| Author | Messages | |
freemj1
Posts:14
 | | 04/30/2008 2:51 PM |
| I have been asked to explore certificate roaming for an EFS project we are considering. I know I could choose to apply only the schema extensions needed for that functionality but I would prefer to just load the W2K8 schema and be done with it. Does anyone know of any show stoppers for a global (75 dc's) W2K3 FFL scenario? I have been doing some reading about the upgrade re-acling current security principals that has me a little worried.
I have done my penance to the Google gods (don't hurt me Joe) but am looking for any real world experience or pitfalls.
Thanks much ...John Freeman Medtronic Inc
[CONFIDENTIALITY AND PRIVACY NOTICE]
Information transmitted by this email is proprietary to Medtronic and is intended for use only by the individual or entity to which it is addressed, and may contain information that is private, privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient or it appears that this mail has been forwarded to you without proper authority, you are notified that any use or dissemination of this information in any manner is strictly prohibited. In such cases, please delete this mail from your records.
To view this notice in other languages you can either select the following link or manually copy and paste the link into the address bar of a web browser: http://emaildisclaimer.medtronic.com
| | | |
| listmail
Posts:463
 | | 04/30/2008 3:17 PM |
| Nope no punishment deserved here... You will have trouble getting much real world experience, especially documented real world experience. 
The pat answer is go to your lab that matches prod and do it and see what happens for you....
Then once you do it in production, go write about it and post it publicly so the next person can find it in google. 
-- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm
_____
From: ActiveDir-owner@mail.activedir.org [mailto:ActiveDir-owner@mail.activedir.org] On Behalf Of Freeman, John Sent: Wednesday, April 30, 2008 2:50 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Windows Server 2008 Schema updates
I have been asked to explore certificate roaming for an EFS project we are considering. I know I could choose to apply only the schema extensions needed for that functionality but I would prefer to just load the W2K8 schema and be done with it. Does anyone know of any show stoppers for a global (75 dc's) W2K3 FFL scenario? I have been doing some reading about the upgrade re-acling current security principals that has me a little worried.
I have done my penance to the Google gods (don't hurt me Joe) but am looking for any real world experience or pitfalls.
Thanks much .John Freeman Medtronic Inc
[CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted by this email is proprietary to Medtronic and is intended for use only by the individual or entity to which it is addressed, and may contain information that is private, privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient or it appears that this mail has been forwarded to you without proper authority, you are notified that any use or dissemination of this information in any manner is strictly prohibited. In such cases, please delete this mail from your records. To view this notice in other languages you can either select the following link or manually copy and paste the link into the address bar of a web browser: http://emaildisclaimer.medtronic.com
| | | |
| hallerec
Posts:6
 | | 04/30/2008 6:13 PM |
| We use credential roaming for EFS certificates but we don't have anything documented that Google can see.
We are at 2003 functional but we didn't extend our schema for 2008 yet. Is the certificate roaming different from the credential roaming?
Ernie
On Wed, Apr 30, 2008 at 3:14 PM, joe <listmail@joeware.net> wrote:
> Nope no punishment deserved here... You will have trouble getting much > real world experience, especially documented real world experience.  > > The pat answer is go to your lab that matches prod and do it and see what > happens for you.... > > Then once you do it in production, go write about it and post it publicly > so the next person can find it in google.  > > > > -- > O'Reilly Active Directory Third Edition - > http://www.joeware.net/win/ad3e.htm > > > > ------------------------------ > *From:* ActiveDir-owner@mail.activedir.org [mailto: > ActiveDir-owner@mail.activedir.org] *On Behalf Of *Freeman, John > *Sent:* Wednesday, April 30, 2008 2:50 PM > *To:* ActiveDir@mail.activedir.org > *Subject:* [ActiveDir] Windows Server 2008 Schema updates > > I have been asked to explore certificate roaming for an EFS project we > are considering. I know I could choose to apply only the schema extensions > needed for that functionality but I would prefer to just load the W2K8 > schema and be done with it. Does anyone know of any show stoppers for a > global (75 dc's) W2K3 FFL scenario? I have been doing some reading about the > upgrade re-acling current security principals that has me a little worried. > > I have done my penance to the Google gods (don't hurt me Joe) but am > looking for any real world experience or pitfalls. > > Thanks much > …John Freeman > Medtronic Inc > > > [CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted by this email > is proprietary to Medtronic and is intended for use only by the individual > or entity to which it is addressed, and may contain information that is > private, privileged, confidential or exempt from disclosure under applicable > law. If you are not the intended recipient or it appears that this mail has > been forwarded to you without proper authority, you are notified that any > use or dissemination of this information in any manner is strictly > prohibited. In such cases, please delete this mail from your records. To > view this notice in other languages you can either select the following link > or manually copy and paste the link into the address bar of a web browser: > http://emaildisclaimer.medtronic.com >
| | | |
| tech4steve
Posts:10
 | | 05/01/2008 1:01 AM |
| Anyone who uses cred roaming ( cert roaming AKA DIMS ) should deploy this fix to the DC's
http://support.microsoft.com/?id=934797
SYMPTOMS After you enable the Credential Roaming feature for Windows Vista-based client computers in a domain, the size of the Ntds.dit file on the domain controller grows continually larger. Additionally, when Active Directory database changes are replicated to other domain controllers in the domain, the size of the Ntds.dit files on the other domain controllers also grows larger. Therefore, this growth eventually occurs on all domain controllers in the domain.
spat ----- Original Message ----- From: Ernie Haller To: ActiveDir@mail.activedir.org Sent: Wednesday, April 30, 2008 3:10 PM Subject: Re: [ActiveDir] Windows Server 2008 Schema updates
We use credential roaming for EFS certificates but we don't have anything documented that Google can see.
We are at 2003 functional but we didn't extend our schema for 2008 yet. Is the certificate roaming different from the credential roaming?
Ernie
On Wed, Apr 30, 2008 at 3:14 PM, joe <listmail@joeware.net> wrote:
Nope no punishment deserved here... You will have trouble getting much real world experience, especially documented real world experience. 
The pat answer is go to your lab that matches prod and do it and see what happens for you....
Then once you do it in production, go write about it and post it publicly so the next person can find it in google. 
-- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm
---------------------------------------------------------------------------- From: ActiveDir-owner@mail.activedir.org [mailto:ActiveDir-owner@mail.activedir.org] On Behalf Of Freeman, John Sent: Wednesday, April 30, 2008 2:50 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Windows Server 2008 Schema updates
I have been asked to explore certificate roaming for an EFS project we are considering. I know I could choose to apply only the schema extensions needed for that functionality but I would prefer to just load the W2K8 schema and be done with it. Does anyone know of any show stoppers for a global (75 dc's) W2K3 FFL scenario? I have been doing some reading about the upgrade re-acling current security principals that has me a little worried.
I have done my penance to the Google gods (don't hurt me Joe) but am looking for any real world experience or pitfalls.
Thanks much …John Freeman Medtronic Inc
[CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted by this email is proprietary to Medtronic and is intended for use only by the individual or entity to which it is addressed, and may contain information that is private, privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient or it appears that this mail has been forwarded to you without proper authority, you are notified that any use or dissemination of this information in any manner is strictly prohibited. In such cases, please delete this mail from your records. To view this notice in other languages you can either select the following link or manually copy and paste the link into the address bar of a web browser: http://emaildisclaimer.medtronic.com
| | | |
| FreddyHARTONO
Posts:19
 | | 05/02/2008 2:51 AM |
| Aiks, to the clients side is the nightmare for my environment.. I was kinda hoping it's a DC side fix L
From: ActiveDir-owner@mail.activedir.org [mailto:ActiveDir-owner@mail.activedir.org] On Behalf Of steve patrick Sent: Thursday, May 01, 2008 12:59 PM To: steve patrick; ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] Windows Server 2008 Schema updates
Sorry I meant to the clients..
----- Original Message -----
From: steve patrick <mailto:tech4steve@comcast.net>
To: ActiveDir@mail.activedir.org
Sent: Wednesday, April 30, 2008 9:58 PM
Subject: Re: [ActiveDir] Windows Server 2008 Schema updates
Anyone who uses cred roaming ( cert roaming AKA DIMS ) should deploy this fix to the DC's
http://support.microsoft.com/?id=934797
SYMPTOMS After you enable the Credential Roaming feature for Windows Vista-based client computers in a domain, the size of the Ntds.dit file on the domain controller grows continually larger. Additionally, when Active Directory database changes are replicated to other domain controllers in the domain, the size of the Ntds.dit files on the other domain controllers also grows larger. Therefore, this growth eventually occurs on all domain controllers in the domain.
spat
----- Original Message -----
From: Ernie Haller <mailto:ernie.haller@gmail.com>
To: ActiveDir@mail.activedir.org
Sent: Wednesday, April 30, 2008 3:10 PM
Subject: Re: [ActiveDir] Windows Server 2008 Schema updates
We use credential roaming for EFS certificates but we don't have anything documented that Google can see.
We are at 2003 functional but we didn't extend our schema for 2008 yet. Is the certificate roaming different from the credential roaming?
Ernie
On Wed, Apr 30, 2008 at 3:14 PM, joe <listmail@joeware.net> wrote:
Nope no punishment deserved here... You will have trouble getting much real world experience, especially documented real world experience. 
The pat answer is go to your lab that matches prod and do it and see what happens for you....
Then once you do it in production, go write about it and post it publicly so the next person can find it in google. 
--
O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm
________________________________
From: ActiveDir-owner@mail.activedir.org [mailto:ActiveDir-owner@mail.activedir.org] On Behalf Of Freeman, John Sent: Wednesday, April 30, 2008 2:50 PM To: ActiveDir@mail.activedir.org Subject: [ActiveDir] Windows Server 2008 Schema updates
I have been asked to explore certificate roaming for an EFS project we are considering. I know I could choose to apply only the schema extensions needed for that functionality but I would prefer to just load the W2K8 schema and be done with it. Does anyone know of any show stoppers for a global (75 dc's) W2K3 FFL scenario? I have been doing some reading about the upgrade re-acling current security principals that has me a little worried.
I have done my penance to the Google gods (don't hurt me Joe) but am looking for any real world experience or pitfalls.
Thanks much
...John Freeman
Medtronic Inc
[CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted by this email is proprietary to Medtronic and is intended for use only by the individual or entity to which it is addressed, and may contain information that is private, privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient or it appears that this mail has been forwarded to you without proper authority, you are notified that any use or dissemination of this information in any manner is strictly prohibited. In such cases, please delete this mail from your records. To view this notice in other languages you can either select the following link or manually copy and paste the link into the address bar of a web browser: http://emaildisclaimer.medtronic.com
| | | |
| sbradcpa
Posts:320
 | | 05/02/2008 3:06 AM |
| Is this in Vista sp1? approvable by WSUS?
Freddy HARTONO wrote: > > Aiks, to the clients side is the nightmare for my environment.. I was > kinda hoping it’s a DC side fix L > > *From:* ActiveDir-owner@mail.activedir.org > [mailto:ActiveDir-owner@mail.activedir.org] *On Behalf Of *steve patrick > *Sent:* Thursday, May 01, 2008 12:59 PM > *To:* steve patrick; ActiveDir@mail.activedir.org > *Subject:* Re: [ActiveDir] Windows Server 2008 Schema updates > > Sorry I meant to the clients.. > > ----- Original Message ----- > > *From:* steve patrick <mailto:tech4steve@comcast.net> > > *To:* ActiveDir@mail.activedir.org > <mailto:ActiveDir@mail.activedir.org> > > *Sent:* Wednesday, April 30, 2008 9:58 PM > > *Subject:* Re: [ActiveDir] Windows Server 2008 Schema updates > > Anyone who uses cred roaming ( cert roaming AKA DIMS ) should > deploy this fix to the DC's > > http://support.microsoft.com/?id=934797 > > SYMPTOMS > After you enable the Credential Roaming feature for Windows > Vista-based client computers in a domain, the size of the Ntds.dit > file on the domain controller grows continually larger. > Additionally, when Active Directory database changes are > replicated to other domain controllers in the domain, the size of > the Ntds.dit files on the other domain controllers also grows > larger. Therefore, this growth eventually occurs on all domain > controllers in the domain. > > spat > > ----- Original Message ----- > > *From:* Ernie Haller <mailto:ernie.haller@gmail.com> > > *To:* ActiveDir@mail.activedir.org > <mailto:ActiveDir@mail.activedir.org> > > *Sent:* Wednesday, April 30, 2008 3:10 PM > > *Subject:* Re: [ActiveDir] Windows Server 2008 Schema updates > > We use credential roaming for EFS certificates but we don't > have anything documented that Google can see. > > We are at 2003 functional but we didn't extend our schema for > 2008 yet. Is the certificate roaming different from the > credential roaming? > > Ernie > > On Wed, Apr 30, 2008 at 3:14 PM, joe <listmail@joeware.net > <mailto:listmail@joeware.net>> wrote: > > Nope no punishment deserved here... You will have trouble > getting much real world experience, especially documented real > world experience.  > > The pat answer is go to your lab that matches prod and do it > and see what happens for you.... > > Then once you do it in production, go write about it and post > it publicly so the next person can find it in google.  > > -- > > O'Reilly Active Directory Third Edition - > http://www.joeware.net/win/ad3e.htm > > ------------------------------------------------------------------------ > > *From:* ActiveDir-owner@mail.activedir.org > <mailto:ActiveDir-owner@mail.activedir.org> > [mailto:ActiveDir-owner@mail.activedir.org > <mailto:ActiveDir-owner@mail.activedir.org>] *On Behalf Of > *Freeman, John > *Sent:* Wednesday, April 30, 2008 2:50 PM > *To:* ActiveDir@mail.activedir.org > <mailto:ActiveDir@mail.activedir.org> > *Subject:* [ActiveDir] Windows Server 2008 Schema updates > > I have been asked to explore certificate roaming for an EFS > project we are considering. I know I could choose to apply > only the schema extensions needed for that functionality but I > would prefer to just load the W2K8 schema and be done with it. > Does anyone know of any show stoppers for a global (75 dc's) > W2K3 FFL scenario? I have been doing some reading about the > upgrade re-acling current security principals that has me a > little worried. > > I have done my penance to the Google gods (don't hurt me Joe) > but am looking for any real world experience or pitfalls. > > Thanks much > > …John Freeman > > Medtronic Inc > > [CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted > by this email is proprietary to Medtronic and is intended for > use only by the individual or entity to which it is addressed, > and may contain information that is private, privileged, > confidential or exempt from disclosure under applicable law. > If you are not the intended recipient or it appears that this > mail has been forwarded to you without proper authority, you > are notified that any use or dissemination of this information > in any manner is strictly prohibited. In such cases, please > delete this mail from your records. To view this notice in > other languages you can either select the following link or > manually copy and paste the link into the address bar of a web > browser: http://emaildisclaimer.medtronic.com > List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.activedir.org/ma/default.aspx
| | | |
| sbradcpa
Posts:320
 | | 05/04/2008 12:02 AM |
| http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=727
Steve Riley on Schema update for Bitlocker
"in the history of windows there's never been a case of a Schema update damaging a forest"
1:02:50
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] wrote: > Is this in Vista sp1? approvable by WSUS? > > Freddy HARTONO wrote: >> >> Aiks, to the clients side is the nightmare for my environment.. I was >> kinda hoping it’s a DC side fix L >> >> *From:* ActiveDir-owner@mail.activedir.org >> [mailto:ActiveDir-owner@mail.activedir.org] *On Behalf Of *steve patrick >> *Sent:* Thursday, May 01, 2008 12:59 PM >> *To:* steve patrick; ActiveDir@mail.activedir.org >> *Subject:* Re: [ActiveDir] Windows Server 2008 Schema updates >> >> Sorry I meant to the clients.. >> >> ----- Original Message ----- >> >> *From:* steve patrick <mailto:tech4steve@comcast.net> >> >> *To:* ActiveDir@mail.activedir.org >> <mailto:ActiveDir@mail.activedir.org> >> >> *Sent:* Wednesday, April 30, 2008 9:58 PM >> >> *Subject:* Re: [ActiveDir] Windows Server 2008 Schema updates >> >> Anyone who uses cred roaming ( cert roaming AKA DIMS ) should >> deploy this fix to the DC's >> >> http://support.microsoft.com/?id=934797 >> >> SYMPTOMS >> After you enable the Credential Roaming feature for Windows >> Vista-based client computers in a domain, the size of the Ntds.dit >> file on the domain controller grows continually larger. >> Additionally, when Active Directory database changes are >> replicated to other domain controllers in the domain, the size of >> the Ntds.dit files on the other domain controllers also grows >> larger. Therefore, this growth eventually occurs on all domain >> controllers in the domain. >> >> spat >> >> ----- Original Message ----- >> >> *From:* Ernie Haller <mailto:ernie.haller@gmail.com> >> >> *To:* ActiveDir@mail.activedir.org >> <mailto:ActiveDir@mail.activedir.org> >> >> *Sent:* Wednesday, April 30, 2008 3:10 PM >> >> *Subject:* Re: [ActiveDir] Windows Server 2008 Schema updates >> >> We use credential roaming for EFS certificates but we don't >> have anything documented that Google can see. >> >> We are at 2003 functional but we didn't extend our schema for >> 2008 yet. Is the certificate roaming different from the >> credential roaming? >> >> Ernie >> >> On Wed, Apr 30, 2008 at 3:14 PM, joe <listmail@joeware.net >> <mailto:listmail@joeware.net>> wrote: >> >> Nope no punishment deserved here... You will have trouble >> getting much real world experience, especially documented real >> world experience.  >> >> The pat answer is go to your lab that matches prod and do it >> and see what happens for you.... >> >> Then once you do it in production, go write about it and post >> it publicly so the next person can find it in google.  >> >> -- >> >> O'Reilly Active Directory Third Edition - >> http://www.joeware.net/win/ad3e.htm >> >> >> ------------------------------------------------------------------------ >> >> *From:* ActiveDir-owner@mail.activedir.org >> <mailto:ActiveDir-owner@mail.activedir.org> >> [mailto:ActiveDir-owner@mail.activedir.org >> <mailto:ActiveDir-owner@mail.activedir.org>] *On Behalf Of >> *Freeman, John >> *Sent:* Wednesday, April 30, 2008 2:50 PM >> *To:* ActiveDir@mail.activedir.org >> <mailto:ActiveDir@mail.activedir.org> >> *Subject:* [ActiveDir] Windows Server 2008 Schema updates >> >> I have been asked to explore certificate roaming for an EFS >> project we are considering. I know I could choose to apply >> only the schema extensions needed for that functionality but I >> would prefer to just load the W2K8 schema and be done with it. >> Does anyone know of any show stoppers for a global (75 dc's) >> W2K3 FFL scenario? I have been doing some reading about the >> upgrade re-acling current security principals that has me a >> little worried. >> >> I have done my penance to the Google gods (don't hurt me Joe) >> but am looking for any real world experience or pitfalls. >> >> Thanks much >> >> …John Freeman >> >> Medtronic Inc >> >> [CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted >> by this email is proprietary to Medtronic and is intended for >> use only by the individual or entity to which it is addressed, >> and may contain information that is private, privileged, >> confidential or exempt from disclosure under applicable law. >> If you are not the intended recipient or it appears that this >> mail has been forwarded to you without proper authority, you >> are notified that any use or dissemination of this information >> in any manner is strictly prohibited. In such cases, please >> delete this mail from your records. To view this notice in >> other languages you can either select the following link or >> manually copy and paste the link into the address bar of a web >> browser: http://emaildisclaimer.medtronic.com >> > List info : http://www.activedir.org/List.aspx > List FAQ : http://www.activedir.org/ListFAQ.aspx > List archive: http://www.activedir.org/ma/default.aspx > List info : http://www.activedir.org/List.aspx List FAQ : http://www.activedir.org/ListFAQ.aspx List archive: http://www.activedir.org/ma/default.aspx
| | | |
| GuidoG
Posts:59
 | | 05/05/2008 6:11 AM |
| Your security principals aren't re-acl'd when applying the 2008 Schema - it's pretty much the same process as upgrading the schema from W2K to W2k3 => ADPREP will add some permissions to SYSVOL causing it to replicate out the contents of SYSVOL. To give you some more control as to when you want the SYSVOL replication to occur, you can add these ACLs separately from upgrading your domain, as it's not required to add your first 2008 DC (i.e. ADPREP /DomainPrep won't add ACLs to SYSVOL, but ADPREP /DomainPrep /GpPrep will)
And if the schema change is all you want for now, you can stop after running ADPREP /ForestPrep anyways.
We have the 2008 schema in production at HP for quite a while now and it has caused no problems during the upgrade. We still have a few 2003 DCs left over, but most are running 2008 by now. As such I don't expect any issues for your pure 2003 environment by adding the 2008 schema. This will also add the BitLocker stuff<http://technet2.microsoft.com/WindowsVista/en/library/3dbad515-5a32-4330-ad6f-d1fb6dfcdd411033.mspx?mfr=true> that you might want to have a look at as well, while you're already tackling file-system security.
Nonetheless, follow the golden rule: first add the extensions in your test-lab, before doing so in production... And even then, do so with an isolated schema master (+ another DC in the same isolated network) so you can ensure that the schema is updated and replicates successfully before you let the change replicate out to the rest of your DCs.
/Guido
________________________________ From: ActiveDir-owner@mail.activedir.org<mailto:ActiveDir-owner@mail.activedir.org> [mailto:ActiveDir-owner@mail.activedir.org<mailto:ActiveDir-owner@mail.activedir.org>] On Behalf Of Freeman, John Sent: Wednesday, April 30, 2008 2:50 PM To: ActiveDir@mail.activedir.org<mailto:ActiveDir@mail.activedir.org> Subject: [ActiveDir] Windows Server 2008 Schema updates I have been asked to explore certificate roaming for an EFS project we are considering. I know I could choose to apply only the schema extensions needed for that functionality but I would prefer to just load the W2K8 schema and be done with it. Does anyone know of any show stoppers for a global (75 dc's) W2K3 FFL scenario? I have been doing some reading about the upgrade re-acling current security principals that has me a little worried.
I have done my penance to the Google gods (don't hurt me Joe) but am looking for any real world experience or pitfalls.
Thanks much ...John Freeman Medtronic Inc
[CONFIDENTIALITY AND PRIVACY NOTICE] Information transmitted by this email is proprietary to Medtronic and is intended for use only by the individual or entity to which it is addressed, and may contain information that is private, privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient or it appears that this mail has been forwarded to you without proper authority, you are notified that any use or dissemination of this information in any manner is strictly prohibited. In such cases, please delete this mail from your records. To view this notice in other languages you can either select the following link or manually copy and paste the link into the address bar of a web browser: http://emaildisclaimer.medtronic.com
| | | |
|
|