Werbung: SecurityConsole.de verwaltet Ihre Computer mit Security Essentails aus der Cloud!
30 Tage kostenfrei testen und 20% Rabatt für Ihre Bestellung mit Promocode: WBF2685582
(Promocode gültig bis 31.12.2011)

Group:  English: Windows Server » microsoft.public.windows.server.dns
Thread: AD Integrated DNS

HTVi
TV Discussion Newsgroups

AD Integrated DNS
Bob Smith 10/20/2008 8:29:02 PM
We recently converted from BIND to AD-Integrated zones. The problem is, the
machine accounts don't have rights to update their own records. We would like
to turn on scavenging, but need to make sure that our servers are registering
in DNS successfully.

One option would be to add the Domain\Machine$ account to the resource
record for both forward and reverse entries. This would give access to update
the record dynamically. I would prefer to do this rather than delete the
record in the hope the machine updates it (safer method). Is there a way to
use DNSCMD to update a resource records ACL? Is there a better way to
approach this?

Thanks in advance.
Re: AD Integrated DNS
Meinolf Weber <meiweb(nospam)[ at ]gmx.de> 10/21/2008 6:37:46 AM
Hello Bob,

Do you use DHCP?
http://technet.microsoft.com/en-us/library/cc787034.aspx

How are your zones configured for dynamic updating?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


[Quoted Text]
> We recently converted from BIND to AD-Integrated zones. The problem
> is, the machine accounts don't have rights to update their own
> records. We would like to turn on scavenging, but need to make sure
> that our servers are registering in DNS successfully.
>
> One option would be to add the Domain\Machine$ account to the resource
> record for both forward and reverse entries. This would give access to
> update the record dynamically. I would prefer to do this rather than
> delete the record in the hope the machine updates it (safer method).
> Is there a way to use DNSCMD to update a resource records ACL? Is
> there a better way to approach this?
>
> Thanks in advance.
>

Re: AD Integrated DNS
Bob Smith 10/21/2008 1:52:01 PM
We use static addresses for all our servers (1000's of machines). I am only
concerned about this for our servers. They are set to update dynamically in
the TCP properties.

"Meinolf Weber" wrote:

[Quoted Text]
> Hello Bob,
>
> Do you use DHCP?
> http://technet.microsoft.com/en-us/library/cc787034.aspx
>
> How are your zones configured for dynamic updating?
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>
> > We recently converted from BIND to AD-Integrated zones. The problem
> > is, the machine accounts don't have rights to update their own
> > records. We would like to turn on scavenging, but need to make sure
> > that our servers are registering in DNS successfully.
> >
> > One option would be to add the Domain\Machine$ account to the resource
> > record for both forward and reverse entries. This would give access to
> > update the record dynamically. I would prefer to do this rather than
> > delete the record in the hope the machine updates it (safer method).
> > Is there a way to use DNSCMD to update a resource records ACL? Is
> > there a better way to approach this?
> >
> > Thanks in advance.
> >
>
>
>

Home | Search | Terms | Imprint Contact
Newsgroups Reader - provided by WiredBox.Net
Suche nach Orten, Städten, Postleitzahlen, Vorwahlen, Kfz-Kennzeichen