Active Directory's A record and delegation to subdomains

Tim Maestas tmaestas at dnsconsultants.com
Tue Sep 18 15:31:48 UTC 2001



> Does AD really need that A record? The p525 doesn't mention it and the stuff
> on the list (what I have been able to gather anyway), isn't conclusive
> either way. It doesn't work when we test it, but that may just be because we
> aren't doing it quite right. If it doesn't need it, how do we set it up?

	My company refuses these A record updates, and so far
	everything is working fine.  Microsoft says that record
	is used for non-srv aware clients/apps to locate a domain
	controller.



> 
> Next question, will the same trick we are using to keep AD out of the
> "production" domain (the technique described on p525) work in a scenario
> where we have delegated subdomains? Our internal DNS structure has the
> corporate offices as "morinda.com" and each remote office as a two letter
> delegated subdomain of that based on country, for example "jp.morinda.com",
> or "ca.morinda.com" or "mx.morinda.com", which they in turn can create
> subdomains for their not-main country offices ("tokyo.jp.morinda.com" or
> "toronto.ca.morinda.com", etc). This has worked superbly well for us and it
> would not make me happy to have to change it. Our testing has shown that it
> doesn't quite work right, but that may be because we haven't set it up
> "right".

	This should work fine - just delegate the "underscore" domains
	off of wherever your AD root happens to reside, as well as
	for each child domain you create in AD.

-Tim



More information about the bind-users mailing list