[858] in winnt

home help back first fref pref prev next nref lref last post

RE: new server

daemon@ATHENA.MIT.EDU (Carrie Groves)
Fri Jun 14 09:09:19 2002

Message-Id: <5.0.2.1.2.20020614090631.00b13880@hesiod>
Date: Fri, 14 Jun 2002 09:09:20 -0400
To: Kerem B Limon <kerem.limon@mit.edu>, "Bryant C. Vernon" <bcvernon@mit.edu>
From: Carrie Groves <cgroves@MIT.EDU>
Cc: Windows Partners at MIT <winpartners@mit.edu>
In-Reply-To: <p05111b00b92ee4b7950d@[18.152.2.36]>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed

Kerem,

Thank you very much for all of this information. Looks like I have a lot of 
reading in my future.

Carrie

At 08:47 PM 6/13/02 -0400, Kerem B Limon wrote:
>Carrie,
>
>You can do this without buying 3rd party software, but there are some 
>caveats you need to consider.
>
>First of all, in order to simplify the transfer, I'd recommend installing 
>Windows NT 4 Server on your new machine, being careful to bring it up as a 
>BDC in your existing domain. This way, you will get it to sync its SID 
>with the PDC and replicate the SAM database. Then, install drivers, 
>updates, server apps you need on the new BDC.
>
>Next, promote the new machine to PDC, which will automatically demote your 
>old BDC. Don't remove the BDC from the network or the PDC SAM yet. What's 
>left is to rename your NT 4 domain to the new name you like, and then 
>remove the BDC.
>
>For this, I recommend Sean Daily's (of--what is now--Windows/.NET mag 
>fame) February 1999 article, "How to Rename Your NT Domain", also on-line at
>
>http://www.winntmag.com/Articles/Index.cfm?ArticleID=4784
>
>Sean has detailed the steps very carefully. When you skim the article, you 
>will notice the primary concern are trust relationships, server apps, and 
>services who are closely tied to the existing domain name; while I am not 
>familiar with your setup, one MIT supported such app is the NetShield 
>anti-virus software (and associated service) for NT 4 servers. You 
>probably have this, and should carefully follow Sean's instructions in 
>correctly migrating it. He also mentions others like Exchange, SQL Server, 
>IIS, SMS, etc.
>
>Finally, you _will_ need to rejoin the workstations to the new domain. 
>Typically this involves repeating the process on every machine, but 
>planning ahead (before changing the domain name), you could create a 
>_local_ logon script for each of the workstations that would join them to 
>the new domain to execute at login (albeit with cached credentials at that 
>time since your old domain will be gone, hence _local_ script). For 
>details, see the John Savill's Windows2000FAQ article at
>
>http://www.windows2000faq.com/Articles/Index.cfm?ArticleID=13524
>
>Note he describes how you can pre-configure the machine accounts such that 
>normal users can join the domain without admin rights. They will, of 
>course, need to reboot, which could also be scripted. With a little 
>tweaking, you can use Mark Russinovich and Bryce Cogswell's Sysinternals 
>utility PsShutdown. See
>
>http://www.sysinternals.com/ntw2k/freeware/pstools.shtml
>http://www.sysinternals.com/ntw2k/freeware/psshutdown.shtml
>
>For other legacy (Windows 9x, Me) workstations, you might have to rejoin 
>manually.
>
>This should be able to get you going where you want. Since Sean's 
>instructions involve shutting down a lot of domain services, I recommend 
>doing this over a weekend or at least overnight to minimize impact on 
>users; and order pizza should something go wrong :)
>
>Regards,
>Kerem
>
>PS: In case you need it, the Sysinternals utility NewSID has the ability 
>to replicate/generate SIDs
>
>http://www.sysinternals.com/ntw2k/source/newsid.shtml
>
>But since you pre-join the new machine to your existing domain, the SIDs 
>for the DCs are sync'd and you shouldn't need it.
>
>Kerem B. Limon
>Consultant, Support Process
>MIT Information Systems
>Computing Help Desk / Software Release Team / Wireless Deployment Team
>
>
>At 14:44 hrs -0400 02/06/13, Bryant C. Vernon wrote:
>>Hi Carrie,
>>
>>You want the bad or the bad news?
>>
>>Unfortunately, all the domain computer IDs and user IDs contain the
>>domain ID as well, so you would not be able to transfer them easily
>>(i.e. without some serious hacking or tool)to a new domain. From my
>>brief research into the problem, I have found a tool that would enable
>>you to do the user transfers (including passwords) for a fairly good
>>price, considering how many man hours it would take to redo everything
>>manually. The tool is called Ideal Migration, and you can read more
>>about it at the following URL: http://www.pointdev.com/IM_descr_us.htm.
>>
>>I am sure there are other tools available, and you may want to look into
>>them for comparative shopping purposes.
>>
>>All the Best,
>>-Bryant
>>
>>
>>-----Original Message-----
>>From: Carrie Groves [mailto:cgroves@MIT.EDU]
>>Sent: Thursday, June 13, 2002 2:11 PM
>>To: ntpartners@mit.edu
>>Subject: new server
>>
>>Hi,
>>
>>I need to replace an NT domain controller with a newer model machine. I
>>plan on changing domain names but all the computers and users who
>>connect
>>to it will be the same. Does anyone know of an easy way to transfer the
>>computer and user IDs to the new domain controller? Or do I have to
>>recreate them all?
>>
>>Thank you,
>>
>>Carrie Groves
>>Network Administrator, SSIT
>>Massachusetts Institute of Technology
>>77 Massachusetts Ave 12-172
>>Cambridge, Ma 02139
>>(617)258-0714
>><mailto:cgroves@mit.edu>

Thanks,
Carrie
8-0714

"Why is the alphabet in that order? Is it because of that song?"
Steven Wright


home help back first fref pref prev next nref lref last post