Slashdot Mirror


Active Directory on Win2k or 2k3?

lordbry asks: "I am a Windows admin for a major university in a business computing area (if we have problems, people might not get paid). We have a Windows NT Domain, and are planning to migrate to Active Directory. One of my co-workers is pushing for doing this under Windows 2003. I, however, feel that (as with any M$ product) we should not even consider using 2003 for production anything until there is an SP 2 or 3, and that we should go with AD under Windows 2000. Does anyone have any advice, arguments, or horror stories that could help me make my case to the rest of my group, all of whom are somewhere in the middle? Does anyone think that 2003 is the way to go?"

105 comments

  1. Don't believe the hype. by sethadam1 · · Score: 5, Insightful

    Windows 2003 is 1000 times better than 2000. It's signficantly more stable, it's got the fantastic volume shadow copy (kinda like CVS...kinda), it's got DFS, and it's extremely well supported.

    Don't think of it like a new Windows - it's actually Windows NT 5.2, which is heavily built upon 2000.

    1. Re:Don't believe the hype. by packetknife · · Score: 2, Insightful

      Did you actually get FRS working on large volumes without eating itself? I ended up with problems with permissions and stability of the service. No lost data but it wasn't staying up on our larger volumes (> 100GB). Any pointers? -Pk

    2. Re:Don't believe the hype. by bergeron76 · · Score: 1

      Windows 2003 is 1000 times better than 2000

      Isn't it also 1000 times the price?

      (no joke, isn't it significantly more expensive?)

      --
      Don't think that a small group of dedicated individuals can't change the world. It's the only thing that ever has.
    3. Re:Don't believe the hype. by Jeremiah+Cornelius · · Score: 3, Informative
      CALs (Client Acces Licenses) are priced differently with 2003.

      Owning a 2000 WS or XP Pro license no longer counts as a server CAL for 2003 - you need also to buy a CAL for that station, on top of OS price.

      That said, 2003 is definitely what 2000 was supposed to be. You are worried about service packs? I would look at 2003 as the 3rd rev of 2000. The directory scales better times 1000 - and is massively more flexible in configuration, especially if you are interoperationg with non-MS Kerberos realms. Plus, you get ADAM, constrained and granular delegation of Kerb IDs, a built-in firewall, etc.

      Really, it's hard to know where to start on the advantages.

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    4. Re:Don't believe the hype. by sharkey · · Score: 1
      Owning a 2000 WS or XP Pro license no longer counts as a server CAL for 2003 - you need also to buy a CAL for that station, on top of OS price.

      That's the way it's been for years (Since NT 4 at least). You pay for Server OS, Client OS and CAL to use Windows server, Windows Professional and connect one to the other.

      The difference is in base price )Windows 2003 Standard w/5 CALs retails for about US $100 more than Windows 2000 Server Standard w/5 CALs) and in Terminal Services licensing (Win2k and XP Pro "include" a CAL for Windows 2000 TS, but you have to buy CALs for Win2003 TS).

      --

      --
      "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
    5. Re:Don't believe the hype. by Samhaine · · Score: 1

      Universities get VERY preferential pricing. (Think full Office Premium licenses for under $70 US)

    6. Re:Don't believe the hype. by Anonymous Coward · · Score: 4, Informative
      Sorry for posting this anonymously but I cannot legally speak for my company. We are a major worldwide bank and after months of testing (including Microsoft) we went with 2003 and haven't looked back.

      I admit my first reaction was "Global infrastructure on a service pack 0 platform ????" but after spending some time on the system my view changed entirely.

      Go with w2k3. You won't regret it.

      ps I am personally responsible for finding bugs that some of the hotfixes fix ;-)

    7. Re:Don't believe the hype. by weave · · Score: 3, Informative
      Just to throw this out, 2003 server doesn't play nice with kerberos 1.2.7 that is under RHEL 3. What makes it weirder is that it sometimes will auth with some people, and not others. So in a small test environment it will probably work well.

      The problem is that windows 0003 server's kerberos server will use tcp to send out large bits of data, like allegedly when a user is a member of a lot of groups. Kerberos 1.2 only uses udp.

      Kerberos 1.3 (used in Fedora) works just fine. We were able to get the Kerberos 1.3 source RPMs to compile under RHEL 3 but also had to get an updated e2fsprogs rpm and hand do a symlink for a library due to a minor version mismatch.

      OK, this may not apply to you but maybe someone reading this who has their RHEL boxes auth against AD in 2000 server may benefit.

    8. Re:Don't believe the hype. by ElForesto · · Score: 1

      It's the licensing costs that have me scrambling to find an alternative to our Windows-only call center software. We're standardized on Win2K now, and I like the per-concurrent-connection licensing scheme. It's easy to figure out and cheap to implement. I couldn't figure out how many of which Win2K3 licenses to buy with a team of lawyers and engineers.

      --
      There is a difference between "insightful" and "inciteful" other than spelling.
    9. Re:Don't believe the hype. by Anonymous Coward · · Score: 0

      Again as the AC (sorry - I signed so much legalese when I joined the company).

      We are planning for over quarter of a million users. Our OU structure took some months to design (probably the longest part of the design) but with the testing we did, we know it's going to work.

      As for the DC-DC repl, it's spot on. FRS has given us one problem only and that was a trivial fix.

      For a wide scale deployment, create a forest root domain and don't let anybody in. Then create child domains on a geographical (avoid political) basis.

      The key rule is to design it for administration, not for internal politics. Use your management skills and escalate if necessary, but just don't give in a design around a political basis. If you do, welcome to AD hell.

      If anybody wants more details, you can use my hushmail address. Just reply to this post and I will email you.

  2. I'd go with 2003 by Ummagumma · · Score: 4, Interesting

    I recently upgraded to AD (well, 5 months ago...), and now Im wishing I went with 2003. Its not a big difference, but our test 2003 machines are a joy to use. Additionally, if you want to run the 2000 Server Adminpak on Windows XP, with the Exchange 2000 tools, its not fun to install - the 2003 tools work natively on an XP client.

    There really is no reason not to go with 2003, given the choice.

    --
    "The natural progress of things is for liberty to yield and government to gain ground." - Thomas Jefferson
    1. Re:I'd go with 2003 by Gorm! · · Score: 1

      Agreed. If it helps you sleep better at night, you can consider 2k3 to be AD SP1.

      We've run AD since a few months after it was released. We have around 30k user accounts in it. We completed an upgrade to 2k3 earlier this year and all of the functionailty that should have been there at the initial release has suddenly appeared. As the parent mentioned, the client tools are a lot better - we no longer need to log into the DCs to do day-to-day administration.

      Also important in a large environment, the 5000 people-in-a-group limit has gone.

      We didn't migrate from NT, so I have no idea how well that works under 2k or 2k3.

  3. At my office by secondsun · · Score: 4, Informative

    We went to 2k3 around the time it was released. The response around the office is more or less, "Fuck chevy this thing's a rock".

    Fot shits and giggles we put it on a pentium 2 300 laptop with 300MB of ram, it was stable, fast, and useful. In all honesty it is a great prduct and a worthy successor to 2k.

    --
    There is nothing wrong with being gay. It's getting caught where the trouble lies.
    1. Re:At my office by Anonymous Coward · · Score: 1, Funny

      Yes, I've heard about MS engineers patting themselves on the back about the amazing 3 month uptimes they're getting with this... err... "rock".

      Nice.

    2. Re:At my office by Anonymous Coward · · Score: 0

      i am sorry but 2000 was never worthy.

      just because its the best that MS ever produced does not mean its good.

      when you are used to eating garbage, and you get your first hamburger, that doesnt mean it is steak.

      and we shall see, win2k is probably the worst product microsoft has produced in my opinion. billions of dollars in damage due to its horrible security record.

      and whats funny is, comparing win2k3 to chevy is quite fitting.
      just think about it

  4. Word of advice.. by eingram · · Score: 2, Interesting

    I've only used it on Windows 2000, so I can't offer advice on which to pick, but I can tell you that it isn't wise to dump over 2500 users in to Active Directory with a script. AD will not like it, trust me. :)

    1. Re:Word of advice.. by altp · · Score: 4, Informative

      I've loaded 33,000 into a Windows 2000 AD with some perl scripts I wrote. Takes several hours, but all went well.

      What type of problems did you encounter?

    2. Re:Word of advice.. by eingram · · Score: 3, Informative

      Users and groups permissions started changing randomly for a few hours afterwards. It was not a fun day. I didn't write the script or even execute it, so I don't know why it happened, but I (and a few other IT people) got to clean up the mess.

    3. Re:Word of advice.. by Anonymous Coward · · Score: 0

      You just needed to wait whilst everything was played out.

    4. Re:Word of advice.. by trmatthe · · Score: 1
      There is a known bug with updating (or creating) more than a few thousand objects on w2k. It is documented by microsoft kb. Search for "ad object add 5000"


      Tim

      --
      Yeah right...
    5. Re:Word of advice.. by weave · · Score: 2, Interesting
      I've added around 10,000 users at a time using vbscript through ADSI calls without a problem. Did this under 2000 server and 2003 server.

      However, another person who replied to you points to a kb article that says it is a problem under 2000 server.

      Maybe I was just lucky.

      Mass adding users is common in educational institutions at the beginning of a term. Scary that it might have problems...

    6. Re:Word of advice.. by Dibblah · · Score: 3, Informative

      Duh. Groups in W2k have only one 'member' attribute. When this gets replicated, the last writer wins.
      What this means is that the groups membership will 'loose' members if you change it in different places and wait for replication.
      This is one reason that 2k3 is better. It fixes this issue.

  5. Windows 2003 - hands down by mrscott · · Score: 4, Insightful

    I've been through this twice now. Once recently and once about 8 months ago. The first one was an upgrade from NT -> 2003 and the second was an upgrade from a 2000 AD -> 2003 AD. Both times, I ended up MORE than happy that I went to 2003. The tools for 2003 beat the hell out of the tools for 2000. If you decide to add Exchange to the mix, Ex 2003 is more stable and has better features over 2000. All in all, if you're going new, there's no reason to wait for the .2 or .3.

  6. Why not both? by packetknife · · Score: 5, Insightful
    In AD you don't have a PDC versus BDC concept. Just domain controllers. I'd consider investigating having a W2K and W2K3 server. In the past year I've worked with W2K3 quite a bit and I've had great as well as frightening experiences. In the past ~4 months or so the availability of good W2K3 documentation has increased significantly, the MS support too.

    I find W2K3 to be quicker and have more nifty options and features. It also depends on your client population, with XP being more easily manages under W2K3 with the stock GPO, copies, and templates provided.

    At the same time I've had problems with W2K3 as a DNS/WINS server. And a DFS server. It took a long time and lots of digging to resolve those issues and it looked like it was the first time MS had come across a lot of the issues we had when we got in touch with them. Eventually worked out but it's never fun to be the first to find a bug in a critical service.

    The other annoyance we've had with W2K3 is it's control over W2K clients. Things like IE settings that'd be pushed from our old domain controller or from IEAK stuff stopped working or worked oddly in W2K3. It would store security settings in two files, push only one, confuse clients, etc.

    If I had to do it all over again ~today~ I'd go W2K3 because I've found the past few months worth of documentaiton and support to be much better than a year ago.

    I should note that the first network I deployed W2K3 in was ~80 nodes. It was critical, 24 hour operation, Engineering intense, lots of storage, license servers, etc. So it wasn't trivial but it's not a University sized environment, not that many thousands of clients.

    In conclusion.. I don't have a conclusion. I think I'd have to hear what services besides AD you'd want to run off of it. Do you run DNS, DFS, SFU, Licenses, TS, etc. off of the same servers?

    Oh, if you do go W2K3, install the Resource Kit bundle right away, it's priceless for administration and scripting.

    Anyhow, good luck, Cheers, -Pk

    1. Re:Why not both? by sharkey · · Score: 1
      At the same time I've had problems with W2K3 as a DNS/WINS server.

      'A' records mysteriously disappearing?

      --

      --
      "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
    2. Re:Why not both? by packetknife · · Score: 1
      No, that didn't happen. With DNS there was the problem of bogus entries being added even though the settings were only domain computers were to be automagically added. And that was slightly disheartening but never easily reproducible, it'd just 'happen' sometimes.

      WINS wouldn't seem to flush old entries even when you tried to force it. So if you have/had a netbios alias on a system in the registry, you couldn't ever get rid of it easily. It would linger until some seemingly arbitrary day/time and it'd go away.

      Cheers, -Pk

    3. Re:Why not both? by linuxbert · · Score: 1

      native 2k3 mode or mixed mode is why
      to take advantage of all 2k3's new features require only 2k3 controlers. if you hace a 2k DC then you cant use those features.

      note that you can have 2k member servers (not DCs) and both AD modes support nt4 BDC's for any older clients you may have

    4. Re:Why not both? by afidel · · Score: 1

      Be carefull, if you have a single 2k3 DC and it goes down you can end up with problems because the remaining DC's won't understand some of the objects in the extended schema. I think this only happens with things like an exchange2k3 server running as a member sever but I remember there being risks to running a mixed environment. I agree with you 100% on the resource kit =)

      --
      There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
    5. Re:Why not both? by sharkey · · Score: 1
      WINS wouldn't seem to flush old entries even when you tried to force it.

      Seems like the only consistent way is to delete the WINS database and let it rebuild itself. I've seen tombstoned records stick around for weeks in there.

      --

      --
      "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
    6. Re:Why not both? by cagle_.25 · · Score: 1

      OK, so ... if you had to choose (for budgetary reasons) between running W2K server with all W2K clients OR running W2K3 server with all W2K clients, which would you choose?

      --
      Human being (n.): A genetically human, genetically distinct, functioning organism.
  7. W2K3 by cloudless.net · · Score: 1

    W2K3 is faster than W2K in most tasks. It somehow use memory more efficiently, and it does not enable unnecessary services by default. Microsoft claims IIS in W2K3 is re-written to be more secure and faster.

  8. Go with 2003 by Finni · · Score: 4, Informative

    Um. AD using Windows 2003 is the service pack for the version of AD using Windows 2000.
    It's not like they re-wrote it from scratch. Nor is it like AD (using 2000) is entirely new either; it was developed from the backend of Exchange's directory service, if I understand correctly.
    Go with 2003, I haven't read of any particular defects of either AD or the server OS features under 2003, compared to 2000. And yes, things like Volume Shadow Copy, or whatever it's called, may make your life as an admin easier. Certainly, if you're running IIS sites, you'll appreciate the security of IIS 6 more than IIS 5.

    1. Re:Go with 2003 by naden · · Score: 3, Funny

      Certainly, if you're running IIS sites, you'll appreciate the security of IIS 6 more than IIS 5.

      If you do run IIS sites .. can I have the URL ?

      I want to .. umm .. view the site .. hehe.

      --
      Funtage Factor: Purple
    2. Re:Go with 2003 by SoundGuy666 · · Score: 1

      I think you'll find that 3/31/07 is slightly more than eight months from now - no matter whether you're using US or European date formats!

      --
      Why can't we all just get along?
    3. Re:Go with 2003 by Anonymous Coward · · Score: 0
      If you do run IIS sites .. can I have the URL ?
      I want to .. umm .. view the site .. hehe.

      IIS can be very easily made secure, and there is a lot of documentation on how to do it. I've actually seen running posts on some sites where idiots tried to attack us. Start off giddy because "the fools run IIS"; days later they repost that nothing works and they admit defeat. That said, I'm already a big enough target for every idiot on the net, so I'm not giving out my site; to many wannabe's equate "Denial of Service" with "Cracking a Site"

  9. Its been a while, but... by Omega1045 · · Score: 2, Informative
    As far as applications and security, I would take a serious look at going with Win2k3. It doesn't "turn on" all kinds of services by default like IIS. So after install, you don't have to hunt down as much stuff to turn off (or forget to hunt something down). Also, IIS on Win2k3 lives in something like a sandbox, preventing some of the buffer overflow attacks that have been so common on Windows machines.

    Win2k3t will run you .NET based apps a little better as .NET runtime binding is built into the way applications are executed on Win2k3 and WinXP.

    I only used the betas and release candidates, but they were all very stable and we actually had fewer problems with the than our Win2k machines.

    Just my 2 cents...

    --

    Great ideas often receive violent opposition from mediocre minds. - Albert Einstein

    1. Re:Its been a while, but... by hokiejimbo · · Score: 1

      just wanted to throw in a resounding Windows 2003. I am a sysadmin at a major univ (guess which one from my name...) and just completed a massive migration of the Student Programs Department to 2003 from 2000. I couldn't be happier. 2003 is responsive and stable... and SECURE, something 2000 leaves a lot to be desired about.

  10. Windows 2003 Is Amazing!! by FlameSnyper · · Score: 2, Interesting

    It lets you do AMAZING THINGS like oh, change properties on multiple users at once... and stuff. Ya know, like you could in frickin' NT, 10 years ago.

    Thanks, Bill.

    If you haven't bought 2000 -- skip it, most of our customers that have 2000 want 2k3, but now have to purchase all new CALs...

    Again, thanks, Bill.

  11. New record for lordbry by Anonymous Coward · · Score: 1, Insightful

    Wow, a question that ultimately implies sending money over to Redmond, and not a single post yet claiming Mandrake 6 on old Pentium 2 would server the purpose just right and he should contribute money to GNU foundation instead?

    1. Re:New record for lordbry by pmsyyz · · Score: 2, Funny

      Mandrake 6 on old Pentium 2 would server the purpose just right and you should contribute money to GNU foundation instead!! UU!!

      --
      Phillip
    2. Re:New record for lordbry by Anonymous Coward · · Score: 1, Funny

      Nah, it's just funny to watch windows people talk sometimes, why spoil it?

      Employee one: "Man, Windows 2000 is pretty good, but using it causes cancer!"

      Employee two: "2003 is WAY better. It includes two packets of chemo pills! Thanks Bill!"

    3. Re:New record for lordbry by gfoyle · · Score: 1, Offtopic

      Why is this marked as a troll? Depending on the situation and what they want to do with AD, Linux with SAMBA might be an inexpensive alternative installing a W2K3 box.

      Where has the love gone?

    4. Re:New record for lordbry by Pantero+Blanco · · Score: 1

      I'd have marked it as Funny due to the Freudian slip, myself.

    5. Re:New record for lordbry by iainl · · Score: 1

      It might, but that really wasn't the tone I got from the post. Personally, it felt a lot more like the ones you get over in the games threads, where people ask "which should I buy for my Cube; Mario or Zelda?", and get the reply "Buy an XBox, they're much better!" - it really doesn't answer their question.

      --
      "I Know You Are But What Am I?"
    6. Re:New record for lordbry by dave420 · · Score: 1

      Because he asked which out of 2000 and 2003 would be better. No samba. We all know samba can be an active directory, but seeing as the guy said it's quite important it doesn't go down, spending the money on a tried and true solution is probably the best idea. Not everyone is worried about money and ideology.

    7. Re:New record for lordbry by Dibblah · · Score: 1

      In fact, it cannot. Even Samba-NG doesn't have support for Samba as a DC.

    8. Re:New record for lordbry by glenstar · · Score: 1
      As a test, I had RC2 of Win2k3 server running on a 233Mhz/256MB machine acting as a DC, primary DNS and fileshare for a network of approximately 20 machines. It worked like a champ and was even responsive on the console. ASP.net applications were a bit painful under this configuration, however.

      Win2k3 is a different animal than Win2k, even if they do share huge portions of the same codebase.

    9. Re:New record for lordbry by dave420 · · Score: 1

      So it can just participate on an AD, and not be one? Can it be a PDC?

    10. Re:New record for lordbry by Dibblah · · Score: 1

      It can be an NT4 PDC/BDC, but not an AD Domain Controller. It can be a member server in an AD domain.

    11. Re:New record for lordbry by dave420 · · Score: 1

      I knew about the participating on an AD, as I set up a redhat box to be a cups print server on our network. It could authenticate people against the AD using kerberos, and worked well until it got something out of whack and refused to join the network any more. I think it's still a bit buggy :)

    12. Re:New record for lordbry by pnutjam · · Score: 1

      I find a ClarkConnect box works well as a drop in solution for a single server small business. Probably isn't as robust as AD though.

  12. Go with 2003 by darkjedi521 · · Score: 4, Insightful

    Windows 2000 is almost EOL'd. Windows 2000 Support Cycle. Non-security updates end 3/31/05 (8 months from now) and security updates end on 3/31/07 - eight months from now. I'd go with 2003 since by the time you are done with the migration, 2000 will probably be at the end of its useful life and you'll be looking at going to 2003 anyways.

  13. 2003 by droyad · · Score: 2, Insightful

    Use 2003, it is the same as 2000 with added admin features. There are a few issues that we have had, but they have all been patched by now.

    If you are worried about stability, we have found 2003 is much more stable than 2000. 2003 is just 2000 with extra features, I don't think much in the core has been changed.

    Additionally you if you go with 2000, you have 3 years less support on the product. I assume you are using licencing, so upgrades are free, but the labour in changing over is huge.

    Remember work out how much time it is going to take you and triple it. You WILL run into problems. Always have a fall back position for when the shit hits the fan.

  14. Go with 2003 by hrbrmstr · · Score: 4, Insightful
    • fewer security patches (== longer uptime)
    • way more flexible schema updates, especially in a large AD environment
    • way more secure than Microsoft's pervious iterations right out of the box and in general operation
    • generally faster (but that will depend on what else you've got running on it - hopefully just AD)
    • much better command line administration (can do most everything from a command window)
    Do yourself a favor and also grab ActiveState's perl distribution and, since you're already running a ludicrously expensive OS, buy their PerlNET disdtribution (part of the Perl Dev Kit - http://activestate.com/Products/Perl_Dev_Kit/prici ng_and_licensing.plex). You get the full power of perl for system administration and the .NET crap that makes it easier to integrate with the beast.

    Also make sure you install the resource kit.
    --
    Mind the gap...
  15. go with 2k3 u fucking moron by siyavash · · Score: 0, Funny

    yes, ofcourse u should go with win2k3... wtf is wrong with you ? they should kick u out of your god damn job for just asking this question... ...hey, how about you go back to DOS 6.22 ? it probably is even better for u...

    god damn idiots.... u make internet sick.

  16. Sorry if this is off topic...but... by Stevyn · · Score: 4, Interesting

    I wouldn't bother to listen to your argument if you are calling Microsoft "M$". That's biased, and so that doesn't help make rational decisions that are needed when you're dealing with a project of this magnitude. Leave the M$ WinBlowz speak for the IRC chatrooms.

    Sorry to sound like a troll or spread flamebait, I just think this talk has to stop because it makes Apple, Linux, etc, users seem like biased morons.

    I'd rather this be replied to harshly than modded down if you find what I said to be disagreeable.

    1. Re:Sorry if this is off topic...but... by Anonymous Coward · · Score: 0

      Well, it's easier to type "M$" than "overpriced Microsoft junk that we're forced to use due to lock-in and intertia".

    2. Re:Sorry if this is off topic...but... by Anonymous Coward · · Score: 1, Funny

      d00d, ar3 j00 cr@zy?

      "M$" is ju$t @ p@rt of teh l33t sp3ak v3rnacul@r.

      And j00@ll kn0w th@t l33t sp3ak impr3$$3s @ll teh h0t chixx0rs!

    3. Re:Sorry if this is off topic...but... by {8_8} · · Score: 1

      Obligatory PA link:

      M$

      It's funny because it's true :)

    4. Re:Sorry if this is off topic...but... by Pantero+Blanco · · Score: 3, Insightful

      Replacing the "S" in something one finds expensive with a "$" isn't just used in "Micro$oft". I've seen it used in context that wasn't even computer related (in discussion of cars, for example)...It's been around longer than MS has. It's not a comment about the quality, it's a comment about the price (though when it's combined with "windoze", "winblows", etc, I agree that it seems childish).

    5. Re:Sorry if this is off topic...but... by Anonymous Coward · · Score: 0

      I've never seen '$un' in /.

      Hmmm, curious !

    6. Re:Sorry if this is off topic...but... by lordbry · · Score: 1

      I realize you will probably not be seen but I wanted to reply anyway (I submitted this 2 weeks ago and was on vacation last week)...

      I did that partially to convey (in addition to my distrust of new microsoft products) that I AM biased... If I ask something like this again I will try to say that I am slightly biased.

      Trolling is generally incoherent. You make a good point.

  17. I think you misunderstand.... by hawkbug · · Score: 1, Informative

    Win2k3 is Win2k SP5 :) No, seriously though - have a look at the version number of the OS sometime. You'll laugh.

    Windows 2000 - Windows NT 5.0
    Windows XP - Windows NT 5.1
    Windows 2003 - Windows NT 5.2

    Something tells me there is nothing ground breaking going on from version to version! In all seriousness though, go with 2003 or you'll be sorry. I say this because it's only going to be a few years I bet before Microsoft drops support for patches for 2K. You don't want to spend a ton of money only to have to do it again very soon for 2003. Also, 2003 is more stable than 2K out of the box, and that counts for something. Driver support is also much better, the ability to roll back drivers, etc.

    1. Re:I think you misunderstand.... by Judg3 · · Score: 3, Informative

      I say this because it's only going to be a few years I bet before Microsoft drops support for patches for 2K.

      Actually, Windows 2000 life cycle is Jun 30th 2005 for mainstream support and Jun 30 2010 for extended support. (By comparison Windows 2003 mainstream is Jun 30 2008 and extended is Jun 30 2013)

      This is from MS.com. Difference between Mainstream and Extended support here.

      --
      Looking for hardware (Currently need: Large Etch-a-Sketch) Have one? See my journal!
    2. Re:I think you misunderstand.... by hawkbug · · Score: 1

      Yes, but for the same price for both OS versions, it makes no sense to go with Win2k when 2k3 will be around longer and has more features. As you've shown, 2K will die out 3 years before 03.

  18. 2003 all the way by CliffH · · Score: 2, Interesting

    Like others have said, it is an upgrade, not a new OS. They have improved AD a good bit. It is more stable than 2000, it's a bit quicker network wise (new BSD stack), handles memory a bit better, and is generally snappier than its predecessor. If you're going to use it for any Terminal Services, you also have the bonus of doing more than 256 color in a terminal session and can easily map all of your drives, printers, sound, etc to the local terminal. 2003 is a good chunk of what 2000, actually, NT4 was supposed to be. Now, if they could get WinFS in there they would have most all of their pre-NT4 technologies in place. :) CliffH

    --
    sigs are like a box of chocolates, they all suck remove the underscores to email me
  19. Suggest 2003 and serious design homework by dgallina · · Score: 2, Insightful

    You *absolutely* want to user Server 2003 over 2000. If you *must* use 2000, make sure you use the very latest service pack and appropriate hot-fixes. As others have mentioned, 2003 is really a *minor* update to 2000, despite the name change.

    I have deployed an extensive AD (60+ domain controllers and 80,000 users) on early (SP2-era) Windows 2000. AD had major bugs and scalability issues in versions before Windows 2000 SP4.

    Whatever you do, make sure to do good research, home-work, and design *before* you start deploying the infrastructure, creating organization units, and policies. Good design will pay off as the infrastructure grows. Bad design will create increasingly complex problems as your infrastructure grows. It's no fun to re-design and re-deploy over a large and broken first attempt :-)

    Good luck!

  20. Relying on service pack numbers? by bookemdano63 · · Score: 2, Interesting

    As an "admin for a major university" I would hope you are basing upgrade decisions on the service pack numbers. Maybe do some research and check stability statistics and use cases.
    I guess this kind of reasoning is why Java 5 is so much better than Java 1.5.

  21. 2003 Is Plenty Stable by nuxx · · Score: 1

    I can tell you that a rather large auto manufacturer is going to a massive 2003-based AD structure for a good part of it's operations throughout the world, and it's all going fairly smoothly.

    I'd definitely go with 2003 myself. There's no reason to go to 2000...

    Oh, and AD can be very nice to work with, just be sure you know what you're doing. It's a complex, powerful tool, and just like any good tool you can hurt yourself or get mired in misconfigurations.

    Another word of advise? Use certified and tested drivers. There's good reason to listen to the Windows Hardware Quality Labs. WHQL approval means the driver isn't going to blow up, and a machine full of solid, approved drivers will run solidly (barring hardware problems).

    After all, you can't expect an untested third party kernel module to never misbehave, can you?

    1. Re:2003 Is Plenty Stable by nuxx · · Score: 2, Insightful

      Oh, and one other thing? If you go with a Windows 2000 AD structure, then wish to bring in 2003 Domain Controllers, you'll get to extend your AD schema. While it wasn't a problem for us, I really don't think you want to have to go through such a process. After all, at it's core AD is a big-ass database. Do you really want to extend a DB schema if you don't have to?

      Just go with 2003 to begin with and be set with the new schema, finer grained GPOs, better management tools, etc.

  22. Why not use the Best of Breed technology? by Radical+Rad · · Score: 3, Interesting

    Which is, according to the industry rags, NDS, now called eDirectory. I know many people will point out that LDAP could almost certainly handle the job and is basically the de facto standard, but NDS has had more time to mature and is more robust. Either one can run completely on Linux (or even Solaris or NT/2Kx if you enjoy paying needless license fees). Are you stuck using the legacy windows platform or can you make a clean break and migrate to something better?

    1. Re:Why not use the Best of Breed technology? by dave420 · · Score: 0

      Right. Something better. You're using something from novell.com to point out why eDirectory is great. Sheesh. I mean, seriously. Did you really expect someone to think that was a good suggestion? Apart from the fact the question was between 2000 and 2003, not 2000, 2003 and anything anyone can pull out of their ass. Why don't you just suggest he ditch the PCs, move to Macs, and use samba 3?

    2. Re:Why not use the Best of Breed technology? by Anonymous Coward · · Score: 0

      Because anything labeled with "Best of Breed" marketingspeak, well, probably isn't.

      Oh, and eDirectory was product of the year in 2002, but not since. Perhaps it is no longer the "pick of the litter"

    3. Re:Why not use the Best of Breed technology? by Anonymous Coward · · Score: 0

      If you had read even the first two words of the blurb he cited you would see it came from Network Magazine. Open your eyes... and your mind... you poor, poor Micro$odomite.

    4. Re:Why not use the Best of Breed technology? by dave420 · · Score: 1

      Hahaha! OK, sure. So it's hand-picked by novell. Like they're going to pick an article that says how shitty their product is. Use your brain, man! Just because it's from a reputable source doesn't mean to say it's the common consensus from the industry, as you pertained.

    5. Re:Why not use the Best of Breed technology? by LO0G · · Score: 2, Insightful

      "I know many people will point out that LDAP could almost certainly handle the job"

      Ok, this has been getting to me throughout the commentary, but people keep on making the same mistake.

      LDAP is a prototol. It's not a product. Any product that implements RFC2251 is LDAP.

      The Active Directory implements LDAP, as does eDirectory and many other directory services.

      Which LDAP did you mean?

    6. Re:Why not use the Best of Breed technology? by Anonymous Coward · · Score: 0

      Notice it is Product of the Year not just Directory Service of the Year. For three years in a row too! Edirectory is still much more refined than Active Directory. It could take a decade for Microsoft to catch up in this field. I know you won't take my word so go find some impartial reviews and read what the experts think.

    7. Re:Why not use the Best of Breed technology? by Anonymous Coward · · Score: 0

      AD may implement its own modified version of LDAP, but M$ has made it incompatible with open standards of the Internet. As such, it cannot call itself LDAP compliant because I cannot build a network that consists of OpenLDAP and AD equiped servers. AD is not LDAP/RFC2251 compliant.

    8. Re:Why not use the Best of Breed technology? by Radical+Rad · · Score: 1
      Ok, this has been getting to me throughout the commentary, but people keep on making the same mistake. LDAP is a prototol. It's not a product.

      I wasn't making a mistake. I know that LDAP is a protocol and not a product. However, there are many implementations of LDAP and many of them are high quality and open source. Any LDAP software is likely to be able to support more transactions per second than one of the big-name products implementing X.500 yet would probably be able to handle the complexity of the job. That was the point I half expected people to rebut me on.

    9. Re:Why not use the Best of Breed technology? by LO0G · · Score: 1

      References please?

  23. Horror Stories by Lord+Bitman · · Score: 1

    once, I took the business advice of someone who abbreviated Microsoft as "M$". As a direct result, millions of Americans lost their lives in one of the bloodiest displays I have ever heard a first-hand account of.

    --
    -- 'The' Lord and Master Bitman On High, Master Of All
  24. Go for it! by yancey · · Score: 1

    I agree that Windows 2003 is much better than 2000. I've used both and am about to rename a domain.. something not even supported under 2000... and can recommend 2003 with full confidence.

    Also, as a standard practice, I disable DCOM and install a virus scanner and set all machines to auto-update (both virus signatures and windows updates) in the early morning (say around 05:00 local time). The servers will automatically update and reboot and I've personally never had a problem even though the servers are directly on the Internet. Granted, I don't run the web server.

    --
    Ouch! The truth hurts!
  25. More expensive? No. by Ayanami+Rei · · Score: 1

    It's priced exactly the same as 2000 server. Even per CAL.

    --
    THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON
  26. I Just Did this Migration by linuxbert · · Score: 4, Insightful

    I just migrated my workplace form NT4 to 2k3 Active Directory.

    The process went without a hitch.
    first we ghosted our pdc, that way we could return things to normal quickly, if the upgrade didnt work. we poped in the 2k3 cd, and went through like a normal install.

    AD is tied to dns. chose your dns name now, its best if you control your own dns servers if you want to use your web domain, otherwise its a bit of a pain (but it works)

    after the install completed dc promo ran and imported all our user and computer accounts. it might be best to do the housekeeping of unused users, groups etc. before migrating.

    Adding additional controlers is easy, just install 2k3 and run dcpromo, and select add an aditional controler to domain. it will automaticly replicate for you.

    Design your directory structure prior to migration.

    and like all windows systems - when in doubt reboot. 2k3 is rock solid, but i had an issue where dns would not replicate properly, untill i reboted the first DC.

    Also i might add that Microsofts Software update services (SUS) works amazingly well. it can be inforced with Group policy, and all your approved updates can be forced to your clients when you want them to be. Patch management is much simpler now.

    1. Re:I Just Did this Migration by anticypher · · Score: 2, Informative

      Yes, get the DNS correct from the very beginning.

      One of my clients with many DNS servers has finally developed some filters to cut out all the AD crap lookups coming from a handful of poorly designed systems. Its not just a little bit of traffic, it was something like a 25x increase in bogus DNS traffic because a handful of his clients thought they could get away with putting their company name as the TLD or some other misunderstanding of AD.

      Plan on first building a sandbox version of your network, with an external DNS server simulating the entire internet. Monitor the kinds of lookups escaping your network to make sure close to 100% of your traffic stays local. Your local AD and DNS servers should agree on your structure, and the rest of the world should agree on your chosen (assigned) domain name.

      the AC

      --
      Hemos is like...sci-fi fans;he thinks technology is cool, but he hasn't bothered to understand the science it's based on
  27. Go for 2003 - Hands Down by major.morgan · · Score: 2, Interesting

    I have worked with Active Directory since it's early Beta's, arranged and performed at least a 100 production installs and upgrades over the past few years. And I would say (strongly recommended) that most of my people move over to 2003. I have yet to have a 2003 install fail, while at the same time it works faster and more stable than 2000 - and not that 2000 Server was bad to begin with. As far as service packs, I would agree with other posts that 2003 is pretty much Windows2000 SP6 or so. Keep in mind the MS version numbers:

    Windows2000 = NT 5.0
    Windows XP = NT 5.1
    Windows2003 = NT 5.2 .2 is a minor version upgrade.

  28. You got lost buddy. by jotaeleemeese · · Score: 1

    This is /. , your Economist, Forbes, BusinessWeek or whatever you normally read is not here.

    Look pal, there are many people out there that as part of their job they have to do things which do not necessarily please them on extreme.

    That does not mean they are not professional.

    There was one a musician in one German orchestra that had to perform the first installment of one of Richard Wagner's masterpieces. His pergorming was so superb that Wagner went to thank him personally. When he asked the performer (I belive it was a french horn player) if he had liked the music he replayed that it was the most hideous thing he had ever played.

    Wagner, surprised of course, said then how he managed to play it so sell. The musician replyed that he was a professional and he would do his utmost to perform to the best of his abilities any music given to him.

    In other words, get off your high horse because you look pathetic.

    --
    IANAL but write like a drunk one.
    1. Re:You got lost buddy. by Anonymous Coward · · Score: 0

      If you are attempting to act in a professional manner yourself, I would suggest employing both correct spelling and grammar. Microsoft produces many fine products that would aid you in creating syntactically correct correspondence. I must commend you, however, upon your shining ability to so widely avoid the subject of the current debate by decrying the author of the previous comment rather than voicing an opinion regarding the rampant bias against Microsoft. Hopefully the discussion can return to the original direction.

  29. Don't believe the hype, use Kerberos instead by SgtChaireBourne · · Score: 1
    No need to reinvent the wheel, especially a high maintenance one with high CAL fees.

    Go with straight kerberos + ldap authentication. AD still has scalability issues which, though improved over earlier versions of itself, are still behind Novell NDS or Kerberos + LDAP. Interoperability with a heterogeneous set of workstations is historically pretty poor for AD. Kerberos and LDAP clients exist and function quite nicely on what ever platform you have.

    Furthermore, if nothing else, pricing in the 2003 version will kill you, even if managing all the licenses doesn't. Of the two, 2000 is the way to go, but the third option (real kerberos) is probably the way to go in your case.

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
  30. Samba! by smoon · · Score: 1

    Sorry. Had to say it.

    I'd go with 2003 though -- aside from extremely annoying problems porting apps over from NT due to new security settings (which you wouldn't have as an AD controller) it's been completely trouble free, stable, and quite frankly rock solid. Oh great, now I feel like a microsoft whore.

    ughh... dirty. dirty.

    --
    "But actually trying to use m4 as a general-purpose langage would be deeply perverse" --ESR
  31. I'd say go for 2K3 by dJCL · · Score: 0, Troll

    I do a lot of junior support on 2K3 SBS networks and find it exceptionally easy to deal with in most cases(not all, I still like linux for easy modification of configurations, everything seems more logical and documented there, but that's just me, I do work for an MS shop). I personally love the new tools to join a system to the domain, and there are other features that either make life easier or just a little more logical.

    Our SBS 2000 clients are already looking out of date, even when we only installed 1 year ago.

    Anyway...

    Enjoy!

    --
    On Arrakis: early worm gets the bird. Magister mundi sum!
  32. Depends on your clients by outcast36 · · Score: 2, Informative

    Just thought I'd add my 2 cents. Everyone else is right, 2003 has some nicer features than 2000. If you want to take advantage of a lot of the 2003 features, you're going to need a majority of XP machines. If your client base is all NT4 or 2000, you're not going to see the maximum benefits.

  33. May cause problems to non windows kerberos clients by Anonymous Coward · · Score: 0

    The university i work in recently upgraded to windows 2003. I am assured by those in the kinow that it is much better than 2000.

    However when authenticating unix kerberos clients against it there are problems. Firstly kerb clients that aren't near bleeding edge (e.g. the default in Redhat A.S. 3.0) tend to fail when authenticating. I think this has something to do with windows switching from udp to tcp earlier than older clients expect, newer kerb auto negotiates better i think. (tracking kerberos erros is tricky and this one only turns up when users are in many groups forcing packet size to get too large).
    Second kerb.keytab files are by default des-cbc-crc in 2000 and des-crc-md5 encrypted in windows 2003 meaning you will have to change keytab files and alter you kerberos configuration (krb5.conf) if you use keytabs. Saying that i haven't had time to test that this actually works. Changing keytabs and encryption types is relatively easy but still a PITA when previously working authentication suddenly drops when you upgrade to 2003.

  34. 2003 all the way by Bravo_Two_Zero · · Score: 2, Informative

    Caveat: We haven't moved from NT4 yet, but...

    This one can go to the bank. Do not go to 2000. Even the Microsoft people (from PSS, no less) say 2003 is the way to go. The list of imporvements for AD (not to mention the other 2003 OS improvements) is staggering.

    Yes, it's true that a M$ product can generally be considered trash until SP2 or SP3, but there are all sorts of known AD issues in 2000 that have been fixed.

    --


    Amateurs discuss tactics. Professionals discuss logistics.

  35. HAHA! by Anonymous Coward · · Score: 0

    gotta love these "admins" who put so much faith in version numbers. win2ksp4 isnt magically more stable than win2k3 cause its got more service packs

    these morons go in the same box as the people who think that all of a sudden firefox will change dramatically and become stable (as if it wasnt already!) when it hits 1.0, but NO WAY AER WE INSTALLING FIREFOX BETAZ 0.9.2!!!1 THAT CANT BE STABLE CAUSE ITZ NTO 1.0!!!!!1111

  36. I tried to install Active Directory by Anonymous Coward · · Score: 0

    I tried to install Active Directory once on my Sony Walkman, but all I could receive after that was broadcasts from the Nevada test site.
    (get it? Radio Active Directory? Nevada test site?)

  37. "Duck and cover!" by Tux2000 · · Score: 2, Insightful

    Some time ago, out IT department and an external IT consulting company (recommended by MS) tried to migrate our NT4 Domains (one per office plus some for special purposes) into a single W2k Active Directory. It took more than week full of night shifts and a second IT consulting company to limit the damage caused by scripts of the first IT consulting company. World readable "top secret" documents, completely locked transfer folders, and locked-out users were only the tip of the iceberg.

    So here is my advice: Have a verified backup of all working systems, run a lot of tests, and try the migration in a *good* lab environment first (a 1:1 copy of your production systems would be ideal). Repeat several times until everything works smoothly. Run the last tests with recent copies of the production system. DO NOT TRUST SCRIPTS! Verify the result of each script, and make all scripts abort if they find data they can not handle.

    Tux2000

    --
    Denken hilft.
  38. My 2.62948 cents Canadian by MikeSweetser · · Score: 1

    Sorry if this is a me-too, but as a web host, I wanted to throw my two cents in..

    The company I work for recently went from Windows 2000 Server to Windows Server 2003 Standard Edition (mm, Microsoft volume licensing) and the gains have been TREMENDOUS. Servers that were choking on running 1,000 websites (with e-mail, FTP, etc) because of memory issues and problems with website applications are now running like a dream with nearly all RAM free. The new application pool settings are a dream to work with, and the server just feels more robust now.

    2003's stability is amazing just on its smarter handling of memory. It also helps that it's smarter on handling rogue applications that decide not to run right, and the fact it doesn't install everything under the sun by default helps as well.

    If you are upgrading from 2000 to 2003, you do need to look for a few minor things (the ASP.NET user changes from ASPNET to NETWORK SERVICE, and you need to make sure ODBC updates completely - I had a few servers that couldn't connect to SQL Servers anymore and required me to install SQL Server and uninstall to fix it; I'm sure Microsoft had a solution for it but I was under a deadline :) but the general upgrade goes very smoothly. Put the CD in, wait an hour, fiddle with a few settings (ODBC, the .NET stuff, change IIS from 5.0 mode to 6.0 mode) and voila, you have a bigger, better, badder server.

    There's no reason to go with 2000 now that 2003 is available - there may be no service pack yet but it's running like a champ. Go with it.

    Mike

  39. Kerb / 2003 was Re:Don't believe the hype. by Jeremiah+Cornelius · · Score: 1

    Thank you. This s very usefull!

    --
    "Flyin' in just a sweet place,
    Never been known to fail..."
  40. new stuff in win2k3 by Vlad_Drak · · Score: 1

    Win2k3 more or less has AD 2.0 (or 1.1 if you must). You can now actually rename a domain, and establish cross-forest trust designs, speed enhancements, better sync, etc. Here's a basic overview of the diffs:

    http://www.techgalaxy.net/Docs/Win2003/WS03_AD_i mp rovements.htm

    You're going to get a lot more flexibility in the long haul this way.. really doesnt make any sense to stay with 2k IMHO.

  41. Remote Desktop Connection to Console Session! by Anonymous Coward · · Score: 0

    This is one of the most amazing features that no one seems to have mentioned ...

    Not needing VNC/pcanywhere installed is a great thing

    Being able to manage the servers that have console applications running from any Windows XP client on the LAN has been a life saver.

    oh and AD management tools (saved queries!!) are sw33t!

  42. 2003, for sure by thebdj · · Score: 1

    Why do so many users and occassional admins fear the "new" thing? Think about the operating systems you are comparing, the thing that really matters in any operating system is the core of it, or the kernel for the geeks.

    The fact is the last two desktop operating systems are definitely on a very similar if not identical kernel. I mean XP is a butt kicking version of Windows 2000 with all the functionality and more, at least for those actually using professional. It was the huge success of 2K outside of the business world that helped result in the death of 9x (ME was BAD) and the complete usual of the NT-esque kernel that 2K used.

    A similar thing can be said with 2003. It is server 2000 with a few extra things here and there and is as such more stable, cleaner, and offers a load more features then 2000 did, or ever will. There is no point in waiting for tons of Service Packs, cause otherwise you will be using 2003 when the server post-longhorn comes out. The fact is Windows isn't quick with Service Packs not so much because they are lazy as they aren't as needed as they were in Win 2K in prior. Use 2003 and keep up with the rest of the pack, if you fall behind now your company will be playing catch up for years.

    --
    "Some days you just can't get rid of a bomb."
  43. Who here has examined the licensing changes? by SgtChaireBourne · · Score: 1

    Aside from some mention of price, the discussion has stayed reasonably technical, but it would be essential to know what has changed in regard to the licensing.

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
  44. 2k3 all the way by Stinking+Pig · · Score: 1

    I work with both on a regular basis at customer sites and in my own vmware-based test and demo environments. 2k3 is a lot better as a server OS and as a AD domain controller.

    That said, one of the reasons it's better is the improved security. If you rely on NTLM for IIS authentication, you may have some fun getting that to work (hint, allow delegation on the IIS server). DOS clients may have some trouble mounting network volumes too (hint, think workstation OS imaging).

    However, 2003 definitely cuts the mysterious breakages down to a minimum. I see a lot less of machines falling out of the domain, for instance.

    --
    "Nothing was broken, and it's been fixed." -- Jon Carroll
  45. Go to 2K3 by sydbarrett74 · · Score: 1

    2K3 without any service packs is more stable than 2K SP4.

    --
    'He who has to break a thing to find out what it is, has left the path of wisdom.' -- Gandalf to Saruman