Do I really need to "sign" my DNS zones before I can reload an AD integrated zone using DNSCMD
i'm tyring update ad-integrated dns dr procedures new 2008 dcs.
i see lot of hits on web seem necessitate "signing" dns zones after doing zone export performed following steps in lab (two 2008 dcs) without problem....what caveats...if of not signing?
i opened elevated command prompt , browsed %windir%\system32\dns , exported zone file:
dnscmd /zoneexport <zone name> <zone file name>
to restore, first deleted existing zone…
dnscmd /zonedelete <zone name> /dsdel /f
i added zone primary…
dnscmd /zoneadd <zone name> <zone type> /file <zone file name> /load
lastly changed zone type ds primary (ad integrated).
dnscmd /zoneresettype <zone name> /dsprimary
i went properties of restored zone , selected proper "dynamic updates" (i.e. nonsecure , secure) scavenging settings set default when zone recreated.
all seemed have worked well. can validate approach or point out risks.
thanks,
david w. king
techical architect - systems, information technology
(919) 784-3889 david.king@rexhealth.com
rex healthcare, 4420 lake boone trail, raleigh, nc 27607
auditing dns record entries (or deletions)
http://blogs.msdn.com/b/anthonw/archive/2006/08/23/715983.aspx
http://blogs.technet.com/b/yuridiogenes/archive/2008/03/06/auditing-a-dns-zone.aspx
how delegate basic server administration junior administrators http://support.microsoft.com/kb/555986
best practices delegating active directory administration http://www.microsoft.com/en-us/download/details.aspx?
hope helps
best regards,
sandesh dubey.
mcse|mcsa:messaging|mcts|mcitp:enterprise adminitrator | blog
disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights.
Windows Server > Directory Services
Comments
Post a Comment