Do I really need to "sign" my DNS zones before I can reload an AD integrated zone using DNSCMD


i'm tyring update ad-integrated dns dr procedures new 2008 dcs.

i see lot of hits on web seem necessitate "signing" dns zones after doing zone export performed following steps in lab (two 2008 dcs) without problem....what caveats...if of not signing?

i opened elevated command prompt , browsed %windir%\system32\dns , exported zone file:
dnscmd /zoneexport <zone name> <zone file name>

to restore, first deleted existing zone…
dnscmd /zonedelete <zone name> /dsdel /f

i added zone primary…
dnscmd /zoneadd <zone name> <zone type> /file <zone file name> /load

lastly changed zone type ds primary (ad integrated).
dnscmd /zoneresettype <zone name> /dsprimary

i went properties of restored zone , selected proper "dynamic updates" (i.e. nonsecure , secure) scavenging settings set default when zone recreated.

all seemed have worked well.  can validate approach or point out risks.

thanks,

david w. king
techical architect - systems, information technology
(919) 784-3889 david.king@rexhealth.com
rex healthcare, 4420 lake boone trail, raleigh, nc 27607

you on right track should enable auditing track same.however if have multiple domain admin remove permission , delegate control non domain admins manage ad.also step restore dns zone correct.

auditing dns record entries (or deletions)
http://blogs.msdn.com/b/anthonw/archive/2006/08/23/715983.aspx
http://blogs.technet.com/b/yuridiogenes/archive/2008/03/06/auditing-a-dns-zone.aspx


how delegate basic server administration junior administrators  http://support.microsoft.com/kb/555986

best practices delegating active directory administration  http://www.microsoft.com/en-us/download/details.aspx?


hope helps


best regards,

sandesh dubey.

mcse|mcsa:messaging|mcts|mcitp:enterprise adminitrator | blog

disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.




Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2