日韩性视频-久久久蜜桃-www中文字幕-在线中文字幕av-亚洲欧美一区二区三区四区-撸久久-香蕉视频一区-久久无码精品丰满人妻-国产高潮av-激情福利社-日韩av网址大全-国产精品久久999-日本五十路在线-性欧美在线-久久99精品波多结衣一区-男女午夜免费视频-黑人极品ⅴideos精品欧美棵-人人妻人人澡人人爽精品欧美一区-日韩一区在线看-欧美a级在线免费观看

歡迎訪問 生活随笔!

生活随笔

當前位置: 首頁 > 编程资源 > 编程问答 >内容正文

编程问答

Directory Service Maintenance

發布時間:2024/4/15 编程问答 29 豆豆
生活随笔 收集整理的這篇文章主要介紹了 Directory Service Maintenance 小編覺得挺不錯的,現在分享給大家,幫大家做個參考.

摘錄自:http://drummermark.com/mcsenotes/

Directory Service Maintenance

Active Directory is a transactional database. This means that it has built-in recovery techniques that are performed automatically should a system fail because of a hardware problem. However, there are routine maintenance AD activities--on each DC--that should be performed regularly:
  • Backing up AD data - a backup can be performed with the DC online. It is wise to back up the database, log files, and system state data. Also, back up your users' data, just in case of a flood or an earthquake-they'll appreciate it! Remember, system state data is:
    • AD database files - (see below)
    • SYSVOL folder - used to replicate GPO data and logon scripts; exist on all DCs.
    • Registry - you know, the registry.
    • System startup files
    • Class Registration database - installed component services.
    • Certificate Services database (if installed)
  • Restoring AD data
    • Rely on AD replication to take care of updating a new DC; simply install new DC.
    • Restore Wizard from the Backup utility; if backups were accomplished.
      • Nonauthoritative restore - a restore of data from backup. Because the data will probably be out of date, normal AD replication processes make sure that data elements are updated. The server must be offline.
      • Authoritative restore - used to restore individual pieces of AD; increments the property version number (PVN) to 100,000; forces replication to all other DCs via normal AD replication processes. At the command prompt, enter: ntdsutilauthoritative restorerestore subtree {distinguished name} i.e. OU=finance,DC=HCSNET,DC=COMquitquit
      Restore operations are highly dependent upon the tombstone period (see below). You cannot restore system state data from tapes that have backups older than the tombstone date. This is because data is deleted once the tombstone lifetime has expired. Introducing a DC with older data that has been erased from other DCs will cause database inconsistencies.
  • Moving the AD database - it's wise to move the database file to a separate physical hard disk from the log files to prevent disk contention. Log files are being written to constantly. When a query is made against the AD database, the disk's heads have to move to read from ntds.dit, which reduces overall performance of the disk subsystem. The database can be moved with ntdsutil. Perform the following steps:
    • Restart the server, press F8 during startup, and select Directory Services Restore Mode. (Starts server, but not AD).
    • Log in using the Administrators account. (Stored locally and can be different for each DC in the enterprise).
    • Open a command prompt enter the following: ntdsutilfilesmove db to {drive\folder}quitquitThese commands move the database file and update the Registry to point to the new location.
  • Defragmenting AD data
    • online - slower than offline; automatically runs every 12 hours; full defragmentation can take place with this method, but the size of the AD database file will never be reduced. The records are moved to contiguous sectors, but the empty space remains.
    • offline - never occurs on the live database file; occurs on a copy. When defragmentation is complete, you must archive the current version of ntds.dit that is being used and move the defragmented version in its place. Don't delete the old ntds.dit until the DC has been rebooted and proven to work with the new defragmented file. Offline defragmentation is the only way to return space from the database to the file system. The procedure is as follows:
      • Restart the server, press F8 during startup, and select Directory Services Restore Mode. (Starts server, but not AD).
      • Log in using the Administrators account. (Stored locally and can be different for each DC in the enterprise).
      • Open a command prompt enter the following: ntdsutilfilescompact to {drive\folder}quitquit
      • Once the process is complete, a new ntds.dit will exist. Copy the new ntds.dit file over the old version of ntds.dit and restart the DC.

AD files

AD uses the Extensible Storage Engine (ESE), which was first used in Exchange Server. It uses the concept of transactions to ensure that the database does not become corrupted by partial updates. This allows it to recover in the case of a power failure. Each transaction is a call to modify the database. For the transactional system to work, the AD database must have log files. They are used to store modifications before the data is written to the physical database file. Remember, these files exist on every DC and each instance must be maintained separately:
  • ntds.dit - the single file that holds all the AD data. This includes all objects and schema information. It is stored by default in \NTDS. The .dit extension stands for "directory information tree."
  • edb*.log - the transactional log for ntds.dit. The current file being used is called edb.log. When that file reaches a specified size (10MB), the file gets renamed to edbxxxxx.log. When the files are no longer needed, they are deleted by the system.
  • edb.chk - the checkpoint file that keeps track of which entries in the log file have been written to the database file. In case of failure, Windows 2000 uses this file to find out which entries in the log file can safely be written out to a database file.
  • res1.log, res2.log - two placeholders that exist to "take up space." If a DC runs out of disk space, these two files (10MB each) prevent a DC from being able to write to the log files, such that, AD can be sure that it has at least 20MB of space to write out any necessary log data.

Garbage Collection

Garbage collection is the process in which old data is purged from AD. Data is not immediately deleted from AD. Instead, the object's attributes are deleted and the object is moved to the Deleted Objects container. The object is then assigned a tombstone. By default, the tombstone is 60 days. This gives AD replication time to replicate the change to all DCs. Garbage collection is also the process of defragmenting the database. To change the garbage collection interval, use ADSIEdit. Connect to the Configuration container and edit the garbageCollPeriod and the tombstoneLifetime attributes, which will show as <not set> in the tool.

總結

以上是生活随笔為你收集整理的Directory Service Maintenance的全部內容,希望文章能夠幫你解決所遇到的問題。

如果覺得生活随笔網站內容還不錯,歡迎將生活随笔推薦給好友。

主站蜘蛛池模板: 91久精品| 18久久| 国产日产欧美 | 爱爱15p | 久久经典视频 | 爱操视频 | 狠狠干干干 | 欧美毛片在线 | 涩涩涩涩涩涩涩涩涩 | a毛片| 国产综合精品久久久久成人影 | jizzjizz在线观看| 99久久久无码国产 | 四虎色| 波多野吉衣久久 | 欧美女同视频 | 日韩免费av网站 | 欧美一级做a爰片免费视频 成人激情在线观看 | 不卡的日韩av | 国内自拍第三页 | 在线a免费 | 特级丰满少妇一级aaa爱毛片 | avxx| 日本a v在线播放 | 亚洲国产日韩一区 | 91在线资源 | 巨乳女教师的诱惑 | 亚洲v欧美 | 日日摸夜夜添狠狠添欧美 | 成人中文字幕在线观看 | avtt在线播放 | 操日韩| 午夜国产福利 | 免费看黄的网址 | 女女爱爱视频 | 一区二区三区免费看视频 | 久久影院精品 | 成人精品视频网站 | 国产在线xxx| 日韩福利在线视频 | 野花视频免费在线观看 | 欧美日韩国产一区二区三区在线观看 | 国内偷拍精品视频 | 伊人99在线 | 欧美三级大片 | av在线操| 欧美亚洲黄色片 | 黄色片xxxx| 狼人伊人av | 在线观看aa | 亚洲第一二三四区 | 51av视频| 日韩少妇视频 | 亚洲av日韩av不卡在线观看 | 国产第七页 | 99久久久久成人国产免费 | 日本wwwwwww | 日韩黄片一区二区三区 | 可以直接在线观看的av | 国产精品污 | 一区二区美女 | 精品视频一区二区在线观看 | 一区二区三区四区中文字幕 | 欧美美女在线 | 日韩福利视频一区 | 国产成人午夜 | 午夜免费观看视频 | 精品一二三区久久aaa片 | 日本一区电影 | 日干夜干天天干 | 日本久久视频 | 亚洲综合婷婷久久 | 成人激情免费视频 | 狠狠搞av | 庆余年三 | 欧美一级片在线观看 | 亚洲色图首页 | 青青偷拍视频 | 国产群p| 蜜桃视频在线播放 | 一区二区三区四区在线 | 91麻豆网站 | julia一区二区三区中文字幕 | 亚洲一区中文 | 三上悠亚激情av一区二区三区 | 久久精品天堂 | 国产成人精品影院 | 51妺嘿嘿午夜福利 | 免费视频久久久 | 男人操女人动态图 | 草啪啪 | 国产视频三区 | 色婷婷av国产精品 | 这里都是精品 | 玖操 | 激情成人综合 | 久久免费高清视频 | 91精品国产色综合久久不卡98口 | 一级片黄色的 |