Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Clustering > W2k3 R2 Cluster: Virtual Server name Machine Accounts in Domain

Reply
Thread Tools Display Modes

W2k3 R2 Cluster: Virtual Server name Machine Accounts in Domain

 
 
Alex French
Guest
Posts: n/a

 
      11-25-2008
Hi All,

I'm trying to get to the bottom of the purpose of machine accounts for the
virtual nodes that get created in AD.

We've built a 2 node active/active cluster with 6 virtual nodes on it (each
with their own LUN, etc...). I've noticed that each virtual node has created
a computer account in AD.

Reading the documentation this is required for Kerberos Authentication, and
that is what we are using.

However, the machine accounts don't seem to get their passwords changed
every 30 days like physical servers do.

Has anyone seen this before? is it a known issue ?

Thanks

Alex


--
----------------8<-------------
Alex French
 
Reply With Quote
 
 
 
 
Jeff Hughes [MSFT]
Guest
Posts: n/a

 
      11-25-2008
In order for Kerberos to work, there has to be a machine object in AD for
the cluster network name resources. That object is merely a placeholder for
a SID so that Kerberos can authenticate a session between clients using the
cluster name and the cluster. They are obviously not real machines
therefore, any machine policies should not be applied to them. Can you give
us a little more detail about what specific issues you are seeing that is a
problem?
--
Jeff Hughes, MCSE
Senior Support Escalation Engineer
Microsoft Enterprise Platforms Support (Server Core/Cluster)


"Alex French" <> wrote in message
news:0E1C4B6D-E7E7-4392-8A09-...
> Hi All,
>
> I'm trying to get to the bottom of the purpose of machine accounts for the
> virtual nodes that get created in AD.
>
> We've built a 2 node active/active cluster with 6 virtual nodes on it
> (each
> with their own LUN, etc...). I've noticed that each virtual node has
> created
> a computer account in AD.
>
> Reading the documentation this is required for Kerberos Authentication,
> and
> that is what we are using.
>
> However, the machine accounts don't seem to get their passwords changed
> every 30 days like physical servers do.
>
> Has anyone seen this before? is it a known issue ?
>
> Thanks
>
> Alex
>
>
> --
> ----------------8<-------------
> Alex French


 
Reply With Quote
 
Alex French
Guest
Posts: n/a

 
      11-25-2008
Hi Jeff,

Thanks for the prompt reply!

We're trying to clean up old AD computer accounts using the 'password last
changed' (pwdLastSet) LDAP attribute and the virtual server computer accounts
get flagged as they haven't changed their password since they were first
created...

Is it by design that the placeholder account doesn't get it's password set?
or is it just that because it's not a 'real' OS instance with a netlogon
service instance behind it that it's not going to ever get changed?

I understand if that's the case - We can code around it !

Thanks again

Alex
--
----------------8<-------------
Alex French


"Jeff Hughes [MSFT]" wrote:

> In order for Kerberos to work, there has to be a machine object in AD for
> the cluster network name resources. That object is merely a placeholder for
> a SID so that Kerberos can authenticate a session between clients using the
> cluster name and the cluster. They are obviously not real machines
> therefore, any machine policies should not be applied to them. Can you give
> us a little more detail about what specific issues you are seeing that is a
> problem?
> --
> Jeff Hughes, MCSE
> Senior Support Escalation Engineer
> Microsoft Enterprise Platforms Support (Server Core/Cluster)
>
>
> "Alex French" <> wrote in message
> news:0E1C4B6D-E7E7-4392-8A09-...
> > Hi All,
> >
> > I'm trying to get to the bottom of the purpose of machine accounts for the
> > virtual nodes that get created in AD.
> >
> > We've built a 2 node active/active cluster with 6 virtual nodes on it
> > (each
> > with their own LUN, etc...). I've noticed that each virtual node has
> > created
> > a computer account in AD.
> >
> > Reading the documentation this is required for Kerberos Authentication,
> > and
> > that is what we are using.
> >
> > However, the machine accounts don't seem to get their passwords changed
> > every 30 days like physical servers do.
> >
> > Has anyone seen this before? is it a known issue ?
> >
> > Thanks
> >
> > Alex
> >
> >
> > --
> > ----------------8<-------------
> > Alex French

>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Promoting W2K3 Member Server (w2k3 sp1) as AD (domain is w2k3 R2 based) John Active Directory 3 07-19-2006 06:24 PM
How to install W2k3 in a virtual server machine Ricky Virtual PC 10 07-13-2006 12:18 AM
Two-Node Virtual Machine Cluster with Windows Server 2003 Scotte Clustering 3 06-17-2005 04:40 PM
XP clients get no logon server error - machine accounts lose password on 2003 AD domain Fred Active Directory 5 03-02-2005 10:12 PM
Virtual Server 2005: Virtual Machine to Physical Machine Migration Alice Virtual PC 1 09-30-2004 05:17 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59