:23 AM > > *To:* NT System Admin Issues > *Subject:* RE: Adding 2008 DC's... > > > > Not demoted, just a vi

RE: Adding 2008 DC's...

2010-01-08 Thread David Lum
ay, January 08, 2010 6:23 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... Not demoted, just a victim of political maneuvering, or a decision by some PHB that hasn't reset his Etch-a-Sketch lately. From: David Lum [mailto:david@nwea

RE: Adding 2008 DC's...

2010-01-08 Thread Steven M. Caesare
Dude, that blows. Carefully document your "I told you so's" for when it explodes spectacularly! -sc From: David Lum [mailto:david@nwea.org] Sent: Friday, January 08, 2010 9:16 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... Amazing, after a m

RE: Adding 2008 DC's...

2010-01-08 Thread Michael B. Smith
the support back. -Mike From: bounce-8784996-8243...@lyris.sunbelt-software.com [mailto:bounce-8784996-8243...@lyris.sunbelt-software.com] On Behalf Of Michael B. Smith Sent: Thursday, January 07, 2010 12:51 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... It removes a number

RE: Adding 2008 DC's...

2010-01-08 Thread Michael Waltonen
ce-8784996-8243...@lyris.sunbelt-software.com [mailto:bounce-8784996-8243...@lyris.sunbelt-software.com] On Behalf Of Michael B. Smith Sent: Thursday, January 07, 2010 12:51 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... It removes a number of "obsolete" security

RE: Adding 2008 DC's...

2010-01-08 Thread Kim Longenbaugh
From: Michael B. Smith [mailto:mich...@smithcons.com] Sent: Thursday, January 07, 2010 10:51 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... It removes a number of "obsolete" security options. I quote the word "obsolete" because some older/insecure

RE: Adding 2008 DC's...

2010-01-08 Thread David Lum
lto:mich...@smithcons.com] Sent: Thursday, January 07, 2010 10:51 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... It removes a number of "obsolete" security options. I quote the word "obsolete" because some older/insecure products depend on them. Older ver

RE: Adding 2008 DC's...

2010-01-07 Thread Michael B. Smith
"CAS" that allowed a single sign-on to Apache/IIS/and Windows by actually doing a man-in-the-middle attack! It depended on this too. From: David Lum [mailto:david@nwea.org] Sent: Thursday, January 07, 2010 1:36 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's...

RE: Adding 2008 DC's...

2010-01-07 Thread David Lum
>From what I've read changing the functional level to 2008 doesn't really "do" >anything I particular anyway, right? From: Michael B. Smith [mailto:mich...@smithcons.com] Sent: Thursday, January 07, 2010 9:09 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC

RE: Adding 2008 DC's...

2010-01-07 Thread David Lum
Agreed. 2008 R2 is the plan actually, but from my org's perspective going to 2008 or 2008 R2 is the same level of change. Dave From: Tim Vander Kooi [mailto:tvanderk...@expl.com] Sent: Thursday, January 07, 2010 9:10 AM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... I

RE: Adding 2008 DC's...

2010-01-07 Thread Steven M. Caesare
It is a significant change... but a very safe one, IMO. If you aren't doing anything specifically custom that might barf on seeing NEW schema attributes show up, this is a non-impact operation. -sc From: David Lum [mailto:david@nwea.org] Sent: Thursday, January 07, 2010 12:00 PM To

RE: Adding 2008 DC's...

2010-01-07 Thread Michael B. Smith
Sent: Thursday, January 07, 2010 12:12 PM To: NT System Admin Issues Subject: RE: Adding 2008 DC's... The only issue I've had so far is when there are legacy unix/linux clients authenticating to AD using samba. We have some older storage appliances that are out of support that wo

RE: Adding 2008 DC's...

2010-01-07 Thread Matthew Bullock
The only issue I've had so far is when there are legacy unix/linux clients authenticating to AD using samba. We have some older storage appliances that are out of support that wont authenticate after upgrading a single DC to 2008. -mb From: David Lum [mailto:david@nwea.org] Sent: Thursday,

RE: Adding 2008 DC's...

2010-01-07 Thread Michael B. Smith
You have to run the schema upgrade, but nothing says that you ever have to bump the domain functional level or the forest functional level. I've done this for a number of customers, with no ill effect. I'd recommend you roll out 2008 or 2008 R2. It'll save you work in the future. From: David Lu

RE: Adding 2008 DC's...

2010-01-07 Thread Tim Vander Kooi
I am curious why you would only go to Server 2008 and not 2008 R2? If you are going to begin your migration of AD to a newer version why not go to the latest one available instead of remaining a couple of years behind? Having at least one DC at 2008 R2 will also make more of the "better together"