Domain trust parameters meaning

Hi all,
can you help me understand what's the meaning of these parameters returned after querying a DC for trust relationships?
DOMAIN_NAME={domain.netbios.name=NETBIOS_NAME,
domain.flags=0x00000022, domain.trust.attributes=0x00000008, domain.dns.name=DNS_NAME,
domain.trust.type=2, objectGUID=0etc, objectSid=Setc}
Specifically I'm interested in these parameters:
domain.flags
domain.trust.attributes
domain.trust.type
What do they represent and what are the possible values?
Thanks in advance
Have a nice day

I believe the answer is: https://msdn.microsoft.com/en-us/library/cc237110.aspx
so in my case 
domain.flags -> I don't understand this
domain.trust.attributes -> Domain is root of another forest
domain.trust.type -> Trust is with a Windows Active Directory-based Domain
Is this correct?

Similar Messages

  • Domain Trust Relationships in Windows Small Business Server 2011

    I have seen that SBS 2011 (and older SBS versions, apparently) do not 'support' Domain Trust relationships.
    Before coming across this information, I have already successfully created a trust relationship between a newly created SBS 2011 domain and an existing 2008 Domain, and everything seems to be working fine - users from one domain are recognized on the other,
    etc.
    So I was wondering - is the 'not supported' more of a 'you're on your own if it breaks', is this a violation of the license, or is it some sort of freak occurrence and I am extremely lucky to have gotten this to work.  This is actually my first time
    setting up a trust relationship and the entire process took about 10 minutes, so it seemed extremely easy for something that I now find out is unsupported.
    If it is a license violation, I'll remove the trust relationship immediately.  This is not a permanent configuration, just testing our software on the SBS2011 platform and domain trusts were the most expedient way of adding the SBS Domain users to the
    list of authorized users on our primary domain's SQL Server.
    Thanks in advance.

    From here, it says that the trust relationship is not supported for SBS: http://technet.microsoft.com/en-us/library/cc672124%28v=ws.10%29.aspx
    This means that this have not been tested by Microsoft and if you will have issues, you will not get supported from Microsoft.
    I don't think that this is a violation of the license but it will be better to check with a Microsoft licensing expert in your country.
    More if you ask them here: http://social.technet.microsoft.com/Forums/en-US/category/sbsserver
    This
    posting is provided "AS IS" with no warranties or guarantees , and confers no rights.   
    Microsoft
    Student Partner 2010 / 2011
    Microsoft
    Certified Professional
    Microsoft
    Certified Systems Administrator: Security
    Microsoft
    Certified Systems Engineer: Security
    Microsoft
    Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
    Microsoft
    Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
    Microsoft
    Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
    Microsoft
    Certified Technology Specialist: Windows 7, Configuring
    Microsoft
    Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
    Microsoft
    Certified IT Professional: Enterprise Administrator
    Microsoft Certified IT Professional: Server Administrator
    Microsoft Certified Trainer

  • Domain Trust and DNS

    Hello,
    We have a 2-way domain trust between a Windows 2003 domain and a 2008 domain.  Nearly all works, we can share folder permissions etc but what we can't do on their domain is add a PC on their network that is part of our domain.
    The error is:
    it can't find the SRV record for _ldap._tcp.dc._msdcs.ukdomain.local.
    if they go to their DNS and look at the seconday forward lookup some for ukdomain.local it doesn't show a zone called _msdcs under ukdomain.local instead outside my zone we have a separete zone called _msdcs.gb.vo.local like this:
    DC1
    ----->Forward Lookup Zones
    -------->_Msdcs.ukdomain.local
    -------->ukdomain.local
    I though it should look like this:
    DC1
    ----->Forward Lookup Zones
    ------->ukdomain.local
    --------->_Msdcs
    Thanks

    If you are on their network can you ping their domain?
    If not then you have a DNS, routing, or firewall issue.
    Are ports being blocked?  For DNS, add a conditional forwarder to point to DNS for the other Domain and do the same on the other side, this will work better in 2008 as it's replicated to the forest.
    Testing
    Domain Controller Connectivity Using PORTQRY
    Protocol and Port
    AD and AD DS Usage
    Type of traffic
    TCP and UDP 389
    Directory, Replication, User and Computer Authentication, Group Policy, Trusts
    LDAP
    TCP 636
    Directory, Replication, User and Computer Authentication, Group Policy, Trusts
    LDAP SSL
    TCP 3268
    Directory, Replication, User and Computer Authentication, Group Policy, Trusts
    LDAP GC
    TCP 3269
    Directory, Replication, User and Computer Authentication, Group Policy, Trusts
    LDAP GC SSL
    TCP and UDP 88
    User and Computer Authentication, Forest Level Trusts
    Kerberos
    TCP and UDP 53
    User and Computer Authentication, Name Resolution, Trusts
    DNS
    TCP and UDP 445
    Replication, User and Computer Authentication, Group Policy, Trusts
    SMB,CIFS,SMB2, DFSN, LSARPC, NbtSS, NetLogonR, SamR, SrvSvc
    TCP 25
    Replication
    SMTP
    TCP 135
    Replication
    RPC, EPM
    TCP Dynamic
    Replication, User and Computer Authentication, Group Policy, Trusts
    RPC, DCOM, EPM, DRSUAPI, NetLogonR, SamR, FRS
    TCP 5722
    File Replication
    RPC, DFSR (SYSVOL)
    UDP 123
    Windows Time, Trusts
    Windows Time
    TCP and UDP 464
    Replication, User and Computer Authentication, Trusts
    Kerberos change/set password
    UDP Dynamic
    Group Policy
    DCOM, RPC, EPM
    UDP 138
    DFS, Group Policy
    DFSN, NetLogon, NetBIOS Datagram Service
    TCP 9389
    AD DS Web Services
    SOAP
    UDP 67 and UDP 2535
    DHCP
    Note
    DHCP is not a core AD DS service but it is often present in many AD DS deployments.
    DHCP, MADCAP
    UDP 137
    User and Computer Authentication,
    NetLogon, NetBIOS Name Resolution
    TCP 139
    User and Computer Authentication, Replication
    DFSN, NetBIOS Session Service, NetLogon
    If it answered your question, remember to “Mark as Answer”.
    If you found this post helpful, please “Vote as Helpful”.
    Postings are provided “AS IS” with no warranties, and confers no rights.
    Active Directory: Ultimate Reading Collection
    Active Directory Visio Stencils 2013 - Directory Services Visio Stencils
    Kelly Bush
    It appears that you've copied and posted the chart, with some editing,
    from my blog, link posted below. No problem, as long as it helps the poster. :-)
    Active Directory Firewall Ports – Let’s Try To Make This Simple
    http://blogs.msmvps.com/acefekay/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple/
    Also, I would like to add, that for firewall checks, to make sure the ephemeral ports are opened. These are the important random response ports. The ports are dependent on the operating system version.
    Here's the matrix:
    Ephemeral Ports:
    And most of all, the Ephemeral ports, or also known as the “service response ports,” that are required for communications. These ports are dynamically created for session responses for each client
    that establishes a session, (no matter what the ‘client’ may be), and not only to Windows, but to Linux and Unix as well. See below in the references section to find out more on what ‘ephemeral’ means.are used only for that session. Once the session has dissolved,
    the ports are put back into the pool for reuse. This applies not only to Windows, but to Linux and Unix as well. See below in the references section to find out more on what ‘ephemeral’ means.
    TCP & UDP 1025-5000
    Window 2003/XP and older
    Ephemeral Dynamic Service Response Ports
    TCP & UDP 49152-65535
    Windows 2008/Vista and newer
    Ephemeral Dynamic Service Response Ports
    TCP Dynamic Ephemeral
    Replication, User and Computer Authentication, Group Policy, Trusts
    RPC, DCOM, EPM, DRSUAPI, NetLogonR, SamR, FRS
    UDP Dynamic Ephermeral
    Group Policy
    DCOM, RPC, EPM
    If the scenario is a Mixed-Mode NT4 & Active Directory scenario with NT4 BDCs, then the following must be opened:
    TCP & UDP 1024 – 65535
    NT4 BDC to Windows 2000 or newer Domain controller PDC-E communications
    RPC, LSA RPC, LDAP, LDAP SSL, LDAP GC, LDAP GC SSL, DNS, Kerberos, SMB
    Ace Fekay
    MVP, MCT, MCSE 2012, MCITP EA & MCTS Windows 2008/R2, Exchange 2013, 2010 EA & 2007, MCSE & MCSA 2003/2000, MCSA Messaging 2003
    Microsoft Certified Trainer
    Microsoft MVP - Directory Services
    Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php
    This posting is provided AS-IS with no warranties or guarantees and confers no rights.

  • AD domain trust

    We have setup a One-Way domain trust between Domain A and Domain B. Users in Domain A can logo on to servers in Domain B. (B trust A). Relevant ports are open in the firewallbetween the domain controllers in A+B. It Works but are very slow. So I need to verify that my conclution is correct. What I think is going on, is that when a users from A is logging on to a server (let us call it B1)in B, thenB1 tries to contact a domain controller in A, using Kerberos. Since this is not allowed in the firewall, the server tries NTML as a fall back option, but here it is the B domain controllers that contact the A domain controllers and the user is authenticated. Because of the "Kerberos then NTML" problem, the logon is very slow. Now is my only option to open so that B1 can connect to domain controllers in Domain A? or is there another way to...
    This topic first appeared in the Spiceworks Community

    Sorry I don't follow your question? Can you expand on what you are after. When you say AD assessment for Domain Trust do you mean you need to validate and document an existing trust, or propose a solution for a new one? And what are you interested in with
    sites.
    Thanks
    Regards,
    Denis Cooper
    MCITP EA - MCT
    Help keep the forums tidy, if this has helped please mark it as an answer
    Blog: http://www.windows-support.co.uk 
    Twitter:   LinkedIn:

  • AD Domain Trust Assessment Examples/Documentation

    Hello
    Does one have a case study or example of documentation used to do a AD assessment for a Domain Trust? I would like to provide info regarding sites. 
    Thank you so much

    Sorry I don't follow your question? Can you expand on what you are after. When you say AD assessment for Domain Trust do you mean you need to validate and document an existing trust, or propose a solution for a new one? And what are you interested in with
    sites.
    Thanks
    Regards,
    Denis Cooper
    MCITP EA - MCT
    Help keep the forums tidy, if this has helped please mark it as an answer
    Blog: http://www.windows-support.co.uk 
    Twitter:   LinkedIn:

  • Setting up two way AD domain trust ?

    Hi,
    I'd like to know what are the steps that I need to take when setting up Active Directory domain trust between two  or more different AD domain? and also the steps to undo the domain trust in case I need to prevent some issues.
    Because I currently have about 15+ site offices that runs their own Active Directory domain to be joined with my current parent company AD domain.
    Thanks
    /* Server Support Specialist */

    Have you thought about using Azure Active Directory with users synchronization to consolidate all your office to one place?
    Answering directly: There are different types of trusts. Think about setting 1-way trust (users from first domain can get access to the resources in second domain but not the other way round) or 2-way trust (users in both domains get access to resources
    such as applications or sysytems in both domains). Please read https://technet.microsoft.com/en-us/library/cc730798.aspx
    Setting up the trust is rather easy task (https://technet.microsoft.com/en-us/library/cc771580.aspx) and can be undone easily as well (https://technet.microsoft.com/en-us/library/cc771137.aspx)
    Hope that helps!
    Did my post help you or make you laugh? Don't forget to click the Helpful vote :) If I answered your question please mark my post as an Answer.

  • Domain trust bet. win2003 and win2008R2 not working

    Hi, I try to create Domain trust but not trust. I think I am missing something about NDS, I have read sevel documents but describe diffrent case by case.
    I will Like a god step by step guide of NDS setup domain A trust domain B.
    Question: Before running trust wizard - should nslook see domain B from domain A doman controller?

    Hi,
    Below are some links to help you with this dending on the trust type you want to establish.
    http://araihan.wordpress.com/2009/08/05/how-to-create-an-external-trust-between-two-domains/
    DNS resolution for certain trust types:
    http://technet.microsoft.com/en-us/library/ee307976(WS.10).aspx
    http://technet.microsoft.com/en-us/library/cc756852(v=ws.10).aspx
    Hope this helps.
    Regards,
    Calin

  • Domain Trust over t3s

    I am able to propagate the weblogic security context from one domain to another over t3 but when I switch to an ssl connection (t3s) I no longer am able to propagate the original user. I do have the domain credential setup to allow for domain trust. Does anyone know if this is possible?
    For example, I have a web app in domain 1 calling a remote ejb in domain 2. When a user logs into the web app in domain 1 which then calls a remote ejb over t3 the security context of domain 1 is propagated into the ejb in domain 2. When I use a server certificate to connect b/w domain 1 and domain 2 over t3s I no longer receive the end user in domain 2. Does anyone know if this is possible?
    Thanks!

    Hi,
    >it can't find the SRV record for _ldap._tcp.dc._msdcs.ukdomain.local. 
    Would you please tell us what are the DNS Settings of the PC? Is there an AD Integrated DNS zone in the ukdomain?
    I suggest you check the SRV Records. You can try to restart the netlogon services to re-register SRV records. More specifically, in the command prompt, type
    net stop netlogon to stop netlogon services, then type net start netlogon to start netlogon services.
    >it However in DNS can see their _msdcs folder but they can't see ours.
    I suggest you select
    zone transfer to transfer DNS zone to their domain.
    More information about DNS zone transfer, please refer to the following link:
    Modify DNS zone transfer settings
    http://technet.microsoft.com/en-us/library/cc782181(v=WS.10).aspx
    Best Regards,
    Erin

  • Change domain trust for Forest trust

    Hi
    I have a forest A with 3 domains (1 (root),2,3) and i have a forest B with 2 domains (4 (root),5).
    Presently, i have a domain trust between domain 2 and 5.
    I need to change for a forest trust ? what is a best practice ?
    1- Remove domain trust and create a forest trust?
    2- Create a forest trust (waiting a few day) a remove a domain trust?
    3- Create a forest trust and remove immediately a domain trust?
    Do you have a link to explain that?
    Thanks

    Hi,
    Which kind of domain trust have you created? Which kind of forest trust do you want to create?
    A one-way forest trust allows all users in one forest to trust all domains in the other forest; a two-way forest trust forms a transitive trust relationship between
    every domain in both forests.
    Based on my understanding of forest trust, a forest trust is a transitive trust between a forest root domain and a second forest root domain. If you create a forest
    trust between two root domains in forest A and forest B, it provides a one-way or two-way, transitive trust relationship between every domain in each forest.
    In another word, all the domains in forest A and forest B would inherit the trust relationship from their root domains. Personally, you can just create a new forest trust and keep the existing domain trust.
    In addition, please make sure that the forest function level is Windows Server 2003 or higher before you create a forest trust.
    Best regards,
    Susie

  • What difference between a domain trust and a forest trust?

    What difference between a domain trust and a forest trust?

    Greetings!
    The answer is right on the question! :)
    I think it is best to distinguish properly between forest and domain. This article is a good one:
    What Are Domains and Forests?
    But in a nutshell, a forest trust is mostly used between two organizations, Suppose company A has a unique forest and company B has another unique forest as well, when they are merged they can simply create a forest trust between each other, This trust can
    be one-way or two-way depending on your needs.
    Domain trusts are between a single instance (domain) of a forest to another instance (domain) of another forest. It is worth mentioning that trust can be transitive as well.
    What Are Domain and Forest Trusts?
    I hope you got the answer.
    Regards.
    Mahdi Tehrani   |  
      |  
    www.mahditehrani.ir
    Please click on Propose As Answer or
    to mark this post as
    and helpful for other people.
    This posting is provided AS-IS with no warranties, and confers no rights.
    How to query members of 'Local Administrators' group in all computers?

  • Domain trust for external exchange domain

    Ok so I have inherited two domains, one domain runs activedirectory services that all of the workstations are joined to (domainA), thesecond domain hosts exchange (domainB).After signing in on a computer in domainA we have to authenticateoutlook with domainB to get email.The end result, I would like is to be able to authenticatewith domainA for email but have it load the profile as if it was domainB. I cancreate a one way trust from domainB to domainA but Im not sure how to foolexchange into believing DomainA\user1 is DomainB\user1. I've messed around withAuthenticate as permissions on domainB but that doesnt seemto work correctly. I don’t want to messwith full access permissions on exchange as that would cause issues.I havent had any problems getting the trust functioning correctly, just the windows/exchange user side of things.Does...
    This topic first appeared in the Spiceworks Community

    Hi,
    Which kind of domain trust have you created? Which kind of forest trust do you want to create?
    A one-way forest trust allows all users in one forest to trust all domains in the other forest; a two-way forest trust forms a transitive trust relationship between
    every domain in both forests.
    Based on my understanding of forest trust, a forest trust is a transitive trust between a forest root domain and a second forest root domain. If you create a forest
    trust between two root domains in forest A and forest B, it provides a one-way or two-way, transitive trust relationship between every domain in each forest.
    In another word, all the domains in forest A and forest B would inherit the trust relationship from their root domains. Personally, you can just create a new forest trust and keep the existing domain trust.
    In addition, please make sure that the forest function level is Windows Server 2003 or higher before you create a forest trust.
    Best regards,
    Susie

  • ACS Mapping Group @ Trust-Tree (Domain Trust)

    Dears,
    Could ACS mapping group @ AD Domain trust??
    I install abc.com / qqq.com and trust other!
    My ACS install in abc.com domain, but I cannot get qqq.com user information?
    ^ ^
    消息编辑者为:mr.marslin

    The Database Group Mapping feature in the External User Databases section enables you to associate unknown users with a CiscoSecure ACS group for assigning authorization profiles. For external user databases from which CiscoSecure ACS can derive group information, you can associate the group memberships defined for the users in the external user database to specific CiscoSecure ACS groups
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a0080205a4f.html#wp712817

  • Pros and cons in setting AD domain trust into my AD domain for more than 10+ AD domain and some with same FQDN or label ?

    Hi,
    Can someone please share what is the pros and Cons of trusting AD domain for more than 10 different AD sites into my existing single domain forest let say ParentCompany.com ?
    At the moment I only have one single forest AD domain with the Domain and Forest functionality Windows Server 2003. The main domain controller FSMO role holder is in the Data Center spread across three different VMs running on Windows Server 2008 R2.
    The main/parent company has acquired smaller business chain of 15+ offices in which they have their own Domain Controller and also their own domain, sometimes they also got the same AD domain between them (no trust or whatsoever in those 15+ AD domain).
    Sounds crazy but yes, there is no standardization in them or whoever manage their IT infrastructure previously.
    I'm now considering what are the benefits of creating the AD domain and trust versus importing those AD objects into my domain and then decommission them.
    No need to worry about Exchange Server since all of the user in those sites connecting to the RDS to my ParentCompany.com terminal servers.
    My requirements or goal are as follows:
    1. Simplify the AD domain structure & maintenance
    2. Try to avoid the disruptions of the user in terms of downtime and selecting multiple different domain everytime they login to their PC or SharePoint sites.
    any kind of help and suggestion would be greatly appreciated.
    Thanks.
    /* Server Support Specialist */

    Can someone please share what is the pros and Cons of trusting AD domain for more than 10 different
    AD sites into my existing single domain forest let say ParentCompany.com ?
    I think you mean 10 AD domains.
    Managing multiple domains can be difficult for administration. I usually recommend using a single domain in a single forest with OUs to separate resources whenever it is possible.
    However, if you can't do that then you can simply create trust relationships between your domains. The advantage is that you can enable access to resources to different domains. I do not see cons here.
    The main/parent company has acquired smaller business chain of 15+ offices in which they have
    their own Domain Controller and also their own domain, sometimes they also got the same AD domain between them (no trust or whatsoever in those 15+ AD domain). Sounds crazy but yes, there is no standardization in them or whoever manage their IT infrastructure
    previously.
    I'm now considering what are the benefits of creating the AD domain and trust versus importing those
    AD objects into my domain and then decommission them.
    I would recommend consolidating your domains into a single one. ADMT is a migration tool that you can use. The advantage would be the ease of administration. Also, by having multiple DCs for the same domain across sites, you will take benefit of High Availability
    of your and DRP.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Cross Domain Trust Error, while opening the infopath in sharepoint list.

    Dear All,
    Facing some issue in
    Environement:
    Windows = Windows Server 2008
    Shareppoint = Sharepoint Server 2013.
    Project Server = Project Server 2013
    Info Path = Info Path Designer 2013
    Detailed:
    I have sharepoint environment with Project Server,I which have created task list in my project site and then i customize that form using info path their is one column named: "Product Name" in my task list which is drop down menu in that menu
    i want to show all the project name which are created in PWA Site. For that i made the External data connection to my sql server and select my desired table from that and also configured the my column data "i:e; Product Name. And published it to the my
    site. Now when i opened that form it prompts the error
    "The form cannot be submitted because this action would violate cross-domain restrictions. 
    If this form template is published to a SharePoint document library, cross-domain access for user form templates must be enabled
    under InfoPath Forms Services in SharePoint Central Administration, and the data connection settings must be stored in a UDC file in a data connection library in the same site collection. 
    If this is an administrator-approved form template, the security level of the form must be set to full trust, or the data connection
    settings must be stored in a UDC file by using the Manage data connection files option under InfoPath Forms Services in SharePoint Central Administration ."
    Oopsss !!
    Now start googling it found couple of solution shared listed below:
    1. Enable the cross domain authenticated in Central Admin –> General Application Settings –> Configure InfoPath Form Services (Done)
    2. Now Created the data connection library in my site collection which is PWA Site after that i went to the infopath and creating the data connection and
    Convert to Connection File and enter the URL of the data connection library
    and its prompt the error " the specified url is not a data connection library and enter the correct filename" didnt remember the exact error description at the moment.
    So, that was all stuff, Kindly suggest me any step which i missed that or ay solution that resolve my this issue.
    Thanks
    REGARDS DANISH DANIE

    it seems the data-seed failed in your dehydration store.
    so i would check if user orabple exsits in your db (pw is orabpel) .. and recreate the schema by executing the following script (based on your db)
    orabpel\system\database\scripts\domain_oracle.ddl
    hth clemens

  • Exchange Autodiscover in a domain trust environment

    I am preparing an Exchange and AD migration / merge between two AD Domains and Exchange Org due to a recent merger / acquisition of another company. I am in the middle of an Exchange 2007 to Exchange 2013 migration whcih may complicate things:
    Let me give you some background:
    Domain A - "My Company" - Where all the mailboxes and AD accounts will eventually reside. We are mostly Exchange 2007 SP3 UR13, but we have Exchange 2013 SP1 set up, and are migrating accounts to 2013 as we speak. Domain is 2003 Native Mode.
    Domain B - "The other company" - Where all the "other" mailboxes and AD accounts currently are. They are Exchange 2010 SP3 UR5. Domain is 2003 Native Mode.
    I currently have a two-way transitive trust set up between Domain A and Domain B. The trust is working, users from either domain can log onto PC's on the other domain without issue. DNS resolution is fully functional between domains. Mapped drives happen,
    group policy runs, everything is good, except Outlook.
    However, when users from either domain try to log into Exchange from a PC on the opposite domain, they get an error which says "The connection to Microsoft Exchange is Unavailable. Outlook must be online or connected to complete this action". It
    appears autodiscover is not allowing connection to the other domain. I can resolve autodiscover.DomainA.com from a DomainB.com computer, and vice versa.
    So question is, do I have to do something  inside of Autodiscover for it to resolve or forward autodiscover requests from one domain to another? I would say I am fairly competent at Exchange, but this is something I am unfamiliar with.

    Ok, that worked fine. I had to deploy the root CERT for domain B through Group Policy and everything is working.
    Only one further question, not really related to above, but sort of. As I explained, "Domain B" is a company we acquired and have maintained for the past 6 months. Their Domain and Exchange was a mess, but we fixed pretty much all their issues. Some of the
    stuff, I have no idea how it was even working. When we first took them over, they were still on Exchange 2010 RTM with no Update rollups, their certificates had expired, an Exchange 2003 server was still in the mix, hosting public folders and acting as the
    outbound mail relay. An absolute mess. We brought them up to SP3 and the current update rollup, properly removed Exchange 2003, migrated public folders. Two of their 4 DC's were in Journal Wrap, probably for months. But everything is fully working and patched.
    One oddity that I have observed, but have been hesitant to mess with is a DNS issue. They have no autodiscover A record in DNS. What they have instead is what looks like a zone inside their primary forward zone. It's not a record, the icon looks like a folder
    with a piece of paper on it. A different color than the other zones, kind of a pale tan. Anyway inside this "autodiscover" zone is a single NS record (not an A record, an NS record), pointing to one of the DC's.
    What I had planned to do is just delete whatever this is, and create an A record pointing to the IP primary CAS Array's VIP IP. But thought I would ask before I did this.
    I have no idea some of the half baked stuff that went on in this environment before I took over... but what is weird is everything is working, at least from within their domain

Maybe you are looking for

  • AS 10g 904 Discoverer Viewer and remote db EUL

    I have installed Oracle AS 10g (9.0.4) with Discoverer Viewer on a RH AS3 box. I need an EUL setup on remote db (9.2.0.5). Do I have to have Discoverer Windows Admin tool or should I be able to setup an EUL from scratch with the java command line? I

  • Allow Software to Delete Channels, but Not User

    I am using the OnDeleteRequest action to prevent the user from deleting channels in my custom device.  However I realized that this also prevents code I write (in this case executing on a right-click action) from deleting channels.  I need a way to d

  • How to remove the autogenerated code in F M- 'MAT_MOVE_BMMH1_MARA'

    Hi, I added the custom fields in MARA to upload the LSMW.So i added the enhancement in LSMW program RMDATIND.It is working fine now.Then,i need to remove the code from that.where i could removed only the enhancement.(Note: when the enhancement is add

  • When sending a text it sends but then i receive the sent message as a reply

    when sending a text it sends but then i receive the sent message as a reply

  • Premiere Pro footage problem!

    Please help! For some reason my H.264 .mov footage flickers between being normal, and having long segments of pale, washed out video with massive black blotches and sharp squares. There is an example below. http://i1267.photobucket.com/albums/jj559/I