<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: Windows Server 2008: the disadvantages of RODCs</title>
	<atom:link href="http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/feed/" rel="self" type="application/rss+xml" />
	<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/</link>
	<description>For Windows Administrators</description>
	<lastBuildDate>Mon, 22 Mar 2010 06:58:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Lukas Beeler</title>
		<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/comment-page-1/#comment-128036</link>
		<dc:creator>Lukas Beeler</dc:creator>
		<pubDate>Wed, 03 Jun 2009 17:10:06 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/#comment-128036</guid>
		<description>Roel,

yes, of course. The computer account must also be cached, and it can easily be configured to do so. It&#039;s just that in dsa.msc, the default search DOES NOT include computer accounts.</description>
		<content:encoded><![CDATA[<p>Roel,</p>
<p>yes, of course. The computer account must also be cached, and it can easily be configured to do so. It&#8217;s just that in dsa.msc, the default search DOES NOT include computer accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roel Slob</title>
		<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/comment-page-1/#comment-128035</link>
		<dc:creator>Roel Slob</dc:creator>
		<pubDate>Wed, 03 Jun 2009 17:04:32 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/#comment-128035</guid>
		<description>The error does not point to the user account, but to the computer account. So if the client pc-account cannot be verified it has not been able to verify any user account in the AD.
It looks to me that you also have to cache the pc-account, but it&#039;s a wild guess.
Is that even possible? I don&#039;t have a virtual environment at hand right now.</description>
		<content:encoded><![CDATA[<p>The error does not point to the user account, but to the computer account. So if the client pc-account cannot be verified it has not been able to verify any user account in the AD.<br />
It looks to me that you also have to cache the pc-account, but it&#8217;s a wild guess.<br />
Is that even possible? I don&#8217;t have a virtual environment at hand right now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kshitiz</title>
		<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/comment-page-1/#comment-128027</link>
		<dc:creator>Kshitiz</dc:creator>
		<pubDate>Wed, 03 Jun 2009 07:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/#comment-128027</guid>
		<description>I am still facing the issue. I am having simple LAb environment with A RWDC, RODC, a client machine and two Domain Users A and B (all at single site). Both RWDC and RODC have DNS and GC. Client machine and User A are set to ave password cached but not User B. After Reboot of Client and User A login, I see the account info being Cached on RODC but when trying to login with User A or B from client machine, when RWDC is Offiline, I get the message &quot;The trust relationship between this workstation and the primary domain failed&quot;. No Fancy stuff, No Multihomed DC etc.

Please share your thoughts.</description>
		<content:encoded><![CDATA[<p>I am still facing the issue. I am having simple LAb environment with A RWDC, RODC, a client machine and two Domain Users A and B (all at single site). Both RWDC and RODC have DNS and GC. Client machine and User A are set to ave password cached but not User B. After Reboot of Client and User A login, I see the account info being Cached on RODC but when trying to login with User A or B from client machine, when RWDC is Offiline, I get the message &#8220;The trust relationship between this workstation and the primary domain failed&#8221;. No Fancy stuff, No Multihomed DC etc.</p>
<p>Please share your thoughts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roel Slob</title>
		<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/comment-page-1/#comment-87693</link>
		<dc:creator>Roel Slob</dc:creator>
		<pubDate>Thu, 17 Jul 2008 16:25:09 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/#comment-87693</guid>
		<description>The reason you could not logon when the writable DC is down is probably because this DC is also the GC. You could give the RODC the role of GC. In that case you should be able to logon to the RODC with the writable DC offline.</description>
		<content:encoded><![CDATA[<p>The reason you could not logon when the writable DC is down is probably because this DC is also the GC. You could give the RODC the role of GC. In that case you should be able to logon to the RODC with the writable DC offline.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/comment-page-1/#comment-18441</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sat, 16 Jun 2007 09:43:42 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/#comment-18441</guid>
		<description>Thanks for the tip! I think your guess is right. It might be a problem related to multihomed DCs. I tried this feature with an RODC having just one network card and it worked there.</description>
		<content:encoded><![CDATA[<p>Thanks for the tip! I think your guess is right. It might be a problem related to multihomed DCs. I tried this feature with an RODC having just one network card and it worked there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lukas Beeler</title>
		<link>http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/comment-page-1/#comment-18432</link>
		<dc:creator>Lukas Beeler</dc:creator>
		<pubDate>Sat, 16 Jun 2007 07:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/archives/windows-server-2008-the-downsides-of-rodcs/#comment-18432</guid>
		<description>I believe your problem was that you used a multi homed domain controller.

See &lt;a href=&quot;http://support.microsoft.com/kb/272294&quot; rel=&quot;nofollow&quot;&gt;KB272294&lt;/a&gt;.

One of the biggest advantages of the RODC is that you can give administrator access to it, without giving any domain specific privileges.</description>
		<content:encoded><![CDATA[<p>I believe your problem was that you used a multi homed domain controller.</p>
<p>See <a href="http://support.microsoft.com/kb/272294" rel="nofollow">KB272294</a>.</p>
<p>One of the biggest advantages of the RODC is that you can give administrator access to it, without giving any domain specific privileges.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
