<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx</link><description>I had this discussion with a fellow PFE David Gregory , who use to be out of Chicago but now has moved to a better place (read Southern California), at a Polo Loco in Compton, CA. The same one 2Pac rapped about, you know the one I'm talking about. This</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3544332</link><pubDate>Sun, 06 Jan 2013 11:18:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3544332</guid><dc:creator>Server Engineer</dc:creator><description>&lt;p&gt;Excellent Post!.. Title is catchy.. ;) &lt;/p&gt;
&lt;p&gt;Mohan R&lt;/p&gt;
&lt;p&gt;Server Engineer&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3544332" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3535252</link><pubDate>Wed, 28 Nov 2012 14:55:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535252</guid><dc:creator>Mark Morowczynski [MSFT]</dc:creator><description>&lt;p&gt;@Megoon&lt;/p&gt;
&lt;p&gt;This would be expected behavior as the KCC will remove any of your converted manual site links that are not needed. If they are needed it will continue to use them. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535252" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3535220</link><pubDate>Wed, 28 Nov 2012 11:43:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535220</guid><dc:creator>megoon</dc:creator><description>&lt;p&gt;@megoon&lt;/p&gt;
&lt;p&gt;without running repadmin /kcc the connection had been changed to &amp;lt;automatically created&amp;gt;.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535220" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3535219</link><pubDate>Wed, 28 Nov 2012 11:40:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3535219</guid><dc:creator>megoon</dc:creator><description>&lt;p&gt;For one site where the dc a w2k3 this works. For the other site with the dc w2k8r2 the manually created connection disappears after running repadmin /kcc. Any idea? Thanks!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3535219" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3529355</link><pubDate>Mon, 29 Oct 2012 14:25:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529355</guid><dc:creator>Mark Morowczynski [MSFT]</dc:creator><description>&lt;p&gt;That&amp;#39;s how I like to do it but you don&amp;#39;t have to. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529355" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3529353</link><pubDate>Mon, 29 Oct 2012 14:17:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529353</guid><dc:creator>MichaelHynek</dc:creator><description>&lt;p&gt;Thanks Mark. There are a lot if issues at play. The big plan is to move to fresh 2012 dcs and stop mucking with the settings so much.&lt;/p&gt;
&lt;p&gt;As they upgrade the DCs to 2012, (because thats the big plan here), should we make the first new 2012 the FSMO master?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529353" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3529352</link><pubDate>Mon, 29 Oct 2012 14:03:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529352</guid><dc:creator>Mark Morowczynski [MSFT]</dc:creator><description>&lt;p&gt;Michael, &lt;/p&gt;
&lt;p&gt;If you follow this post, if you flip them from Manual to managed by the KCC, the KCC will then delete them if they are not necessary. However if you do want to delete them your method is fine. The KCC runs every 15 minutes or you can force it by running repadmin /kcc. The time issue you state is correct if the time source is set to NT5DS for domain hierarchy these may not be configured this way. I&amp;#39;m not familiar with that kerberos error. &amp;nbsp;You may want to open a case. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529352" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3529338</link><pubDate>Mon, 29 Oct 2012 13:15:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529338</guid><dc:creator>MichaelHynek</dc:creator><description>&lt;p&gt;Kerberos error ID 3, error code 0x7 KDC_ERR_S_PRINCIPAL_UNKNOWN, error text: &amp;quot;File:9 Line:b22 Error Data is in record data.&amp;quot; &lt;/p&gt;
&lt;p&gt;This link says I can ignore, but I&amp;#39;m not certain I like that answer&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/dd811c65-fe12-4113-868f-60bbc1cde995"&gt;social.technet.microsoft.com/.../dd811c65-fe12-4113-868f-60bbc1cde995&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529338" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3529335</link><pubDate>Mon, 29 Oct 2012 13:04:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529335</guid><dc:creator>MichaelHynek</dc:creator><description>&lt;p&gt;Mark,&lt;/p&gt;
&lt;p&gt;Well, all the fsmo roles were moved from server 02 to 02A . Looking at the fsmo role report (aduc/addt) at each domain controller, they all report that server 02A is now the fsmo master. I restart the time service on each of the domain controllers and they all want to sync on 02, even server 02A (the pdc emul) will sync to 02. They should all sync to 02A the new PDC emulator and server 02A will get time from clock until you configure it for external ntp source. There will also be a warning in system event log about configuring the server to external time.&lt;/p&gt;
&lt;p&gt;Hope that resolves confusion with that.&lt;/p&gt;
&lt;p&gt;What is the best method for deleting the manual connection object and then forcing the KCC to generate a new connection object. I&amp;#39;ve had the most luck doing it at the server console I am modifying sites and services for. For example, if i were to destroy the manual connection objects on server 4, I would RDP onto server 4 and do this work. What&amp;#39;s your technique?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529335" width="1" height="1"&gt;</description></item><item><title>re: You Are Not Smarter Than The KCC</title><link>http://blogs.technet.com/b/markmoro/archive/2011/08/05/you-are-not-smarter-than-the-kcc.aspx#3529091</link><pubDate>Fri, 26 Oct 2012 20:04:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3529091</guid><dc:creator>Mark Morowczynski [MSFT]</dc:creator><description>&lt;p&gt;Michael,&lt;/p&gt;
&lt;p&gt;Lot going on there. Sounds to me like manual COs are not the biggest concern. What types of kerberos errors? I&amp;#39;m also confused you say that all servers see the new FSMO role master but are still getting time from the old one? &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3529091" width="1" height="1"&gt;</description></item></channel></rss>