¸ÅÀÀ:
- ½«ÐµķþÎñ¹ÜÀíÆ÷Óë ADDS ½áºÏʹÓÃ
- ÔÚ Server Core ÉÏÔËÐÐÓò·þÎñ
- Ö»¶ÁÓò¿ØÖÆÆ÷
- ¸ü¸ÄÃÜÂë¡¢±¸·ÝºÍÉó¼Æ
Microsoft ͨ¹ý Windows 2000 ÏòÊÀÈËչʾÁË Active Directory¡£½ÓÏÂÀ´£¬ÔÚ Windows Server 2003 ÕâÒ»ÖØÒª°æ±¾ÖУ¬Active Directory µÃµ½Á˼«´óµÄ¸Ä½ø£¬µ«Î´×öÈκÎ
ÖØ´ó¸ü¸Ä¡£Èç½ñ£¬Active Directory® ÒѳÉΪ¹¦ÄÜÇ¿´óÇÒ¼«Æä³ÉÊìµÄĿ¼·þÎñ¡£¾¡¹ÜÈç´Ë£¬Active Directory ÍŶÓÈÔͨ¹ý²»Ð¸µÄŬÁ¦ÔÚ×îа汾ÖмÌÐøÍêÉÆÆä¹¦ÄÜ£¬ÒÔÌá¸ßÕâÒ»ºËÐÄÍøÂç·þÎñµÄ°²È«ÐԺͿɹÜÀíÐÔ¡£
ÔÚÊÀ¼ÍÖ®½»£¬Active Directory Ö÷ÒªÊÇÑéÖ¤µÇ¼µÄÓû§¡¢¶ÔÓû§ºÍ¼ÆËã»úÓ¦ÓÃ×é²ßÂÔ²¢ÐÖúÆäÕÒµ½ËùÐèµÄ´òÓ¡»ú¡£½ö½ö¼¸Äêºó£¬Microsoft ÓÖ·¢²¼ÁËÒ»¸ö¶ÀÁ¢µÄ¸ÄÁ¼°æ£¬³ÆÎª Active Directory Ó¦ÓóÌÐòģʽ (ADAM)¡£
µ½ÁË 2006£¬Ò»Çж¼»ÀȻһС£Active Directory ²»ÔÙÊÇÒ»ÖÖÌØ¶¨µÄ¼¼Êõ¡£ÏÖÔÚ£¬ËüÒѳÉΪһÖÖÆ·ÅÆÃû³Æ£¬´ú±íһϵÁÐ Windows® Éí·ÝºÍ·ÃÎÊ¿ØÖÆ·þÎñ¡£Í¼ 1 ΪÄúչʾÁË Active Directory Æ·ÅÆ×é³ÉÄÚÈݵĸÙÒª¡£

Figure 1 Active Directory ×é¼þ
| µ±Ç° Active Directory ¼¼Êõ | ÏÈǰ³ÆÎ½ | ˵Ã÷ |
| Active Directory Óò·þÎñ (ADDS) | Active Directory | ÎÒÃÇϰ¹ß³ÆÎª Active Directory¡£ËüΪÓòÓû§ºÍ¼ÆËã»úÌṩ Kerberos ºÍ»ùÓÚ NTLM µÄÑéÖ¤£¬²¢¹ÜÀí OU¡¢Óû§¡¢×é¡¢×é²ßÂԵȵȡ£ |
| Active Directory ÇáÐÍĿ¼·þÎñ (ADLDS) | Active Directory Ó¦ÓóÌÐòģʽ (ADAM) | ÒÔ ADDS ËùÓÃÔ´´úÂëΪ»ù´¡µÄ¸ßÐÔÄÜ LDAP ·þÎñÆ÷¡£ |
| Active Directory Ö¤Êé·þÎñ (ADCS) | Ö¤Êé·þÎñ | ʹÓà X.509 Ö¤ÊéÌṩǿÑéÖ¤¡£ |
| Active Directory Rights Management Services (ADRMS) | ȨÏÞ¹ÜÀí·þÎñÆ÷ | ͨ¹ý´´½¨ÊÜȨÏÞ±£»¤µÄÎļþºÍÈÝÆ÷·ÀֹδÊÚȨÓû§Ê¹ÓÃÊý×Ö×ʲú£¬ÈçÎĵµºÍµç×ÓÓʼþ¡£ |
| Active Directory ÁªºÏÉí·ÝÑéÖ¤·þÎñ (ADFS) | Active Directory ÁªºÏÉí·ÝÑéÖ¤·þÎñ | Ϊ¼æÈÝ WS-* µÄ Web ·þÎñÌṩ Web µ¥µãµÇ¼ºÍÁªºÏÉí·ÝÑéÖ¤¡£ |
Òò´Ë£¬ÒªÊÇΪʹÓúÏÊʵÄÊõÓӦ¸Ã½«ÕâÆªÎÄÕ³ÆÎª¡°Óò·þÎñ¡±½éÉÜ¡£µ«ÎªÁ˲»²úÉú»ìÏý£¬»¹ÊÇÓ¦¸Ã°ÑËü½Ð×ö×Ô 2000 ÄêÒÔÀ´ÉîΪÄú³ÆµÀµÄ Active Directory¡£
Windows Server 2008 ÖеķþÎñÆ÷¹ÜÀíÆ÷
¶ÔÓÚ Active Directory£¬ÎÒÊ×ÏÈÒªÌÖÂÛµÄÁ½Ïî¸Ä½ø²¢²»ÊÇ Active Directory Óò·þÎñ (ADDS) Öеĸü¸Ä£»¶øÊÇ Windows Öеĸü¸Ä£¬ËüÃÇ»á¸Ä±äÄú¹ÜÀí Active Directory µÄ·½Ê½¡£µÚÒ»ÏîÊÇеġ°·þÎñÆ÷¹ÜÀíÆ÷¡±£¬ËüÔÚÄúÊ×´ÎÆô¶¯ Windows Server® 2008 ·þÎñÆ÷ʱ¾Í»á³öÏÖ¡££¨µÚ¶þÏîÊÇ Active Directory °²×°£¬ÉÔºóÎÒÃǽ«¶ÔÆä½øÐнâ˵¡££©
°²×° Windows Server 2003 ºó£¬Ä¬ÈÏ»áËæºó³öÏÖ¡°ÅäÖ÷þÎñÆ÷Ïòµ¼¡±£¬Äú¿ÉÄÜ´ÓÖжԷþÎñÆ÷¹ÜÀíÆ÷ÓÐÒ»¶¨µÄÁ˽⡣µ«ÄǸö°æ±¾¶ÔÓÚÈÕ³£¹ÜÀí²»ÊÇÊ®·ÖÓÐÓã¬ÎÒËùÈÏʶµÄÿ¸öÈ˶¼Ñ¡ÔñÁË¡°µÇ¼ʱ²»ÏÔʾ´ËÒ³¡±¸´Ñ¡¿ò¡£
Windows Server 2008 ÖеķþÎñÆ÷¹ÜÀíÆ÷Ôò·Ç³£ÓÐÓã¨Çë²ÎÔÄ Byron Hynes ÔÚ±¾ÆÚ¡¶TechNet ÔÓÖ¾¡·×«Ð´µÄÎÄÕÂÁ˽â·þÎñÆ÷¹ÜÀíÆ÷µÄ¸Å¿ö£©¡£Ê×ÏÈ£¬Èçͼ 2 ÖÐËùʾ£¬·þÎñÆ÷¹ÜÀíÆ÷ÏÖÔÚÊôÓÚ Microsoft® ¹ÜÀí¿ØÖÆÌ¨ (MMC) ¹ÜÀíµ¥Ôª£¬¶ø·Ç Microsoft HTML Ó¦ÓóÌÐò (HTA)¡£ÕâÒâζ×ÅËü¾ß±¸ÁËÓû§ËùÊìϤµÄ½çÃæ£¬¹¦ÄÜÍ걸ÇÒÒ×ÓÚ×Ô¶¨Òå¡£Äú¿ÉËæÊ±Ê¹Ó÷þÎñÆ÷¹ÜÀíÆ÷ÕÆ¿Ø·þÎñÆ÷½ÇÉ«£¨DNS¡¢ADDS ºÍ IIS ÕâÀàÖ÷Òª·þÎñ£©ºÍ¹¦ÄÜ£¨Microsoft .NET Framework¡¢BitLockerTM Çý¶¯Æ÷¼ÓÃÜºÍ Windows PowerShellTM ÕâÀàÈí¼þ×é¼þ£©µÄ°²×°¡£³ýÁËÌí¼ÓºÍɾ³ýÈí¼þ£¬·þÎñÆ÷¹ÜÀíÆ÷»¹ÎªÔËÐÐÕï¶Ï¹¤¾ß£¨Èçʼþ²é¿´Æ÷ºÍ PerfMon£©¼°ÏµÍ³ÅäÖÃʵÓù¤¾ß£¨ÈçÉ豸¹ÜÀíÆ÷ºÍ Windows ·À»ðǽ¹ÜÀíµ¥Ôª£©ÌṩÁ˵¥µãÁªÂç¡£Èç¹ûÄúÄÜΪ Active Directory ¼ÓÈë MMC ¹ÜÀíµ¥Ôª£¬ÀýÈ磬Óû§ºÍ¼ÆËã»ú¡¢ÓòºÍÐÅÈιØÏµ¡¢Õ¾µãºÍ·þÎñ£¬Äú½«»ñµÃÒ»¸ö¼«Îª³öÉ«µÄ½çÃæ£¬ÓÃÓÚÖ´ÐÐ Windows Server 2008 Óò¿ØÖÆÆ÷ (DC) µÄÈÕ³£¹ÜÀí¡£
ͼ 2 Windows Server 2008 ÖеķþÎñÆ÷¹ÜÀíÆ÷ (µ¥»÷¸ÃͼÏñ»ñµÃ½Ï´óÊÓͼ)
Windows Server 2008 Server Core
Windows Server Core ÊÇÒ»¸öÐ嵀 Windows °²×°Ñ¡ÏËüÌṩһ¸ö¾«¼òµÄ Windows£¬½ö°üº¬ÔËÐÐijЩ¹Ø¼üµÄ·þÎñÆ÷½ÇÉ«£¨°üÀ¨ Active Directory Óò·þÎñ£©Ëù±ØÐèµÄ×é¼þ¡££¨Í¼ 3 ÖÐÁгöÁË Server Core Ö§³ÖµÄ½ÇÉ«¡££©ËäÈ» Server Core °²×°³ÌÐòÓÐͼÐλ¯ UI£¬µ«Ëü²¢²»ÔËÐÐ Windows ×ÀÃæÍâ¿Ç³ÌÐò£¬²¢ÇÒ¼¸ºõÂÔÈ¥ÁËËùÓйÜÀíºÍÅäÖà Windows µÄͼÐι¤¾ß£¨Çë²ÎÔÄͼ 4£©¡£È¡¶ø´úÖ®µÄÊÇÒ»¸öÃüÁîÐд°¿Ú£¬ÈÃÄú¶Ô½ÓÏÂÀ´µÄ²Ù×÷Éõ¸ÐÃÔã¡£ÈçºÎ¸ü¸Ä¼ÆËã»úÃû³Æ£¿ÈçºÎÅäÖþ²Ì¬ IP µØÖ·£¿
ͼ 4 ÔÚ Server Core UI Öп´²»µ½Ì«¶àµÄÄÚÈÝ (µ¥»÷¸ÃͼÏñ»ñµÃ½Ï´óÊÓͼ)
ÔÚ Server Core ×î³õ°²×°µÄ¼¸·ÖÖÓ£¬¿ÉÄÜ»áÓÐЩ»ìÂÒ¡£ºÜ¿ìÄú¾Í»áÖØÐÂÊìϤ WMIC¡¢NETSH ºÍ NETDOM£¬È»ºóÇáËÉÍê³ÉËùÓг£¹æÉèÖúÍÅäÖÃÈÎÎñ¡£²¢ÇÒ£¬ÄúÈÔ¿ÉÓÃ×¢²á±í±à¼Æ÷ºÍ¼Çʱ¾Âú×ãͼÐι¤¾ßµÄÐèÇó¡£
Server Core µÄÖ÷ÒªÓŵãÊÇÒÆ³ýÁËÐí¶àµäÐÍ Windows °²×°ÐèÒª£¬¶øÕâЩºËÐÄ·þÎñÆ÷½ÇÉ«²»ÐèÒªµÄ´úÂë¡£ÕâÑùÔâÊܶñÒâÈí¼þ¹¥»÷µÄ¼¸ÂʽµµÍÁË£¨ÊǼþºÃÊ£©£¬²¢ÇÒ DC ËùÐèµÄ²¹¶¡ºÍÖØÐÂÆô¶¯´ÎÊýÒ²´óΪ¼õÉÙ£¨¸üºÃµÄÊ£©¡£Õ¼ÓõĴÅÅ̿ռäÉÙÁËÐí¶à£¬´Ó¶ø¼õСµÄÓ²ÅÌÒªÇ󣬿ÉÄÜÔÚÒ»°ãÌõ¼þϲ»Ëãʲô£¬µ«¶ÔÓÚÐéÄâ·þÎñÆ÷»·¾³µÄ°ïÖúÈ´ºÜ´ó¡£
ȱÉÙͼÐλ¯ÊµÓù¤¾ß¶Ô ADDS µÄ¹ÜÀí»áÔì³ÉÀ§ÄÑÂð£¿ÍêÈ«²»»á¡£Í¨¹ýÔÚ¹¤×÷Õ¾ÔËÐÐʵÓù¤¾ß£¬È»ºóÁ¬½ÓÍøÂçÉϵÄÓò¿ØÖÆÆ÷£¬Äú¿ÉÔ¶³ÌÖ´Ðоø´ó²¿·Ö¹ÜÀíÈÎÎñ¡£ÎÒÆÚÍû Server Core °²×°×îÖÕ¿ÉÒÔÔËÐÐ´ó²¿·Ö DC¡£
DCPROMO ¸ü¸Ä
ADDS ±¾Éí×îÏÈÒýÆðÄú×¢ÒâµÄ¸ü¸ÄÊÇÐ嵀 DCPROMO¡£ËüµÄ×÷ÓÃÓë Windows Server 2003 ÖÐµÄ DCPROMO Ò»Ñù£¬µ«¾¹ýÖØÐ±àдºó¸üÈÝÒ×ʹÓÃÁË¡£ÀýÈ磬Äú²»±ØÊäÈëÄúµÄÓò¹ÜÀíԱƾ֤£¬DCPROMO ¿ÉÒÔ½«ÄúµÄµÇ¼ƾ֤Ìṩ¸ø·þÎñÆ÷¡£ÄúÒ²²»±ØÍ¨¹ý¼üÈë DCPROMO /ADV À´È¡µÃ¡°¸ß¼¶Ä£Ê½ DCPROMO¡±Ñ¡ÏÏÖÔÚµÚÒ»¸ö DCPROMO ¶Ô»°¿òÖÐÌṩÁËÕâЩѡÏîµÄ¸´Ñ¡¿ò¡£¸ß¼¶Ä£Ê½»¹ÔÊÐíÄúÑ¡Ôñ¸´ÖÆËùÐèµÄÏÖÓÐÓò¿ØÖÆÆ÷¡£ÕâÑù£¬Äú¾Í¿ÉÒÔ´ÓÉú²ú DC ÖÐ×ªÒÆ DCPROMO µÄ¸´ÖƸººÉ¡£
½« DC ÌáÉýµ½ÐÂÓò»òÁÖÖÐʱ£¬DCPROMO »áΪÄúÌṩѡÏ¹©ÄúÉèÖÃÁÖºÍÓò²Ù×÷¼¶±ð£¬¶ø²»ÊÇÔÚÌáÉýºó²Å×¼ÐíÄúÉèÖá£Äú»¹¿ÉÖ¸¶¨ÏëÒªÔÚÌáÉýÆÚ¼ä·ÅÖà DC µÄ Active Directory Õ¾µã£¬Èç¹û´æÔÚÎÞÈ˲ÎÓëµÄ DCPROMO£¬Õâ»á·Ç³£ÓаïÖú¡£DCPROMO ÉõÖÁ»á¸ù¾Ý DC µÄ IP µØÖ·¶Ô×îºÃµÄÕ¾µã¸ø³ö½¨Òé¡£
Ð嵀 DCPROMO »¹ÔÚÒ»¸öÒ³ÃæÉϻ㼯ÁËËùÓÐÅäÖÃÑ¡ÏÈÃÄãÔÚ´ËÑ¡ÔñРDC ÊÇÈ«¾Ö±à¼¡¢DNS ·þÎñÆ÷»¹ÊÇÖ»¶Á DC¡£Äú²»±Ø×ªµ½ Active Directory Õ¾µãºÍ·þÎñ¹ÜÀíµ¥ÔªÖÐµÄÆ«Æ§Î»Öý« DC ±ê¼ÇΪ GC¡£
РDCPROMO ÄÜÇ¡ºÃÔÚÌáÉý¿ªÊ¼Ç°ÔÚÒ»¸öÏìÓ¦ÎļþÖб£´æËùÓÐ DCPROMO ÉèÖã¬Õâ¿ÉÄÜÊÇËü×î³öÉ«µÄ¹¦ÄÜ¡£±ÈÆðÊÖ¹¤ÕûÀíÏìÓ¦Îļþ£¬ÕâÒª¼òµ¥µÃ¶à£¬»¹²»ÈÝÒ׳ö´í¡£ÄúËæºó¿ÉʹÓÃÏìÓ¦ÎļþÔÚÆäËû·þÎñÆ÷ÉÏÖ´ÐÐÎÞÈ˲ÎÓëµÄ DCPROMO¡£ÎªÁËÂú×ã½Å±¾³ÕÃÔÕßµÄÔ¸Íû£¬ËùÓÐ DCPROMO Ñ¡ÏîÏÖÔÚ¾ù¿Éͨ¹ýÃüÁîÐзÃÎÊ¡£
Ö»¶ÁÓò¿ØÖÆÆ÷
ÔÚ Active Directory µÄÔçÆÚ½×¶Î£¬ÆóÒµ³£³£ÔÚÓû§¿ÉÄܵǼµÄÿ¸öÕ¾µã¾ù²¿ÊðÓò¿ØÖÆÆ÷¡£ÀýÈç£¬ÒøÐÐͨ³£ÔÚÿ¸öÖ§Ðж¼°²×° DC¡£ÆäÖеÄÂß¼ÊÇÿ¸öÖ§ÐеÄÓû§¶¼ÄܵǼ²¢·ÃÎʱ¾µØÍøÂç×ÊÔ´£¬¼´Ê¹ WAN ʧЧҲÄÜÈç´Ë¡£
ÄÇʱ£¬Êµ¼ÊµÄ DC °²È«ÐèÇóûÓб»ºÜºÃµØÀí½â¡£ÎÒ¿´µ½¹ý¿ØÖÆÆ÷¶Ñ·ÅÔÚ×À×ÓÏÂÃæ£¬Â·¹ýµÄÈË¿ÉÒÔÇáÒ×½Ó´¥µ½ËüÃÇ¡£Ö±µ½¼¸Äêºó£¬Active Directory ¼Ü¹¹Ê¦²ÅÍêÈ«Áì»áµ½²»°²È«µÄ DC Ëù´øÀ´µÄ°²È«·çÏÕ£¬IT ×éÖ¯¿ªÊ¼½« DC ÖØÐ·Żص½ÖÐÑëÊý¾ÝÖÐÐÄ¡£ÕâÒÔʹ·ÖÖ§Óû§±ØÐë¾ÓÉ WAN ½øÐÐÑéÖ¤£¬µ«ÓÉÓÚÌá¸ßÁ˰²È«ÐÔ£¬ÕâÒ²ÊÇÖµµÃµÄ¡£
Windows Server 2008 ÖÐµÄ Active Directory ͨ¹ýÒý½øÖ»¶ÁÓò¿ØÖÆÆ÷»ò RODC ¸Ä±äÁË·ÖÖ§²¿ÊðµÄ¹æÔò¡£ËüÃÇÊÇ Windows Server 2008 Óò·þÎñÖÐ×î´óµÄ±ä»¯¡£
Active Directory ÍŶÓÔÚÉè¼Æ RODC Ê±ÖØµã¿¼ÂÇÁË·ÖÖ§»ú¹¹µÄÐèÇó£¬ËûÃǵÄÄ¿±êÊÇ¡°ÔÚ·ÖÖ§»ú¹¹¾ÍµØ½â¾öÎÊÌ⡱¡£ÕâÆäÖеÄÒªµãÊÇÈç¹ûÄúÔÚʵ¼ÊÌõ¼þ²»°²È«µÄ·ÖÖ§²¿ÊðÁË DC£¬»ù±¾ÉÏÄúÊÇÎÞ·¨·ÀÖ¹ DC£¨ºÍÐÅÈÎËüµÄ»úÆ÷£©Êܵ½¹¥»÷µÄ£¬µ«ÊÇÄú¿É·ÀÖ¹¹¥»÷ÏòÆäËûÓòÀ©É¢¡£
×¢Ò⣬¼´Ê¹ÕâÐèÒª¶Ô ADDS »ù´¡½á¹¹×öºÜ´óµÄ¸ü¸Ä£¬µ« RODC µÄʵÏÖ²¢²»¸´ÔÓ¡£ÄúµÄÓò±ØÐë´¦ÓÚ Windows Server 2003 µÄÁÖ¹¦Äܼ¶£¬²¢ÇÒÓòÖбØÐëÖÁÉÙÓÐÒ»¸ö Windows Server 2008 DC¡£³ýÁËÊÇ·ÖÖ§½â¾ö·½°¸£¬ÔÚÃæ¶Ô»¥ÁªÍøµÄ»·¾³ÖÐºÍ DC ´¦ÓÚÍøÂçÍâΧµÄÇé¿öÏ£¬RODC ͬÑù·¢»Ó×ÅÖØÒªµÄ×÷Óá£
DC ÀëÖ°
ÔÚ·ÖÖ§»ú¹¹ÖУ¬ÐèÒª¿¼ÂǼ¸ÀàÍþв¡£µÚÒ»ÀàÊÇ¡°DC ʧÇÔ¡±£¬¼´ÓÐÈË´ø×Å DC »ò DC µÄ´ÅÅÌÁïÖ®´ó¼ª¡£Õâ²»µ«»áʹ±¾µØµÄ·þÎñ±ÀÀ££¬¹¥»÷Õß×îÖÕ»¹ÓпÉÄܵõ½ÓòÖÐËùÓеÄÓû§ÃûºÍÃÜÂ룬²¢ÓɵÃÒÔ·ÃÎʱ£ÃÜ×ÊÔ´»òÔì³É¾Ü¾ø·þÎñ¡£Îª·À·¶ÕâÖÖÍþв£¬Ä¬ÈÏÇé¿öÏ£¬RODC ²»½«ÃÜÂë¹þÏ£´æ´¢ÔÚÆäĿ¼ÐÅÏ¢Ê÷ (DIT) ÖС£Òò´Ë£¬Óû§Ê×´ÎÏòÌØ¶¨µÄ RODC ½øÐÐÉí·ÝÑé֤ʱ£¬RODC »á½«¸ÃÇëÇó·¢Ë͸øÓòÖеÄÍêÈ«Óò¿ØÖÆÆ÷ (FDC)¡£FDC ´¦Àí¸ÃÇëÇó£¬Èç¹ûÑéÖ¤³É¹¦£¬RODC »áÇ©·¢ÃÜÂë¹þÏ£¸´ÖÆÇëÇó¡£
Êܵ½¹¥»÷µÄ RODC ÓпÉÄÜÇëÇóÃô¸ÐÕÊ»§µÄÃÜÂë¹þÏ£¡£Îª·ÀÖ¹ÕâÖÖÇé¿ö·¢Éú£¬Óò¹ÜÀíÔ±¿ÉΪÿ¸ö RODC ÅäÖÃÃÜÂë¸´ÖÆ²ßÂÔ¡£¸Ã²ßÂÔÓÉ RODC ¼ÆËã»ú¶ÔÏóµÄÁ½¸öÊôÐÔ×é³É¡£msDS-RevealOnDemandGroup ÊôÐÔ°üº¬ÃÜÂ뻺´æÓÚ RODC ÉϵÄ×é¡¢Óû§»ò¼ÆËã»úÕÊ»§µÄ¶ÀÓÐÃû³Æ£¨ËüÃÇͨ³£ÊÇÓë RODC λÓÚͬһվµãµÄÓû§ºÍ¼ÆËã»ú£©¡£msDS-NeverRevealGroup °üº¬ÃÜÂë믧´æÓÚ RODC ÉϵÄ×é¡¢Óû§»ò¼ÆËã»úÕÊ»§µÄ¶ÀÓÐÃû³Æ£¨ÀýÈ磬Óò¹ÜÀíÔ±ÕÊ»§¾ø²»Ó¦½«ÆäÃÜÂë¹þÏ£»º´æÓÚ RODC ÉÏ£©¡£Èç RODC ÇëÇóÌØÊâÕÊ»§µÄÃÜÂë¹þÏ££¬FDC »á¸ù¾ÝÃÜÂë¸´ÖÆ²ßÂÔÆÀ¹ÀÇëÇó£¬ÒÔÈ·¶¨ÊÇ·ñÓ¦½«ÃÜÂë¹þÏ£¸´ÖƸø RODC¡£Èç DC ʧÇÔ£¬ÔòÊܹ¥»÷µÄ¶ÔÏó½öÏÞÓÚÔÚ´ÓÍøÂç×ªÒÆÊ±ÔÚʧÇÔ RODC ÉÏ»º´æµÄÃÜÂë£¬ÖØÒªµÄÃÜÂë²»»áÊܵ½¹¥»÷¡£
RODC ¼ÆËã»ú¶ÔÏó°üº¬µÄÆäËûÁ½¸öÊôÐÔ¿ÉÒÔ°ïÄú¾«×¼È·¶¨Ó¦»º´æÆäÃÜÂëµÄÕÊ»§¡£msDS-AuthenticatedAtDC ÊôÐÔÁгö RODC ÒÑÑéÖ¤ÁËÃÜÂëµÄÕÊ»§£¬msDS-RevealedList ÊôÐÔÃüÃûÆäÃÜÂ뵱ǰÓÉ RODC ´æ´¢µÄÕÊ»§¡£
Óû§ºÍ¼ÆËã»úÃÜÂë¹þÏ£²¢²»ÊÇ DC ´æ´¢µÄÎ¨Ò»ÃØÃÜÐÅÏ¢¡£KrbTGT ÕÊ»§°üº¬ÔÚÿ¸öÓò¿ØÖÆÆ÷ÉÏÔËÐÐµÄ Kerberos ÃÜÔ¿·Ö·¢ÖÐÐÄ (KDC) ·þÎñµÄÃÜÔ¿¡£ÔÚͨ³£Çé¿öÏ£¬ÓòÖеÄÿ¸ö KDC ¹²ÏíÏàͬµÄ KrbTGT ÕÊ»§£¬ËùÒÔÓпÉÄܹ¥»÷Õß´ÓÇÔµÃµÄ DC ÉÏ»ñÈ¡ÕâЩÃÜÔ¿£¬È»ºóʹÓÃËüÃǹ¥»÷ÓòµÄÆäÓಿ·Ö¡£µ«ÊÇ£¬Èç¹ûÿ¸ö RODC ¾ùÓÐÆä×Ô¼ºµÄ KrbTGT ÕÊ»§ºÍÃÜÔ¿£¬¾Í¿É·ÀÖ¹ÕâÖÖ¹¥»÷¡£
Ó¦ÓóÌÐò»¹¾³£ÔÚ DIT Öд洢ÃÜÂë»òÆäËû»úÃÜÐÅÏ¢¡£Èç¹û¹¥»÷ÕßÇÔµÃÁË DC£¬¿ÉÄÜ»áµÃµ½ÕâЩӦÓóÌÐòÃÜÂ룬½ø¶øÓÃÆä·ÃÎÊÓ¦ÓóÌÐò¡£Îª·À·¶ÕâÀ๥»÷£¬Windows Server 2008 Óò·þÎñÔÊÐí¹ÜÀíÔ±¶¨ÒåÖ»¶Á¹ýÂËÊôÐÔ¼¯ (RO-FAS)¡£RO-FAS ÖеÄÊôÐÔ¾ø²»»á¸´ÖƵ½ RODC£¬Òò´Ë²»ÄÜ´ÓʧÇ﵀ DC ÖлñÈ¡ÕâЩÊôÐÔ¡£Í¨¹ýÉèÖù¹¼ÜÖÐÏàÓ¦ attributeSchema ¶ÔÏóµÄ searchFlags ÊôÐÔµÄµÚ 9 λ (0x0200)£¬Äú¿ÉÒÔ½«ÊôÐÔÖ¸¶¨¸ø RO-FAS¡£
ÃÅÄÚ´Öºº
·ÖÖ§»ú¹¹Óò¿ØÖÆÆ÷»áÃæÁÙµÄÁíÒ»ÀàÍþвÊDZ¾µØ·þÎñÆ÷¹ÜÀíԱͨ¹ýÀûÓà DC µÄȨÏÞÌáÉý×Ô¼ºµÄȨÏÞ£¬½ø¶ø·ÃÎÊÆäËûÓò×ÊÔ´»ò·¢Æð¾Ü¾ø·þÎñ¹¥»÷¡£Í¬Ñù£¬Èç¹û±¾µØ¹ÜÀíÔ±¿ÉÒÔʵ¼Ê½Ó´¥µ½Óò¿ØÖÆÆ÷£¬¾ÍºÜÄÑ·À·¶ÕâÀ๥»÷¡£µ«ÊÇ£¬¿ÉÒÔ·ÀÖ¹¹¥»÷Õßͨ¹ýʹÓ÷ÖÖ§»ú¹¹µÄÓò¿ØÖÆÆ÷¹¥»÷ÓòÖÐµÄÆäËû DC¡£
´ËÓòÖеÄÍêÈ« DC ²»»á½« RODC ÊÓΪÓò¿ØÖÆÆ÷ÓèÒÔÐÅÈΡ£´ÓÐÅÈνǶȽ²£¬FDC ½« RODC ÊÓΪÓòÖеijÉÔ±·þÎñÆ÷¡£RODC ²»ÊÇÆóÒµÓò¿ØÖÆÆ÷»òÓò¿ØÖÆÆ÷×éµÄ³ÉÔ±¡£RODC ¸üÐÂĿ¼ÖÐÈκÎÄÚÈݵÄÄÜÁ¦Ê®·ÖÓÐÏÞ£¬Òò´Ë¼´Ê¹¹¥»÷Õß»ñµÃÁË RODC ÕÊ»§£¬Ò²²»»áµÃµ½ºÜ¸ßµÄȨÏÞ¡£
RODC ÉõÖÁ¿ÉÄܲ»³öÏÖÔÚ DS ¸´ÖÆÍØÆËÖС£ÓÉÓÚ RODC ÀàËÆÕý³£µÄ³ÉÔ±·þÎñÆ÷£¬¶ø²»ÏóÓò¿ØÖÆÆ÷£¬ÖªÊ¶Ò»ÖÂÐÔ¼ì²éÆ÷£¨KCC£¬¸Ã½ø³ÌÔÚÿ¸ö DC ÉϸºÔð¼ÆËã DS ¸´ÖÆÍØÆË£©²»»á´Ó RODC ¹¹½¨Á¬½Ó¶ÔÏó¡£ÍêÈ« DC »ò RODC ¶¼²»»áÊÔͼ´Ó RODC ½øÐи´ÖÆ¡£ÁíÒ»·½Ã棬RODC ½«´´½¨Ò»¸ö´ú±íÔ´×ÔÍêÈ« DC ÈëÕ¾¸´ÖÆÐ¶¨µÄÁ¬½Ó¶ÔÏ󣬵«ÊÇ´ËÁ¬½Ó¶ÔÏó½ö´æÔÚÓÚ RODC ¸±±¾ÖУ¬ÆäËû DC ûÓиÃÁ¬½Ó¶ÔÏóµÄ¸±±¾¡£´Ó¸´ÖƵĽǶȣ¬RODC ÏñĿ¼¶ÔÏóµÄ Roach Motel¡£¶ÔÏóÏòÄÚ¸´ÖÆ£¬µ«²»ÏòÍâ¸´ÖÆ¡£
RODC ÉϵĹÜÀí½ÇÉ«·ÖÀë
Óɱ¾µØ·þÎñÆ÷¹ÜÀíÔ±¹ÜÀí·ÖÖ§»ú¹¹ DC ÊǺÜѰ³£µÄÏÖÏó£¬ÕâЩ¹ÜÀíÔ±×öÿÏ×÷£¬´ÓÔÚÓò¿ØÖÆÆ÷ÉÏÔËÐб¸·Ý£¬µ½ÕûÀí¼üÅÌ¡£µ«ÊÇ£¬ÊÚÓèÔ¶³ÌÕ¾µã¹ÜÀíÔ±ÔÚÓò¿ØÖÆÆ÷½øÐг£¹æÎ¬»¤Ëù±ØÐèµÄȨÏÞ»áÓа²È«·çÏÕ£¬Õ¾µã¹ÜÀíÔ±ÓпÉÄÜÌáÉýÆäÔÚÓòÖеÄȨÏÞ¡£RODC ͨ¹ýÌṩÁ½ÖÖ¹ÜÀí½ÇÉ«·ÖÀëÀ´·ÀÖ¹´ËÖÖÍþв¡£
µÚÒ»ÖÖÊÇÓò¹ÜÀíÔ±¿ÉÒÔʹÓà DCPROMO£¬ÒÔÕý³£·½Ê½ÌáÉý RODC£¬»òÕßʹÓÃÁ½¸ö²½ÖèµÄ¹ý³Ì£¬Êµ¼ÊµÄÌáÉýÁ÷³Ì°²È«µØÎ¯Åɸø·ÖÖ§Õ¾µã¹ÜÀíÔ±£¬¶ø²»ÊÚÓèÈκÎÓò¹ÜÀíȨÏÞ¡£Óò¹ÜÀíԱʹÓà Active Directory Óû§ºÍ¼ÆËã»ú MMC ¹ÜÀíµ¥ÔªÔ¤ÏÈÔÚÓòÖд´½¨ RODC ¼ÆËã»úÕÊ»§£¬Èçͼ 5 ÖÐËùʾ¡£
ͼ 5 Ô¤ÏÈ´´½¨ RODC ¼ÆËã»úÕÊ»§ (µ¥»÷¸ÃͼÏñ»ñµÃ½Ï´óÊÓͼ)
Ñ¡Ôñ¡°Ô¤´´½¨Ö»¶ÁÓò¿ØÖÆÆ÷ÕÊ»§¡±»áÔËÐо«¼òÐÍ DCPROMO£¬ËüÖ´ÐÐÒªÇóÓÐÓò¹ÜÀí·ÃÎÊȨÏÞµÄËùÓÐÈÎÎñ£¬°üÀ¨´´½¨¼ÆËã»úÕÊ»§¡¢ÏòÕ¾µãÖ¸ÅÉ RODC¡¢Ö¸¶¨ DC µÄ½ÇÉ«¡¢Ö¸¶¨ÃÜÂë¸´ÖÆ²ßÂÔ²¢¶¨ÒåÐèҪȨÏÞÀ´ÔÚ RODC ÉÏÍê³É DCPROMO ²Ù×÷µÄÓû§»ò×顣ίÅɵĹÜÀíÔ±»ò×é´æ´¢ÔÚ RODC ¼ÆËã»ú¶ÔÏóµÄ managedBy ÊôÐÔÖС£
ίÅɵĹÜÀíÔ±Ëæºó¿ÉÔÚ·þÎñÆ÷ÉÏÔËÐÐ DCPROMO¡£DCPROMO ½«¼ì²âÔ¤´´½¨µÄÕÊ»§²¢½«·þÎñÆ÷ת»¯Îª RODC¡£ÒÔ´Ë·½Ê½ÔËÐÐ DCPROMO ²»ÐèÒªÓò¹ÜÀíԱƾ¾Ý¡£
RODC Ìṩ¹ÜÀí½ÇÉ«·ÖÀëµÄµÚ¶þÖÖ·½Ê½ÊÇÔÚ RODC ±¾Éí´´½¨±¾µØ¹ÜÀí½ÇÉ«¡£ÕâЩ½ÇÉ«¿´ÆðÀ´Ïñ»úÆ÷±¾µØ×飬ËüÃÇ´æ´¢ÔÚ RODC µÄ×¢²á±íÖУ¬²¢ÇÒÖ»ÄÜÔÚ RODC ÉϽøÐÐÆÀ¹À¡£µ«ÊÇ£¬¹ÜÀíÔ±ÊÇʹÓà NTDSUTIL ¹ÜÀí±¾µØ RODC ½ÇÉ«£¬¶ø²»ÊÇʹÓüÆËã»ú¹ÜÀí MMC ¹ÜÀíµ¥Ôª¡£Í¼ 6 ÁгöÁË RODC Éϵı¾µØ¹ÜÀí½ÇÉ«¡£ÕâЩ½ÇÉ«Óë Windows ÖеÄÄÚÖÃ×éÒ»Ò»¶ÔÓ¦¡£

Figure 6 ±¾µØ RODC ¹ÜÀí½ÇÉ«
| ÕÊ»§²Ù×÷Ô± |
| Administrators |
| ±¸·Ý²Ù×÷Ô± |
| Ö¤Êé·þÎñ DCOM ·ÃÎÊ |
| ¼ÓÃܲÙ×÷Ô± |
| ·Ö²¼Ê½ COM Óû§ |
| ʼþÈÕÖ¾¶ÁÈ¡Æ÷ |
| Guests |
| IIS_IUSRS |
| ´«ÈëÁÖÐÅÈι¹½¨Æ÷ |
| ÍøÂçÅäÖòÙ×÷Ô± |
| ÐÔÄÜÈÕÖ¾Óû§ |
| ÐÔÄÜ¼à¿ØÆ÷Óû§ |
| Windows 2000 ÒÔǰ°æ±¾¼æÈÝ·ÃÎÊ |
| ´òÓ¡²Ù×÷Ô± |
| Remote Desktop Users |
| Replicator |
| ·þÎñÆ÷²Ù×÷Ô± |
| ÖÕ¶Ë·þÎñÆ÷Ðí¿ÉÖ¤·þÎñÆ÷ |
| Óû§ |
| Windows ÊÚȨ·ÃÎÊ×é |
RODC ÌØÐÔ
ÓÉÓÚ RODC ÊÇÖ»¶ÁµÄ£¬²¢ÇÒÆäËûÓò¿ØÖÆÆ÷²»´ÓÆä½øÐи´ÖÆ£¬ËüÃÇ»á³öÏÖһЩÒì³£µÄÐÐΪ¡£ÀýÈ磬ÑÓ³Ù¶ÔÏ󣨼´£¬ÒòΪ DC µÄ¸´ÖÆÊ±¼ä²»Äܳ¤ÓÚÁÖµÄÉú´æÖÜÆÚ£¬ËùÒÔ³ýÁËÌØÊâµÄ DC£¬¸ÃÀà¶ÔÏóÒÑ´ÓÆäËûλÖÃɾ³ý£©Í¨³£ÓÉ DC µÄ³öÕ¾¸´ÖÆ»ï°é¼ì²â¡£µ«ÊÇ£¬ÓÉÓÚ RODC ûÓÐÈëÕ¾¸´ÖÆ»ï°é£¬Òò¶øËüÃDz»»á¼ì²âÑÓ³Ù¶ÔÏó¡£
RODC ²»»áΪ LDAP ¸üУ¨Ìí¼Ó¡¢Ð޸ġ¢É¾³ý¡¢ÖØÃüÃû»òÒÆ¶¯£©²Ù×÷Ìṩ·þÎñ¡£¶øÊÇ·µ»Ø´íÎ󣬯äÖаüº¬¶ÔÄÜÌṩ²Ù×÷µÄ¿Éд DC µÄ LDAP ²ÎÕÕ¡£Èç¹û·¢Æð LDAP ¸üеÄÓ¦ÓóÌÐò¶Ô²ÎÕÕ²Ù×÷´¦Öò»µ±£¬Ó¦ÓóÌÐò½«ÎÞ·¨Ê¹Óá£
×îºó£¬Èç¹ûÁÖÖÐÆäËûÓòµÄÓû§ÊÔͼÏò RODC ÑéÖ¤£¬RODC ±ØÐëÄܹ»·ÃÎÊÆäËùÔÚÓòµÄÍêÈ« DC À´»ñÈ¡ÐÅÈÎÃÜÂ룬ÒԱ㽫ÑéÖ¤ÇëÇóÕýÈ·´«µÝ¸øÓû§ÓòÖÐµÄ DC¡£Èç¹ûÔÚÆäÓòÖÐ RODC ºÍÍêÈ« DC Ö®¼äµÄÍøÂçÁ¬½Ó²»¿ÉÓã¬ÑéÖ¤½«Ê§°Ü¡£
¾«×¼ÃÜÂë²ßÂÔ
ÄÜÔÚÓòÖж¨Òå¶à¸öÃÜÂë²ßÂÔ¿ÉÄÜÊÇ Windows Server 2008 ADDS ×îÊÜ»¶ÓµÄ¹¦ÄÜ¡£Äú¿ÉÄÜÖªµÀ£¬ÔÚ Windows 2000 ºÍ Windows Server 2003 Active Directory ÖУ¬Ã¿¸öÓò½öÖ§³ÖÒ»¸öÓ¦ÓÃÓÚÓòÖÐËùÓа²È«Ö÷ÌåµÄÃÜÂë²ßÂÔ¡£Èç¹ûÒ»×éÌØ¶¨Óû§ÐèÒªÒ»¸öµ¥¶ÀµÄÃÜÂë²ßÂÔ£¬Äú±ØÐë´´½¨Ò»¸öµ¥¶ÀµÄÓò¡£µ«ÏÖÔÚ Windows Server 2008 ADDS ÖÐÐÂÔöÁËÒ»ÏÄÜ£¬³ÆÎª¾«×¼ÃÜÂë²ßÂÔ£¬Äú¿ÉÒÔÓÃËüÔÚÓòÖж¨Òå¶à¸öÃÜÂë²ßÂÔ¡£
вßÂÔʹÓÃ×齫¾«×¼µÄÃÜÂë²ßÂÔÓ¦ÓÃÓÚÓû§¡£ÄúÏÈÔÚ CN=ÃÜÂëÉèÖÃÈÝÆ÷¡¢CN=ϵͳ¡¢DC=<Óò> ÈÝÆ÷Öд´½¨Ð msDS-PasswordSettings ¶ÔÏóÀ´¶¨Ò徫׼ÃÜÂë²ßÂÔ¡£msDS-PasswordSettings ¶ÔÏ󣨼ò³Æ PSO£©°üº¬Óë¡°×é²ßÂÔ¡±ÖеÄÃÜÂë²ßÂÔÉèÖÃÆ½ÐеÄÊôÐÔ£¨Çë²Î¼ûͼ 7£©¡£

Figure 7 mSDS-PasswordSettings ¶ÔÏóÖеÄÊôÐÔ
| ÊôÐÔ | ˵Ã÷ |
| mSDS-PasswordReversibleEncryptionEnabled | ָʾÊÇ·ñʹÓÃÁË¿ÉÄæ¼ÓÃܶÔÃÜÂë½øÐмÓÃܵIJ¼¶ûÖµ¡£ |
| mSDS-PasswordHistoryLength | ÃÜÂëÀúÊ·¼Ç¼ÖÐά»¤µÄÌõÄ¿ÊýÁ¿¡£ |
| mSDS-PasswordComplexityEnabled | ָʾÊÇ·ñÆôÓÃÁËÃÜÂ븴ÔÓÐÔÏÞÖÆµÄ²¼¶ûÖµ¡£ |
| mSDS-MinimumPasswordLength | ¶¨Òå×î¶ÌÃÜÂ볤¶ÈµÄÕûÊý¡£ |
| mSDS-MinimumPasswordAge | ָʾ¿ÉÒÔ¸ü¸ÄÃÜÂëǰÆä×î¶ÌʹÓÃÆÚÏÞµÄ INTEGER8¡£ |
| mSDS-MaximumPasswordAge | ָʾ±ØÐë¸ü¸ÄÃÜÂëǰÆä×ʹÓÃÆÚÏÞµÄ INTEGER8¡£ |
| mSDS-LockoutThreshold | Ö¸Ê¾Ëø¶¨Ç°Ê§°ÜµÇ¼ÊýÄ¿µÄÕûÊý¡£ |
| mSDS-LockoutObservationWindow | ָʾÄÉÃëÊýµÄ INTEGER8£¬Îª´¥·¢Ëø¶¨£¬±ØÐëÔڴ˼ä¸ôÄÚÁ¬Ðø³öÏֵǼʧ°Ü¡£ |
| mSDS-LockoutDuration | ָʾÕÊ»§Ëø¶¨ÄÉÃëÊýµÄ INTEGER8¡£ |
Ëæºó£¬Äú¿Éͨ¹ý½«Óû§»ò×éÃû³ÆÌí¼Óµ½ PSO µÄ¶àÖµ mDS-PSOAppliesTo ÊôÐÔÖÐΪÓû§»ò×éÖ¸ÅÉÃÜÂë²ßÂÔ¡£Ò»µ©Äú½ÓÊܲ»Ïò OU Ó¦ÓÃÃÜÂë²ßÂÔÕâÒ»¹ÛÄ»á·Ç³£Ò×ÓÚʵʩ¡£µ«ÔÚÆäËû·½Ã滹ÓÐһЩ¸´ÔÓ¡£
Óû§Í¨³£ÊÇÐí¶à×éµÄ³ÉÔ±¡£Òò´Ë£¬Èç¹ûÓÉÓÚÕâЩ×é³ÉÔ±¹ØÏµµ¼ÖÂÁËÓû§²úÉú¶àÏîÏ໥³åÍ»µÄÃÜÂë²ßÂÔ£¬ÄÇÓÖ½«ÈçºÎÄØ£¿ÔÚÕâÖÖÇé¿öÏ£¬ADDS ʹÓÃÓÅÏȼ¶ÆÀ¹ÀÀ´È·¶¨Ó¦ÓÃÄĸöÃÜÂë²ßÂÔ¡£Æä¹¤×÷ÔÀíÈçÏÂËùʾ£º
- Èç¹ûÃÜÂë²ßÂÔÖ±½ÓÁ´½ÓÓû§¶ÔÏ󣨶ø²»ÊÇͨ¹ý×é³ÉÔ±¹ØÏµ£©£¬½«Ó¦ÓøÃÃÜÂë²ßÂÔ¡£
- Èç¹û¶à¸öÃÜÂë²ßÂÔÖ±½ÓÓëÓû§Á´½Ó£¬½«Ó¦ÓÃÓÅÏÈȨֵ×îС£¨ÓÉ PSO µÄ msDS-PasswordSettingsPrecendence ÊôÐÔֵȷ¶¨£©µÄ²ßÂÔ¡£
- Èç¹û¶à¸ö PSO µÄÓÅÏÈȨÏàͬ£¬½«Ó¦Óà objectGUID Öµ×îСµÄÄǸö PSO¡£
- Èç¹ûûÓÐ PSO ÓëÓû§Ö±½ÓÁ´½Ó£¬ADDS ½«ÆÀ¹ÀÓëÓû§×éÏàÁ´½ÓµÄ PSO¡£Èç¹ûÓжà¸ö PSO£¬½«Ó¦Óà msDS-PasswordSettingsPrecedence ÊôÐÔÖÐÖµ×îСµÄÄǸö PSO¡£
- Èç¹û¶à¸ö PSO µÄÓÅÏÈȨֵÏàͬ£¬½«Ó¦Óà objectGUID Öµ×îСµÄÄǸö PSO¡£
- Èç¹ûûÓÐ PSO ÓëÓû§Ïà¹ØÁª£¬½«Ê¹ÓÃÓòÃÜÂë²ßÂÔ¡£
Óû§¶ÔÏóÓÐÒ»¸öÃûΪ msDS-ResultantPSO µÄÐÂÊôÐÔ£¬ÐÖú¾«È·ÅÅÐòÓ¦ÓøøÓû§µÄ PSO¡£´ËÊôÐÔ°üº¬¿ØÖƸÃÓû§ÃÜÂëµÄ PSO µÄ¶ÀÓÐÃû³Æ¡£
¾«×¼ÃÜÂë²ßÂÔ¸³ÓèÄú¸ü¶àµÄÁé»îÐÔ£¬µ«Äú±ØÐë×Ðϸ¹ÜÀí²¢¼ò»¯ÕâЩ²ßÂÔ¡£Òª¶¨Ò徫׼ÃÜÂë²ßÂÔ£¬Ã»ÓÐÏֳɵÄʵÓù¤¾ß£¬ÄúÐèҪʹÓà ADSIEdit »ò²éÕÒµÚÈý·½ÊµÓù¤¾ß¡£
¿ÉÖØÆôµÄ Active Directory Ŀ¼·þÎñ
ÿ´Î¹Ø±ÕÓò¿ØÖÆÆ÷½øÐÐ DIT ά»¤Ê±£¬¶¼»áÔÚÍøÂç·þÎñ²ãÔì³ÉһЩÖжϡ£Windows Server 2008 DC ÓÐÒ»Ïîй¦ÄÜ£¬¿ÉÒÔÈÃÄú²»±ØÍêÈ«¹Ø±Õ DC ¾ÍÐÐֹͣĿ¼·þÎñ¡£
ÔÚ Windows Server 2008 DC ÉÏʹÓà NET STOP NTDS ÃüÁîÀ´ÖÐÖ¹ ADDS¡£Ö´Ðд˲Ù×÷ʱ£¬DC Éϵı¾µØ°²È«»ú¹¹ (LSASS) ¼ÌÐøÔËÐУ¬µ«Ëü»áÐ¶ÔØËùÓÐÓë ADDS Ïà¹ØµÄ DLL£¬Òò´ËÎÞ·¨ÔÙʹÓÃĿ¼·þÎñ¡£LSASS Ëæºó½«ÓòÑéÖ¤ÇëÇóת·¢¸ø DC£¬Æä²Ù×÷·½Ê½Óë³ÉÔ±·þÎñÆ÷²¢ÎÞ¶þÖ¡£ÓÉÓÚÐ¶ÔØÁË´¦Àí ADDS µÄ DLL£¬Äú¿ÉÒÔÓ¦ÓÃÓë ADDS Ïà¹ØµÄ²¹¶¡³ÌÐò£¬»òÖ´ÐÐÀëÏß DIT Ë鯬ÕûÀí¡£ADDS µÄÆô¶¯Óë NET START NTDS Ò»Ñù¼òµ¥¡£µ«ÊÇ£¬´Óϵͳ״̬±¸·Ý»Ö¸´ DIT ÈÔÐèÒªÄúÖØÐÂÆô¶¯£¬È»ºó½øÈëĿ¼·þÎñÐÞ¸´Ä£Ê½¡£
ÄúÐèÒªÖªÏþĿ¼·þÎñ²¢²»ÊÇÕæÕýµÄ Windows ·þÎñ¡£ËüÈÔÊÇ LSASS µÄÒ»¸ö¹¹³É×é¼þ£¬²»¹Ø»ú£¬ÄúÎÞ·¨Í£Ö¹ LSASS¡£µ«ÊÇÔÚ Windows Server 2008 ÖÐÆô¶¯ºÍֹͣĿ¼·þÎñ·Ç³£±ãÀû¡£
±¸·ÝºÍ»Ö¸´
Windows Server 2008 ÖжÔÕû¸ö±¸·ÝºÍ»Ö¸´»úÖÆ½øÐÐÁËÐ޸ġ£ÕâÀïÎÒ²»ÏëÒ»Ò»ÀÛÊö£¬µ«Ð嵀 Windows Server ±¸·ÝÓÐһЩ¸ü¸ÄÓ°Ïìµ½ÁË ADDS¡£
Windows Server ±¸·ÝÊÇÒ»¸ö»ùÓÚ¾íµÄ±¸·Ý½â¾ö·½°¸£¬ÕâÒâζ×ÅËüÒ»´Î±¸·ÝÕû¸ö´ÅÅÌ¾í¡£ÁíÍ⣬Ëü½ö±¸·Ýµ½´ÅÅÌ£¨»òÀàËÆ´ÅÅÌ£©É豸£¬²»Ö§³Ö´Å´ø¡£
WBADMIN ÃüÁîÐб¸·ÝʵÓù¤¾ßÓÐÒ»¸öϵͳ״̬±¸·ÝÑ¡ÏʹÓà WBADMIN START SYSTEMSTATEBACKUP ÃüÁÄúÏÖÔÚ¿ÉÒÔ´´½¨±¸·ÝÓ³Ïñ£¬ÆäÖаüº¬ÔÚÓò¿ØÖÆÆ÷»Ö¸´ Active Directory ËùÐèµÄÈ«²¿ÖØÒªÏµÍ³Îļþ¡£ÕâÑù£¬±¸·Ý¼¯ÖÐ×î¶à¿ÉÒÔÓÐÎå¸ö¾í£¬µ«Ã¿¸ö¾íÖ»°üº¬»Ö¸´ÏµÍ³×´Ì¬ËùÐèµÄÎļþ¡£¸üÓÐЩÄÕÈ˵ÄÊÇ£¬´Ó Windows Server 2008 µÄ RC0 Æð£¬ÄúÎÞ·¨¶ÔÍøÂç¹²ÏíÖ´ÐÐϵͳ״̬±¸·Ý¡£Äú±ØÐëÓпɹ©ÏµÍ³×´Ì¬±¸·ÝÓ³ÏñʹÓõı¾µØ´ÅÅÌ¾í£¬ÇÒ¸Ã¾í²»ÄÜÊÇϵͳ״̬±¸·Ý¾í¼¯µÄÒ»²¿·Ö¡£¶ÔÓÚÄúÒª½øÐÐϵͳ״̬±¸·ÝµÄÿ¸öÓò¿ØÖÆÆ÷£¬Äú¿ÉÄܱØÐëÏòÆäÐÂÌí¼ÓÒ»¸ö´ÅÅÌ¾í¡£
ϵͳ״̬»¹Ô·Ç³£¼òµ¥¡£Ö»Ð轫 DC Òýµ¼ÎªÄ¿Â¼·þÎñ»¹Ôģʽ£¬È»ºóÔËÐÐ WBADMIN START SYSTEMSTATERECOVERY ÃüÁî¼´¿É¡£Õ⽫²úÉú·ÇȨÍþ»¹ÔµÄ DIT£¬Äú¿ÉÔÚÆäÖÐʹÓà NTDSUTIL ¶ÔÌØ¶¨¶ÔÏóÖ´ÐÐȨÍþ»¹Ô£¬¾ÍÏñÔÚ Windows Server 2003 ÖÐÒ»Ñù¡£
Windows Server ±¸·ÝÖеÄÒ»¸ö·½ÃæÐèÌØ±ð×¢Ò⣺ËüÒÔÐéÄâÓ²ÅÌ (VHD) ¸ñʽ´æ´¢±¸·ÝÓ³Ïñ¡£Microsoft Virtual Server 2005 ҲʹÓÃÕâÖÖ¸ñʽ´æ´¢ÆäÐéÄâ´ÅÅÌÓ³Ïñ¡£Õâ±íʾÄú¿É»ñÈ¡Óà Windows Server ±¸·Ý´´½¨µÄ±¸·ÝÓ³Ïñ£¬ÔÚ Microsoft Virtual Server ÏÂÔËÐеÄÐéÄâ»úÖн«Æä°²×°³ÉÒ»¸ö´ÅÅÌ¡£È»ºó¾ÍÏñÕý³£´ÅÅÌÒ»Ñùä¯ÀÀ±¸·ÝÄÚÈÝ¡£
ADDS ±¸·ÝµÄÁíÒ»Ïî¸ü¸ÄÊÇ¿ÉÒÔʹÓá°¾íÓ°¸´ÖÆ·þÎñ¡±´´½¨ Active Directory µÄʱ¼äµã¿ìÕÕ¡£Ê¹Óà NTDSUTIL ´´½¨¿ìÕÕʱ£¬¡°¾íÓ°¸´ÖÆ·þÎñ¡±ÔÚÿ¸ö´ÅÅ̿鱻¸üвÙ×÷¸²¸Çǰ£¬±£´æÆä¸üÐÂǰµÄÓ³Ïñ¡£Í¨¹ý½«±£´æµÄ¸üÐÂǰӳÏñÓë DIT µÄµ±Ç°°æ±¾×éºÏÔÚÒ»Æð£¬¡°¾íÓ°¸´ÖÆ·þÎñ¡±¿ÉÓü«Ð¡µÄ¿ªÏú¹¹½¨ÍêÕûµÄ DIT ¿ìÕÕ¡£ÎÞÂÛ DIT µÄ´óСÈçºÎ£¬´´½¨µäÐ͵ĿìÕÕÖ»Ð輸Ãë¡£
¾ÍÆä±¾Éí¶øÑÔ£¬ÕâÊÇÒ»ÏîÓÐȤµÄ¹¦ÄÜ£¬µ«²¢·Ç×ÜÊÇÄÇÑùÓÐÓᣵ«ÊÇ£¬ÔÚ Windows Server 2008 ÖУ¬ADDS ÄÉÈëÁËÒ»¸ö³ÆÎª DSAMAIN µÄÃüÁîÐÐʵÓù¤¾ß£¬ËüÒÔÖ»¶Áģʽ°²×°¿ìÕÕÓ³Ïñ¡£ÕâÑù¾ÍÌṩÁËÒ»¸ö¶ÀÁ¢ LDAP ·þÎñÆ÷£¬ËüºÜÏóÔÚ¿ìÕÕʱ°üº¬Ä¿Â¼ÄÚÈÝµÄ ADLDS ʵÀý¡£Äú¿ÉʹÓà LDP ʵÓù¤¾ß»òÆäËû LDAP ¹¤¾ßä¯ÀÀĿ¼£¬²¢´ÓÏÈǰµÄʱ¼äµã¼ìË÷Ŀ¼¶ÔÏóµÄ°æ±¾¡£
ʹÓà DFS-R ¸´ÖÆ SYSVOL
Windows Server 2003 R2 ´øÓÐÒ»¸ö¸ÄÁ¼µÄ·Ö²¼Ê½Îļþ·þÎñ (DFS)£¬ÆäÖÐÒý½øÁ˳ÆÎª DFS-R µÄÈ«ÐÂÎļþ¸´ÖÆ»úÖÆ¡£ËüʹÓõÄÊÇÔ¶³Ì²î·ÖѹËõ£¬ÕâÖÖ·½Ê½Í¨¹ýÈ·¶¨ÐèÒª¸´ÖÆÄÄЩĿ±êÎļþ¿éÀ´ÓëÔ´Îļþͬ²½£¬¼«´óµØ¼õÉÙÁËÎļþ¸´ÖÆÁ÷Á¿¡£µ«ÊÇ£¬Windows Server 2003 R2 ÈÔʹÓÃÎļþ¸´ÖÆ·þÎñ£¨¶ø²»ÊÇ DFS-R£©ÔÚÓò¿ØÖÆÆ÷Ö®¼ä¸´ÖÆ SYSVOL¡£Òò´Ë£¬SYSVOL ¸´ÖÆ»¹ÊÇ Active Directory ¹ÜÀíÔ±µÄÎÊÌâÖ®Ô´¡£
ÔÚ Windows Server 2008 Óò¹¦Äܼ¶ÔËÐÐʱ£¬Windows Server 2008 ʹÓà DFS-R ¸´ÖÆ SYSVOL£¬Ìá¸ß SYSVOL ¸´ÖƵÄËٶȺÍÇ¿¶È¡£Õâ¾Í¿ÉÒÔ½«´óÐÍÎļþ·ÅÈë SYSVOL£¬¹©ËùÓÐ DC ʹÓá£Òª½« DFS-R ÓÃÓÚ SYSVOL£¬±ØÐëÏÈʹÓà DFSRMIG ʵÓù¤¾ß½«¾É SYSVOL Êý¾ÝÇ¨ÒÆÖÁ DFS-R¡£´Ë¹ý³Ì°üÀ¨Ëĸö²½Ö裺
- ´´½¨ DFS-R. ËùÐèµÄ Active Directory ¶ÔÏó¡£
- ÔÚÿ¸öÓò¿ØÖÆÆ÷ÉÏΪ SYSVOL н¨Îļþ½á¹¹¡£
- ת»»ËùÓÐÓò¿ØÖÆÆ÷ÒÔʹÓÃÐ嵀 SYSVOL¡£
- ɾ³ý¾ÉµÄ SYSVOL¡£
´Ë¹ý³Ì¿ÉÄÜ»¨µã¶ùʱ¼ä£¬¾ßÌåÊÓ SYSVOL µÄ´óСºÍÓò¿ØÖÆÆ÷µÄÊýÁ¿¶ø¶¨£¬µ«ÐÔÄܺͿɿ¿ÐÔµÄÌá¸ßÍêȫֵµÃΪ´Ë»¨·Ñʱ¼ä¡£
É󼯏Ľø
Windows Server 2003 ÖÐ Active Directory µÄÉó¼ÆÏµÍ³¾ßÓÐË«ÖØÐ§Ó¦¡£Ò»·½Ã棬ËüΪ׷×ÙĿ¼Öеĸü¸ÄÌṩÁ˼«ÆäÈ«Ãæ¡¢Áé»îºÍ°²È«µÄ½â¾ö·½°¸¡£µ«ÊÇÒ²ÓÐÊÂÀý·´Ó³Óöµ½Ä³Ð©ÑÏÖØµÄʹÓÃÐÔÎÊÌâ¡£
ÔÚ Windows Server 2003 Óò¿ØÖÆÆ÷ÉÏÆôÓÃĿ¼¸ü¸ÄÉó¼Æ·Ç³£ÀàËÆ¡°È«ÓС±»ò¡°È«ÎÞ¡±£¬Ëü»òÕ߯ôÓ㬻òÕß½ûÓ᣷±Ã¦ÆóÒµ DC ÉϵÄÉó¼ÆÁ÷Á¿¿ÉÄÜʹÉ󼯱äµÃ²»ÊµÓá£Í¨¹ý¸Ä±äµ¥¸öµÄ°²È«ÃèÊö·ûÅäÖÃÉó¼ÆÏµÍ³£¬Ê¹ÆäÉú³ÉÄúÕæÕýÐèÒªµÄÐÅÏ¢¼È·ÑÁ¦£¬ÓÖÈÝÒ׳ö´í¡£Éó¼ÆÐÅÏ¢±¾Éí¾³£º¬ÒåÄ£ºý£¬²¢ÇÒËùº¬µÄÐÅÏ¢³£³£ÊÇÄú²»ÐèÒªµÄ£¬ÀýÈçÊôÐԱ仯ǰºóµÄÖµ¡£Ê¹Óà Windows ×Ô´øµÄ¹¤¾ß´Ó¶à¸öÓò¿ØÖÆÆ÷ÊÕ¼¯¡¢¹ØÁª²¢´æµµÐÅÏ¢²»Ì«ÏÖʵ¡£
Windows Server 2008 ÖеÄĿ¼·þÎñÉó¼ÆÏµÍ³½â¾öÁËһЩÕâÑùµÄÎÊÌâ¡£Ê×ÏÈ£¬Ä¿Â¼·þÎñÉó¼ÆÐÂÔöÁËËĸöÉó¼Æ×ÓÀࣺDS ·ÃÎÊ¡¢DS ¸ü¸Ä¡¢DS ¸´ÖƺÍÏêϸµÄ DS ¸´ÖÆ¡£Èç¹ûÄúÖ»ÏëÉó¼ÆÄ¿Â¼¸ü¸Ä£¬²»±Ø·ÑÁ¦²é¿´ËùÓжÁÈ¡ºÍ¸´ÖÆÊ¼þ¡£µ«ÊÇ£¬Èç¹ûÄúÏëÔÚÉó¼ÆÈÕÖ¾Öаüº¬¶ÔÏóɾ³ý£¬Äú±ØÐëÆôÓà DS ·ÃÎÊ¡£Õâ»áÉú³ÉËùÓÐ DS ¶ÔÏó·ÃÎʵÄÐÅÏ¢£¬±¾ÖÊÉÏÕ⻹ÊÇÉú³ÉÁ˹ý¶àµÄÐÅÏ¢²¢ÇÒÈÔÊÇÓÉÄúÅäÖð²È«ÃèÊö·ûÀ´ÎªÄú¹ØÐĵĶÔÏóÉú³ÉËùÐèµÄÐÅÏ¢¡£
Éó¼ÆÐÅÏ¢Òѵõ½Á˳ä·ÖÕûÀí£¬ËùÒÔËüÃǼÈÄܶÁÈ¡£¬ÓÖ°üº¬ÄúËùÐèµÄÊý¾Ý¡£ÌرðÊÇ£¬Ä¿Â¼¸ü¸ÄÉú³É°üº¬±ä»¯ÊôÐÔоÉÖµµÄÉó¼ÆÈÕÖ¾ÌõÄ¿¡£ÕâÊÇÒ»¸ö¾Þ´óµÄ¸Ä½ø¡£Î¨Ò»µÄ²»×ãÊÇоÉÖµÏÔʾÔÚ²»Í¬µÄÉó¼ÆÈÕÖ¾ÌõÄ¿ÖУ¬Òò´ËÄú±ØÐ뽫ËüÃǹØÁªÆðÀ´²ÅÄÜÕæÕýÀí½âËù×öµÄ¸ü¸Ä¡£Ðí¶à¼ÓÔØÏîÉó¼ÆÈÕÖ¾ÊÕ¼¯²úÆ·£¨°üÀ¨ Microsoft Éó¼ÆÊÕ¼¯·þÎñ£©¾ùÖ§³ÖÕâÀà¹ØÁª¡£
UI ¸Ä½ø
Active Directory Óû§ºÍ¼ÆËã»ú¡¢Õ¾µãºÍ·þÎñ£¬ÒÔ¼°ÓòºÍÐÅÈÎ MMC ¹ÜÀíµ¥Ôª¶ÔÓÚ¹ÜÀí Active Directory ¶øÑÔͨ³£×ã¹»ÁË¡£ÔÚ Windows Server 2008 ÖУ¬»ù±¾¹ÜÀí¹¤¾ßÒѵõ½ÕûÀí£¬²¢ÒýÈëÁËÒ»×éÉϳ˵Äй¦ÄÜ¡£Èç¹ûÄúÆôÓø߼¶¹¦ÄÜ£¬Ã¿¸ö¶ÔÏóµÄÊôÐÔ¶Ô»°¿ò»á¶îÍâÏÔʾһ¸öÑ¡Ï£¬ÃûΪ¡°ÊôÐÔ±à¼Æ÷¡±¡£ADSIEdit ҲʹÓÃÕâ¸öÊôÐÔ±à¼Æ÷Ñ¡Ï£¬Äú¿ÉÓÃËü¼ì²é²¢±à¼¶ÔÏóµÄËùÓÐÊôÐÔ¡£¸ÃÑ¡Ï±¾ÉíÏÖÔÚ¿ÉÒÔ¶ÔÒѱàÂëµÄÊôÐÔ£¨ÀýÈç userAccountControl ÊôÐÔ£©½øÐÐЧ¹û¸üºÃµØ½âÂ롣ͼ 8 ÏÔʾÁËÎ޷켯³ÉÊôÐÔ±à¼Æ÷µÄ·½Ê½¡£
ͼ 8 Active Directory Óû§ºÍ¼ÆËã»úÖеÄÊôÐÔ±à¼Æ÷ (µ¥»÷¸ÃͼÏñ»ñµÃ½Ï´óÊÓͼ)
½áÊøÓï
³ýÁËÎÒÔÚ±¾ÎÄÖÐËùÌÖÂ۵Ĺؼüµã£¬Windows Server 2008 ÖÐµÄ ADDS »¹ÓÐÐí¶àÆäËû¸Ä½ø¡£ÀýÈ磬Èç¹ûÓò´¦ÓÚ Windows Server 2008 ÓòµÄ¹¦Äܼ¶£¬KDC ʹÓà 256 λµÄ¸ß¼¶¼ÓÃܱê×¼ (AES-256)¡£Í¨¹ýÑ¡ÖÐÈκΠDS ¶ÔÏóµÄ¡°¶ÔÏó¡±Ñ¡ÏÉϺÏÊʵĸ´Ñ¡¿ò£¬¿ÉÒÔÆôÓöÔÏóµÄ¡°ÒâÍâɾ³ý·À»¤¡±¡£ÌṩÊý¾Ý¹ÜÀí·þÎñµÄ¡°¿ÉÀ©Õ¹´æ´¢ÒýÇæ¡±Òѵõ½¸Ä½ø£¬¿ÉÒÔʹÓõ¥Ò»Î»ÊýµÄ´íÎóÐÞÕý£¬ÔÚ DIT ³öÏÖ¹ÊÕÏʱ£¬¼õСÁË´ÅÅÌ×Óϵͳ²úÉúÓ²¼þ»òÈí¼þ´íÎóµÄ¿ÉÄÜÐÔ¡£DNS ·þÎñÔÚÍêÈ«¼ÓÔØ DNS Êý¾Ý¿âǰ¿ªÊ¼´¦ÀíÇëÇó¡£DC Locator Ä£¿éÒѾÔöÇ¿£¬Òò´Ë£¬Èç¹ûËüδÄÜÔÚËùÐèµÄÕ¾µãÕÒµ½ DC£¬½«³¢ÊÔÔÚ×î½üµÄÕ¾µãÕÒµ½ DC£¬¶ø²»ÊǽöʹÓÿÉÒÔÔÚÓòÖÐÕÒµ½µÄÈÎÒâ DC¡£NTDSUTIL ÏÖÔÚÖ§³Ö RODC ºÍ¾íÓ°¸´ÖÆ·þÎñ¿ìÕÕ¡£
ºÁÎÞÒÉÒ壬Windows Server 2008 ¶Ô Active Directory Óò·þÎñ×ö³öÁËÏ൱¶àµÄ¸Ä½ø¡£ÔÚËüÃǵĹ²Í¬×÷ÓÃÏ£¬ADDS µÄ°²È«ÐԺͿɹÜÀíÐԵõ½Á˼«´óµÄ¸ÄÉÆ¡£×î³öÉ«µÄÊÇ£¬½« Windows Server 2008 ¼¯³Éµ½ÄúµÄ Active Directory »·¾³Öв»Éæ¼°¾Þ´óµÄÇ¨ÒÆ£¬Õû¸ö¹ý³ÌÊôÓÚÔöÁ¿¸ü¸Ä£¬·Ç³£¼òµ¥¡£
Gil Kirkpatrick ÊÇ NetPro µÄ CTO£¬Ëû×Ô 1996 ÄêÆð±ãÒ»Ö±²ÎÓ뿪·¢ Active Directory Èí¼þ¡£ËûÓëÀ´×Ô HP µÄ Guido Grillenmeier Ò»Æð´´°ìÁ˹ãÊÜ»¶ÓµÄ Active Directory ÔÖÄѻָ´Ñ§Ï°°à¡£Gil »¹ÊÇĿ¼ר¼Ò»áÒ飨Çëתµ½ www.dec2008.com£©µÄ´´Ê¼ÈË¡£