{"id":1879,"date":"2011-07-04T20:45:37","date_gmt":"2011-07-04T19:45:37","guid":{"rendered":"http:\/\/www.piglet-net.net\/pigblog\/?p=1879"},"modified":"2011-07-05T17:16:09","modified_gmt":"2011-07-05T16:16:09","slug":"time-machine","status":"publish","type":"post","link":"https:\/\/www.piglet-net.net\/pigblog\/?p=1879","title":{"rendered":"Time Machine"},"content":{"rendered":"<p>Warning: tech content (and Windows tech content at that) follows.<\/p>\n<p>I don&#8217;t blog about work much, and only then, in general, tech terms- this is one of those: mainly for discussion with a few people I know who read here and may offer an explanation.<\/p>\n<p>I&#8217;ll start by saying it&#8217;s fixed. Rebuilding a Windows Domain Controller is not hard, if other DCs exist. That, in itself, is a lesson why you never, ever, only have one DC in a Windows domain.<br \/>\n<!--more--><br \/>\nFirst, I&#8217;ll set the scene: a (planned but very lengthy) power outage, combined with a desire to maintain service as long as possible, are probably the cause, along with a bit of VMWare cleverness.<\/p>\n<p>The symptoms: Logon failures, unexpected password prompts, account creation failing. One DC with a clock an hour ahead of the others. These symptoms are expected together- <a href=\"http:\/\/en.wikipedia.org\/wiki\/Kerberos_%28protocol%29\">Kerberos<\/a> expects times to be matched fairly closely. <\/p>\n<p>You&#8217;d expect the fix to be easy: fix the duff time, reboot the lot, and off it should go. Here&#8217;s the but- one DC (on VMWare) kept on advancing it&#8217;s clock, each time it started. Some client PCs would pick up time from that server too. As another DC was Infrastructure Master, this one would be refused from talking to the rest of the domain properly.<\/p>\n<p>After much mucking about checking NTP servers, hardware clocks,  and VMWare settings (There&#8217;s a setting to sync the HW clock to the ESX host at boot), and checking the <a href=\"http:\/\/support.microsoft.com\/gp\/cp_dst\">Daylight Savings patches<\/a> (which would seem obvious for a 1 hour difference), no good reason was found for the problem: with increasing calls from users and my patience wearing thin, I decided to rebuild, so stopped the time service, synched the clock manually, and ran our old friend<br \/>\n<code><br \/>\ndcpromo<\/code><br \/>\nand demoted the server out, renamed it, changed it&#8217;s IP, then built a new VMWare Server 2003 R2 box, patched it, and did<\/p>\n<p><code><br \/>\ndcpromo<\/code><\/p>\n<p>again to do the reverse. A bit of tweaking  to add DNS and RADIUS and all is well. It seems extreme, but had I done it earlier I&#8217;d probably not have the headache I do. What a nice welcome back to work that wasn&#8217;t.<\/p>\n<p>My theory is as follows: The large VMWare cluster this DC ran on was running on reduced capacity, and may have even stopped, as the power ran out. At that point the DC would have been paused, and got confused when it was re-awakened several hours in the future. What I <em>don&#8217;t<\/em> understand, is why it <strong>would not<\/strong> be told what the correct time was, even with the updating service disabled. Any ideas? *nudges LeeH-W, Sublimeproduct and Andy*<\/p>\n<p>The obvious stuff was OK- hardware clock, ESX Host clock (been there, done that) NTP servers, Timezone, Daylight saving.<\/p>\n<p>Lessons for next time? Just take the bloody lot down, instead of trying to keep stuff going. <\/p>\n<p>Oh, and if any non-sysadmin types have made it this far, this is why we hate power failures, patches, and reboots. <\/p>\n<p>[edit] Read the comments. I&#8217;ve solved the mystery.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Warning: tech content (and Windows tech content at that) follows. I don&#8217;t blog about work much, and only then, in general, tech terms- this is one of those: mainly for discussion with a few people I know who read here and may offer an explanation. I&#8217;ll start by saying it&#8217;s fixed. Rebuilding a Windows Domain &hellip; <a href=\"https:\/\/www.piglet-net.net\/pigblog\/?p=1879\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Time Machine<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,23],"tags":[],"class_list":["post-1879","post","type-post","status-publish","format-standard","hentry","category-computers","category-tech"],"_links":{"self":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts\/1879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1879"}],"version-history":[{"count":0,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=\/wp\/v2\/posts\/1879\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.piglet-net.net\/pigblog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}