answersLogoWhite

0


Best Answer

SRV Resource Records

When a Windows 2000-based domain controller starts up, the Net Logon service uses dynamic updates to register SRV resource records in the DNS database, as described in "A DNS RR for specifying the location of services (DNS SRV)

The SRV record is used to map the name of a service (in this case, the LDAP service) to the DNS computer name of a server that offers that service. In a Windows 2000 network, an LDAP resource record locates a domain controller.

A workstation that is logging on to a Windows 2000 domain queries DNS for SRV records in the general form:

_Service ._ Protocol . DnsDomainName

Active Directory servers offer the LDAP service over the TCP protocol; therefore, clients find an LDAP server by querying DNS for a record of the form:

_ldap._tcp. DnsDomainName

_msdcs Subdomain

There are possible implementations of LDAP servers other than Windows 2000-based domain controllers. There are also possible implementations of LDAP directory services that employ Global Catalog servers but are not servers that are running Windows 2000. To facilitate locating Windows 2000-based domain controllers, in addition to the standard _ Service ._ Protocol . DnsDomainName format, the Net Logon service registers SRV records that identify the well-known server-type pseudonyms "dc" (domain controller), "gc" (Global Catalog), "pdc" (primary domain controller, and "domains" (globally unique identifier, or GUID) as prefixes in the _msdcs subdomain. This Microsoft-specific subdomain allows location of domain controllers that have Windows 2000-specific roles in the domain or forest, as well as the location by GUID when a domain has been renamed. To accommodate locating domain controllers by server type or by GUID (abbreviated "dctype"), Windows 2000-based domain controllers register SRV records in the following form:

_ Service ._ Protocol . DcType ._msdcs. DnsDomainName

The addition of the _msdcs subdomain means that two sets of DNS names can be used to find an LDAP server: DnsDomainName is used to find an LDAP server or Kerberos server that is running TCP (or, in the case of a Kerberos server, either TCP or the User Datagram Protocol [UDP]), and the subdomain _msdcs. DnsDomainName is used to find an LDAP server that is running TCP and also functioning in a particular Windows 2000 role. The name "_msdcs" is reserved for locating domain controllers. The single keyword "_msdcs" was chosen to avoid cluttering the DNS namespace unnecessarily. Other constant, well-known names (pdc, dc, and gc) were kept short to avoid exceeding the maximum length of DnsDomainName.

User Avatar

Wiki User

12y ago
This answer is:
User Avatar
More answers
User Avatar

Wiki User

13y ago

SRV records

This answer is:
User Avatar

Add your answer:

Earn +20 pts
Q: What is the active directory clients rely on in dns to locate active directory resources such as domain controllers and global catalog servers?
Write your answer...
Submit
Still have questions?
magnify glass
imp
Related questions

What do active directory clients rely on in DNS to locateresources in active directory?

DHCP


Which of the following directives grant access to a directory hierarchy to the specifies clients?

AllowOverride


Cataloguer models how to start?

To be a catalog model you will need to have a good modeling agency representing you. Your agent will find you work with clients that are in need of catalog models.


What products does the Applegate Directory provide?

Applegate Directory provides business to business solutions. They are mainly for networking in the United Kingdom and Ireland. The directory provides information on more than 250,000 clients and customers.


DNS Without WINS on Server 2003?

That's actually fairly common. DNS is required for Active Directory domain controllers in Server 2003, but WINS is only used for older NetBEUI clients. The use of NetBEUI is deprecated in most modern Windows networks, so a WINS server is rarely used.


Which service is provided by Exchange Server 2003 to provide Active Directory authentication for non outlook clients?

dsa.msc


Preventing a system from providing resources or services to the intended authorized clients is a definition for?

Denial of service is preventing a system from providing resources or services to intended authorized clients.


How might an entry in an online business directory help one's business?

By using a webpage-based business directory a person or company can improve their levels of advertising. This may help them to reach new clients and contacts.


What enables a server to share resources with clients?

NOS or "Network operating systems."


What does the sysvol folder stores in an active directory?

The sysVOL folder stores the server's copy of the domain's public files. The contents such as group policy, users etc of the sysvol folder are replicated to all domain controllers in the domain. The sysvol folder must be located on an NTFS volume The article describes how to use the Burflags registry entry to rebuild each domain controller's copy of the system volume (SYSVOL) tree on all domain controllers in a common Active Directory directory service domain. The term SYSVOL refers to a set of files and folders that reside on the local hard disk of each domain controller in a domain and that are replicated by the File Replication service (FRS). Network clients access the contents of the SYSVOL tree by using the following shared folders:


What is require by DNS for Active Directory to function?

SRV records. SRV Records are the locator records withing DNS that allow clients to locate an Active Directory domain controller or global catalog.Source: Microsoft Windows Server 2008 Active Directory Configuration Official Academic Course Textbook.


What Authentication is designed for use with Active Directory Web servers whose clients are on the other side of a proxy server or firewall?

Digest Authentication