ä»é±ã¯ãActive Directoryãéçšããäžã§æ³šæãå¿ èŠãªæ©èœã®ã²ãšã€ãæäœãã¹ã¿ã«ã€ããŠåãäžãããã
NTãã¡ã€ã³ã§ã¯ããã¡ã€ã³ã³ã³ãããŒã©ã«PDC(Primary Domain Controller)ã»BDC(Backup Domain Controller)ãšããäž»åŸã®åºå¥ããã£ãããŠãŒã¶ãŒã¢ã«ãŠã³ãæ å ±ã管çããã®ã¯PDCã®ä»äºã§ãBDCã¯ã¢ã«ãŠã³ãæ å ±ã®ã³ããŒãåãåãã ãããšããéããããã
äžæ¹ãActive Directoryã§ã¯ãã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ã察çã§ããã©ã€ããª/ããã¯ã¢ãããšããåºå¥ã¯ãªããããããäžéšã®ãã¡ã€ã³ã³ã³ãããŒã©ã ããæã£ãŠããæ©èœãããããããã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ãå®å šã«åäžãšããããã§ã¯ãªãã
FSMOãæ§æãã5ã€ã®æ©èœ
å ·äœçã«ã¯ã以äžã«ç€ºã5çš®é¡ã®æ©èœã«ã€ããŠããã©ã¬ã¹ãããããã¯ãã¡ã€ã³ãæ§æãããã¡ã€ã³ã³ã³ãããŒã©ã®ãã¡1å°ã ããæ åœããããã«ãªã£ãŠããã
- ã¹ããŒããã¹ã¿(ãã©ã¬ã¹ãããšã«1å°): Active Directoryã管çããæ å ±ã®çš®é¡(ããŒã¿ããŒã¹ã¹ããŒã)ã管çãã
- ãã¡ã€ã³ååä»ãæäœãã¹ã¿(ãã©ã¬ã¹ãããšã«1å°): ãã©ã¬ã¹ãã«ããããã¡ã€ã³ã®è¿œå /åé€ã管çãããWindows 2000 Serverã§ããã¡ã€ã³ããŒãã³ã°ãã¹ã¿ãšåŒãã§ãããã®ãšåäž
- RIDããŒã«ãã¹ã¿(ãã¡ã€ã³ããšã«1å°): ãªããžã§ã¯ãã®åºæèå¥ã«äœ¿çšããSIDã®äžéšãæ§æãããRIDã®æ å ±ã管çããŠéè€ãé²ã
- PDCãšãã¥ã¬ãŒã¿(ãã¡ã€ã³ããšã«1å°): ãã¡ã€ã³ã³ã³ãããŒã©ããã¯ã©ã€ã¢ã³ãPCããNTãã¡ã€ã³ã®ãã©ã€ããªãã¡ã€ã³ã³ã³ãããŒã©ãšããŠèŠããããã«ããŠãWindows 9x/NTãšã®äºææ§ã確ä¿ããããã®æ©èœããŸããè€æ°ã®ãã¡ã€ã³ã³ã³ãããŒã©ã®éã§æ å ±ã®åæãå®äºããŠããªããšããã¹ã¯ãŒãæ å ±ã®é£ãéããåå ã§ãã°ãªã³ã«å€±æããããšããããããã®éã«ãã°ãªã³æ å ±ã®è»¢éãåãä»ããŠèªèšŒãè¡ãæ©èœãåãæã€
- ã€ã³ãã©ã¹ãã©ã¯ãã£ãã¹ã¿(ãã¡ã€ã³ããšã«1å°): ãã¡ã€ã³å ã§ãã°ã«ãŒãã«æå±ããŠãããŠãŒã¶ãŒã¢ã«ãŠã³ãã®ã¡ã³ãæ å ±ã管çãã
ããã5çš®é¡ã®æ©èœãç·ç§°ããŠãFSMO(Flexible Single Master Operationããã£ãºã¢)ãšããããŸããFSMOã®æ©èœãæã€ãã¡ã€ã³ã³ã³ãããŒã©ã®ããšãæäœãã¹ã¿ãšããã
ã¹ããŒããã¹ã¿ãšãã¡ã€ã³ååä»ãæäœãã¹ã¿ã¯ããã©ã¬ã¹ãã«ãŒããã¡ã€ã³ã§æåã«ã»ããã¢ãããããã¡ã€ã³ã³ã³ãããŒã©ãæ åœããããã®ä»ã®æ©èœã¯ãåã ã®ãã¡ã€ã³ã§æåã«ã»ããã¢ãããããã¡ã€ã³ã³ã³ãããŒã©ãæ åœããã
ã€ãŸããåäžãã¡ã€ã³æ§æã§ããã°ãæåã«Active Directoryãæ§æãããšãã«æ§æãã1å°ç®ã®ãã¡ã€ã³ã³ã³ãããŒã©ããæäœãã¹ã¿ãšããŠäžèšã®æ©èœãã¹ãŠãåãæã£ãŠããããšã«ãªãããã®åŸãåäžãã©ã¬ã¹ãå ã«ãã¡ã€ã³ã远å ãããšãããããã®ãã¡ã€ã³ã§æåã«æ§æãããã¡ã€ã³ã³ã³ãããŒã©ããåœè©²ãã¡ã€ã³ã®RIDããŒã«ãã¹ã¿ã»PDCãšãã¥ã¬ãŒã¿ã»ã€ã³ãã©ã¹ãã©ã¯ãã£ãã¹ã¿ãåãæã€ã
ãã©ã¬ã¹ãããã¡ã€ã³ããæäœãã¹ã¿ãããªããªããšããã¡ã€ã³ã®åäœã«æ¯éããããããã®ããããã¡ã€ã³ã³ã³ãããŒã©ã«é害ãçºçããå Žåããããã¯ãã¡ã€ã³ã³ã³ãããŒã©ãéæ ŒããŠãã¡ã€ã³ãåé€ããå Žåã«åããŠãã©ã®ãã¡ã€ã³ã³ã³ãããŒã©ãæäœãã¹ã¿ã«ãªã£ãŠããããææ¡ããŠããå¿ èŠãããã
æäœãã¹ã¿ã«ãªã£ãŠãããã¡ã€ã³ã³ã³ãããŒã©ã®ç¢ºèª
次åã«ãæäœãã¹ã¿ãå¥ã®ãã¡ã€ã³ã³ã³ãããŒã©ã«ç§»åããæ¹æ³ã«ã€ããŠè§£èª¬ããäºå®ã ããã®éã«äœ¿çšããMMC管çã³ã³ãœãŒã«ã®ç»é¢ã§ãã©ã®ãã¡ã€ã³ã³ã³ãããŒã©ãæäœãã¹ã¿ã«ãªã£ãŠããããææ¡ã§ãããããããããããç ©éãªæé ã«ãªãã®ã¯åŠããªããããntdsutilã³ãã³ãã䜿ã£ãŠèª¿ã¹ãæ¹æ³ã玹ä»ããã
ãã®ã³ãã³ãã¯ãæäœãã¹ã¿ã®ç¶æ 確èªã ãã§ãªããé害çºçæã«å¿ èŠãšãªãæäœãã¹ã¿ã®åŒ·å¶ç§»åãActive Directoryã®åçš®ã¡ã³ããã³ã¹äœæ¥ã§ã䜿çšãããä»åã¯ã²ãšãŸããç¶æ 確èªã®æ¹æ³ã ã解説ãããããªãã以äžã®è§£èª¬ã§ãå ¥åããããšããå ŽåãæåŸã«[Enter]ããŒãæŒãæäœãŸã§å«ãã
- ã³ãã³ãããã³ãããå®è¡ããŠããntdsutilããšå ¥åãã
- ãntdsutil:ããšããããã³ããã衚瀺ãããããã§ãRolesããšå ¥åãã
- ããã³ããããfsmo maintenance:ãã«å€åãããããã¯ãntdsutilã³ãã³ãã®ã¢ãŒã(ã³ã³ããã¹ããšåŒãã§ãã)ãåãæ¿ãã£ãããšãæå³ããŠãã
- ãconnectionsããšå ¥åããŠã察象ãšãªããã¡ã€ã³ããããã¯ãã¡ã€ã³ã³ã³ãããŒã©ã«æ¥ç¶ããæç€ºãè¡ãã
- ããã³ããããserver connections:ãã«å€åããã®ã§ãããã§ãconnect to domain <ãã¡ã€ã³DNSå>ããŸãã¯ãconnect to domain <ãã¡ã€ã³ã³ã³ãããŒã©ã®DNSå>ããšå ¥åããããã¡ã€ã³ãå¯Ÿè±¡ã«æå®ããå Žåãåœè©²ãã¡ã€ã³ãæ§æãããã¡ã€ã³ã³ã³ãããŒã©ãã©ãã1å°ãèªåçã«æå®ããŠæ¥ç¶ããã
- ã\<ãã¡ã€ã³ã³ã³ãããŒã©ã®DNSå> ã«çµåããŠããŸã...ããšããã¡ãã»ãŒãžã衚瀺ãããç¶ããŠãæ¥ç¶ã«æåãããšãããŒã«ã«ã§ãã°ãªã³ããŠãããŠãŒã¶ãŒã®è³æ Œæ å ±ã䜿ã£ãŠ \<ãã¡ã€ã³ã³ã³ãããŒã©ã®DNSå> ã«æ¥ç¶ããŸãããããšè¡šç€ºããã
- ãquitããšå ¥åããŠãå ã®ã³ã³ããã¹ããžæ»ããããã³ããããfsmo maintenance:ãã«æ»ãã
- ãSelect operation targetããšå ¥åãããããã³ããããselect operation target:ãã«å€åããã
- ãList roles for connected serverããšå ¥åããããã®æäœã«ãããFSMOã®æ©èœããšã«ãããããã©ã®ãµãŒããåãæã£ãŠãããã衚瀺ããããã®ãšããLDAPèå¥åã§è¡šç€ºããç¹ã«æ³šæãããã
- ãquitãã3åç¶ããŠå ¥åãããšãã³ã³ããã¹ãããé ã«å ã«æ»ããæåŸã«ntdsutilã³ãã³ããã®ãã®ãçµäºããã