home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






SID Stalking: Cloning Windows NT

By Jonathan Feldman  Microsoft tells you not to take a particular action, and that if you do, you risk being branded an "unsupportable" site. Do you do it anyway? Your impulse may be to say "no," but network managers say "yes" every day when they roll out Windows NT via drive duplication. Despite Microsoft's stance, half a dozen vendors are doing a brisk business these days selling drive-duplication products. For many network managers, the ability to duplicate a workstation in minutes--as opposed to installing one in hours--far outweighs the risk of being denounced as an untouchable.

The problem with the Microsoft-sanctioned method of rolling out NT is that it requires skilled staff to configure and maintain unattended Windows NT setup files. Microsoft provides a 128-page document that details unattended NT setups, and any reasonably skilled technician can wade through it and get results. However, deploying a workstation without applications, and, for that matter, testing the setup file, usually takes from 20 to 45 minutes. Compare this with taking a functioning workstation and conducting a 10-minute drive duplication with easy-to-use software. Multiply the time differential by hundreds of workstations, and it's easy to see why duplication is a compelling option.

To make an informed decision about whether to duplicate Windows NT or use the more cumbersome and complex install methods, you should read Microsoft's position, detailed in Knowledge Base Article Q162001 (support. microsoft.com/support/ kb/articles/q162/0/01.asp). In a nutshell, Microsoft does not support duplicated workstations because each NT workstation should have a unique SID (Security ID).

Obviously, straight duplication of a specific workstation will result in both workstations having the same SID. Fortunately, duplication lets you easily create a unique workstation SID using a SID generator either during or after duplication. After one of these tools is used, a correctly duplicated NT workstation is indistinguishable from an installed NT workstation.

After pilot tests prove to network managers that duplication works if it is done correctly, the decision often is not whether to duplicate, but which duplication technologies and techniques to use. With this in mind, we tested SID generators from KeyLabs, Micro House International, PowerQuest Corp., Symantec Corp. and Systems Internals.

Besides discovering that not all SID generators are created equal, we found that some tools can cut down on postduplication technician error by automatically assigning specific machine names and IP addresses. We were impressed with features like image multicasting, and found that the ability to compress, write directly to tape and span image files can help with long-term image storage. Licensing for many of the more sophisticated packages is per workstation duplicated, so check licensing policies before purchasing. Some packages let you license per technician, which can significantly cut costs.

Although Microsoft's officially sanctioned deployment methods do work, they require that you become familiar with the structure of .INF files. Also, an automated setup can take three times as long as a straight duplication. Bottom line: Duplication always takes less time and is far less complex. Combine an initial duplication rollout with software deployment tools, and you've got a one-two punch that will streamline rollouts and future upgrades.

That Vicious SID Other vendors don't ban duplication of their operating systems; for example, IBM Corp.'s AIX supports the creation of a bootable system backup that can be used as a deployment tool as well. Of course, most other operating systems don't use specific software-generated identifiers. So the question is, what's the big deal about the SID?

Empirical evidence shows that SID duplication is not actually such a big deal; before SID generators were available, we saw large installations of NT 4.0 workstations that worked without problems. These workstations weren't part of an NT domain; instead, they were using Novell's IntranetWare Client32 with Workstation Manager, which allowed them to authenticate via NDS rather than an NT domain. We've also seen clients that work just fine after being disk-duplicated, then joined to an NT domain.

According to Microsoft's Q162001, a standalone NT workstation generates a "statistically unique" SID on its first bootup to GUI mode. It then creates users and groups based on the computer's SID. That is, each computer has a unique number, and each user number is concatenated to the computer number, resulting in a fully qualified user SID. For example, if your computer number is 32768 and your user number on that computer is 1001, your fully qualified SID would be 32768-1001. In real life, the computer IDs are 48-bit quantities, meaning that the chances of duplication are very slim.


Related Links

Which Duplication Method Is Right For You?
July 1, 1997


Other Workshops

Network Address Translation: Hiding in Plan Sight
By Mike Fratto

Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page


e-mail E-mail this URL






Looking for a new job?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
The tumbling of IT jobs stopped in the second quarter, as the IT sector added about 44,000 jobs.

It's just a glimmer, but Oracle is starting to see a bit of light at the end of the recession tunnel.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service