ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    DC Demotion Question

    IT Discussion
    11
    108
    8.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @tiagom
      last edited by

      @tiagom said in DC Demotion Question:

      I looked it up before i posted and it doesn't seem possible to make cached credentials expire. That's why i found it so odd that i thought the did expire.

      Well I thought that there was a way to expire them, too. That is very weird.

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        https://social.technet.microsoft.com/Forums/sharepoint/en-US/87e84872-c321-4b8c-b13d-0d60a003c3d3/how-long-does-windows-cache-domain-user-passwords?forum=winserversecurity

        Yup, looks like once you get a machine off of AD physically, you can attack it forever.

        travisdh1T 1 Reply Last reply Reply Quote 0
        • travisdh1T
          travisdh1 @scottalanmiller
          last edited by

          @scottalanmiller said in DC Demotion Question:

          https://social.technet.microsoft.com/Forums/sharepoint/en-US/87e84872-c321-4b8c-b13d-0d60a003c3d3/how-long-does-windows-cache-domain-user-passwords?forum=winserversecurity

          Yup, looks like once you get a machine off of AD physically, you can attack it forever.

          Wow, just, wow.

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • T
            tiagom
            last edited by tiagom

            Theres some built in safety from my understanding. The cached credentials are hashed twice, so at best they would only have access to that computer, it does not comprise the security of AD.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @travisdh1
              last edited by

              @travisdh1 yeah, I don't like that.

              1 Reply Last reply Reply Quote 0
              • BRRABillB
                BRRABill @dafyre
                last edited by

                @dafyre said in DC Demotion Question:

                As far as I can tell, you can use the Windows RSAT stuff to manage the SAMBA4 domain controllers, GPOs should work... Dang.. I need to spin one up now, lol.

                Let us know how that goes.

                1 Reply Last reply Reply Quote 1
                • wirestyle22W
                  wirestyle22 @dafyre
                  last edited by

                  @dafyre said in DC Demotion Question:

                  As far as I can tell, you can use the Windows RSAT stuff to manage the SAMBA4 domain controllers, GPOs should work... Dang.. I need to spin one up now, lol.

                  Interested in seeing this

                  BRRABillB 1 Reply Last reply Reply Quote 0
                  • BRRABillB
                    BRRABill @wirestyle22
                    last edited by

                    @wirestyle22 said

                    Interested in seeing this

                    @scottalanmiller said he is going to do a writeup someday (soon?) on this process. (Replacing AD with Samba.)

                    I'll probably give it a go. We're down to less than 20 employees, so if it burns, it burns.

                    wirestyle22W 1 Reply Last reply Reply Quote 1
                    • wirestyle22W
                      wirestyle22 @BRRABill
                      last edited by

                      @BRRABill said in DC Demotion Question:

                      @wirestyle22 said

                      Interested in seeing this

                      @scottalanmiller said he is going to do a writeup someday (soon?) on this process. (Replacing AD with Samba.)

                      I'll probably give it a go. We're down to less than 20 employees, so if it burns, it burns.

                      Is SAMBA4 better in a windows only environment or is it simply the best solution for hybrid environments?

                      travisdh1T 1 Reply Last reply Reply Quote 0
                      • travisdh1T
                        travisdh1 @wirestyle22
                        last edited by

                        @wirestyle22 said in DC Demotion Question:

                        @BRRABill said in DC Demotion Question:

                        @wirestyle22 said

                        Interested in seeing this

                        @scottalanmiller said he is going to do a writeup someday (soon?) on this process. (Replacing AD with Samba.)

                        I'll probably give it a go. We're down to less than 20 employees, so if it burns, it burns.

                        Is SAMBA4 better in a windows only environment or is it simply the best solution for hybrid environments?

                        In a Windows only environment, I don't know if it really makes sense. Assuming you have the license in place already, why not use the native platform? Doesn't mean a SAMBA DC doesn't make all kinds of sense when you don't have the licensing in place already.

                        wirestyle22W scottalanmillerS 2 Replies Last reply Reply Quote 0
                        • wirestyle22W
                          wirestyle22 @travisdh1
                          last edited by wirestyle22

                          @travisdh1 said in DC Demotion Question:

                          @wirestyle22 said in DC Demotion Question:

                          @BRRABill said in DC Demotion Question:

                          @wirestyle22 said

                          Interested in seeing this

                          @scottalanmiller said he is going to do a writeup someday (soon?) on this process. (Replacing AD with Samba.)

                          I'll probably give it a go. We're down to less than 20 employees, so if it burns, it burns.

                          Is SAMBA4 better in a windows only environment or is it simply the best solution for hybrid environments?

                          In a Windows only environment, I don't know if it really makes sense. Assuming you have the license in place already, why not use the native platform? Doesn't mean a SAMBA DC doesn't make all kinds of sense when you don't have the licensing in place already.

                          Well, you need to maintain said licensing (ie refreshes etc). I'd rather move to SAMBA and use the licensing for other stuff or spend less if possible

                          1 Reply Last reply Reply Quote 2
                          • scottalanmillerS
                            scottalanmiller @travisdh1
                            last edited by

                            @travisdh1 said in DC Demotion Question:

                            @wirestyle22 said in DC Demotion Question:

                            @BRRABill said in DC Demotion Question:

                            @wirestyle22 said

                            Interested in seeing this

                            @scottalanmiller said he is going to do a writeup someday (soon?) on this process. (Replacing AD with Samba.)

                            I'll probably give it a go. We're down to less than 20 employees, so if it burns, it burns.

                            Is SAMBA4 better in a windows only environment or is it simply the best solution for hybrid environments?

                            In a Windows only environment, I don't know if it really makes sense. Assuming you have the license in place already, why not use the native platform? Doesn't mean a SAMBA DC doesn't make all kinds of sense when you don't have the licensing in place already.

                            They have licensing for 2003. This is a free update.

                            BRRABillB 1 Reply Last reply Reply Quote 0
                            • BRRABillB
                              BRRABill @scottalanmiller
                              last edited by

                              @scottalanmiller said

                              They have licensing for 2003. This is a free update.

                              Huh?

                              wirestyle22W 1 Reply Last reply Reply Quote 0
                              • wirestyle22W
                                wirestyle22 @BRRABill
                                last edited by

                                @BRRABill said in DC Demotion Question:

                                @scottalanmiller said

                                They have licensing for 2003. This is a free update.

                                Huh?

                                He means I'm always going to have licensing in place

                                1 Reply Last reply Reply Quote 1
                                • BRRABillB
                                  BRRABill
                                  last edited by

                                  Well, I DCPROMOed the one physical DC last night. Nothing seems to have burned down.

                                  I was having some DNS issues, but I think it was due to the fact that my machine was pointing to the demoted DC (which obviously had the DNS role installed) and it had been gutted by DCPROMO. I removed the role and everything seems OK thus far.

                                  Though very few users are here. I'll feel better by like 10AM.

                                  JaredBuschJ 1 Reply Last reply Reply Quote 1
                                  • JaredBuschJ
                                    JaredBusch @BRRABill
                                    last edited by

                                    @BRRABill said in DC Demotion Question:

                                    Well, I DCPROMOed the one physical DC last night. Nothing seems to have burned down.

                                    I was having some DNS issues, but I think it was due to the fact that my machine was pointing to the demoted DC (which obviously had the DNS role installed) and it had been gutted by DCPROMO. I removed the role and everything seems OK thus far.

                                    Though very few users are here. I'll feel better by like 10AM.

                                    Did you update DHCP to no longer pass out the old DC as a DNS option?

                                    Did you go through all the static IP devices and remove the old DC DNS info from them?

                                    BRRABillB 1 Reply Last reply Reply Quote 0
                                    • BRRABillB
                                      BRRABill @JaredBusch
                                      last edited by

                                      @JaredBusch said in DC Demotion Question:

                                      @BRRABill said in DC Demotion Question:

                                      Well, I DCPROMOed the one physical DC last night. Nothing seems to have burned down.

                                      I was having some DNS issues, but I think it was due to the fact that my machine was pointing to the demoted DC (which obviously had the DNS role installed) and it had been gutted by DCPROMO. I removed the role and everything seems OK thus far.

                                      Though very few users are here. I'll feel better by like 10AM.

                                      Did you update DHCP to no longer pass out the old DC as a DNS option?

                                      Did you go through all the static IP devices and remove the old DC DNS info from them?

                                      Yes and hopefully. 🙂

                                      1 Reply Last reply Reply Quote 0
                                      • BRRABillB
                                        BRRABill
                                        last edited by

                                        Everything is still running fine.

                                        Next step will be to P2V this puppy and get it on XS.

                                        Then I'll be even happier!

                                        1 Reply Last reply Reply Quote 0
                                        • BRRABillB
                                          BRRABill
                                          last edited by

                                          Did you know...

                                          Apparently it's a PITA to transfer DHCP to an existing DC?

                                          (Countdown to someone saying "just install in on a Linux box" in 5...4...3...)

                                          coliverC wirestyle22W 2 Replies Last reply Reply Quote 0
                                          • coliverC
                                            coliver @BRRABill
                                            last edited by

                                            @BRRABill said in DC Demotion Question:

                                            Did you know...

                                            Apparently it's a PITA to transfer DHCP to an existing DC?

                                            (Countdown to someone saying "just install in on a Linux box" in 5...4...3...)

                                            It is? How so? You can easily backup the DHCP scopes and restore them to the new DC, decom the old one and turn up the new one. I've done it twice in the past without any issues.

                                            DashrenderD BRRABillB 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 2 / 6
                                            • First post
                                              Last post