Введение
Флексибильные операции с одним мастером (FSMO, F иногда "плавающие"; произносится "Физмо"), или просто операция с одним мастером, или мастер операций, — это функция Microsoft Active Directory (AD). Начиная с 2005 года, термин FSMO устарел и заменен на "мастеры операций". FSMO представляет собой специализированный набор задач для контроллера домена (DC), используемый в тех случаях, когда стандартные методы передачи и обновления данных оказываются недостаточными. AD обычно полагается на несколько равноправных DC, каждый из которых содержит копию базы данных AD, синхронизируемую с помощью многомастерной репликации. Задачи, которые не подходят для многомастерной репликации и могут выполняться только с использованием одной мастер-базы данных, выполняются в рамках FSMO.
Flexible Single Master Operations (FSMO, F is sometimes "floating"; pronounced Fiz mo), or just single master operation or operations master, is a feature of Microsoft's Active Directory (AD). As of 2005, the term FSMO has been deprecated in favour of operations masters. FSMO is a specialized domain controller (DC) set of tasks, used where standard data transfer and update methods are inadequate. AD normally relies on multiple peer DCs, each with a copy of the AD database, being synchronized by multi master replication. The tasks which are not suited to multi master replication and are viable only with a single master database are the FSMOs.
Роли в домене
Эти роли применимы на уровне домена (т.е. для каждого домена в лесу существует одна роль):
The PDC Emulator (Primary Domain Controller) This role is the most used of all FSMO roles and has the widest range of functions. The domain controller that holds the PDC Emulator role is crucial in a mixed environment where Windows NT 4.0 BDCs are still present. This is because the PDC Emulator role emulates the functions of a Windows NT 4.0 PDC. Even if all Windows NT 4.0 domain controllers have been migrated to Windows 2000 or later, the domain controller that holds the PDC Emulator role still does a lot. The PDC Emulator is the domain source for time synchronization for all other domain controllers; in a multi domain forest, the PDC Emulator in each domain synchronizes to the forest root PDC Emulator. All other domain member computers synchronize to their respective domain controllers. It is critically important that computer clocks are synchronized across the forest because excessive clock skew causes Kerberos authentication to fail. In addition, all password changes occur on the PDC Emulator and receive priority replication. The RID Master (Relative ID) This FSMO role owner is the single DC responsible for processing RID Pool requests from all DCs within a given domain. It is also responsible for moving an object from one domain to another during an interdomain object move. When a DC creates a security principal object such as a user or group, it attaches a unique SID to the object. This SID consists of a domain SID (the same for all SIDs created in a domain) and a relative ID (RID) that is unique for each security principal SID created in a domain. Each DC in a domain is allocated a pool of RIDs that it is allowed to assign to the security principals it creates. When a DC's allocated RID pool falls below a threshold, that DC issues a request for additional RIDs to the domain's RID Master FSMO role owner, the RID Master FSMO role owner responds to the request by retrieving RIDs from the domain's unallocated RID pool and assigns them to the pool of the requesting DC. The Infrastructure Master The purpose of this role is to ensure that cross domain object references are correctly handled. For example, if a user from one domain is added to a security group from a different domain, the Infrastructure Master makes sure this is done properly. However, if the Active Directory deployment has only a single domain, then the Infrastructure Master role does no work at all, and even in a multi domain environment it is rarely used except when complex user administration tasks are performed. This applies to the domain partition (default naming context) only. and will only query the domain partition. However, every application partition, including Forest and Domain level DNS domain zones has its own Infrastructure Master. The holder of this role is stored in the attribute of the object in the root of the partition, it can be modified with , for example one can modify the attribute of the object to .
Эмулятор PDC (Первичный контроллер домена) Эта роль является наиболее востребованной из всех ролей FSMO и обладает самым широким спектром функций. Контроллер домена, на котором размещена роль эмулятора PDC, критически важен в смешанной среде, где все еще присутствуют BDC Windows NT 4.0. Это связано с тем, что роль эмулятора PDC эмулирует функции PDC Windows NT 4.0. Даже если все контроллеры домена Windows NT 4.0 были перенесены на Windows 2000 или более позднюю версию, контроллер домена, на котором размещена роль эмулятора PDC, по-прежнему выполняет множество задач. Эмулятор PDC является источником времени для синхронизации всех остальных контроллеров домена; в лесу с несколькими доменами эмулятор PDC в каждом домене синхронизируется с корневым эмулятором PDC леса. Все остальные компьютеры-члены домена синхронизируются со своими соответствующими контроллерами домена. Крайне важно, чтобы время на компьютерах было синхронизировано во всем лесу, поскольку значительная разница во времени приводит к сбоям аутентификации Kerberos. Кроме того, все изменения паролей происходят на эмуляторе PDC и получают приоритет репликации.
The PDC Emulator (Primary Domain Controller) This role is the most used of all FSMO roles and has the widest range of functions. The domain controller that holds the PDC Emulator role is crucial in a mixed environment where Windows NT 4.0 BDCs are still present. This is because the PDC Emulator role emulates the functions of a Windows NT 4.0 PDC. Even if all Windows NT 4.0 domain controllers have been migrated to Windows 2000 or later, the domain controller that holds the PDC Emulator role still does a lot. The PDC Emulator is the domain source for time synchronization for all other domain controllers; in a multi domain forest, the PDC Emulator in each domain synchronizes to the forest root PDC Emulator. All other domain member computers synchronize to their respective domain controllers. It is critically important that computer clocks are synchronized across the forest because excessive clock skew causes Kerberos authentication to fail. In addition, all password changes occur on the PDC Emulator and receive priority replication. The RID Master (Relative ID) This FSMO role owner is the single DC responsible for processing RID Pool requests from all DCs within a given domain. It is also responsible for moving an object from one domain to another during an interdomain object move. When a DC creates a security principal object such as a user or group, it attaches a unique SID to the object. This SID consists of a domain SID (the same for all SIDs created in a domain) and a relative ID (RID) that is unique for each security principal SID created in a domain. Each DC in a domain is allocated a pool of RIDs that it is allowed to assign to the security principals it creates. When a DC's allocated RID pool falls below a threshold, that DC issues a request for additional RIDs to the domain's RID Master FSMO role owner, the RID Master FSMO role owner responds to the request by retrieving RIDs from the domain's unallocated RID pool and assigns them to the pool of the requesting DC. The Infrastructure Master The purpose of this role is to ensure that cross domain object references are correctly handled. For example, if a user from one domain is added to a security group from a different domain, the Infrastructure Master makes sure this is done properly. However, if the Active Directory deployment has only a single domain, then the Infrastructure Master role does no work at all, and even in a multi domain environment it is rarely used except when complex user administration tasks are performed. This applies to the domain partition (default naming context) only. and will only query the domain partition. However, every application partition, including Forest and Domain level DNS domain zones has its own Infrastructure Master. The holder of this role is stored in the attribute of the object in the root of the partition, it can be modified with , for example one can modify the attribute of the object to .
RID Master (Относительный идентификатор) Владелец этой роли FSMO является единственным контроллером домена, ответственным за обработку запросов на пулы RID от всех контроллеров домена в пределах данного домена. Он также отвечает за перемещение объекта из одного домена в другой при перемещении объекта между доменами. Когда контроллер домена создает объект безопасности, такой как пользователь или группа, он присваивает объекту уникальный SID. Этот SID состоит из SID домена (одинакового для всех SID, созданных в домене) и относительного идентификатора (RID), который уникален для каждого SID безопасности, созданного в домене. Каждому контроллеру домена в домене выделяется пул RID, который он может присваивать создаваемым им принципалам безопасности. Когда выделенный пул RID контроллера домена опускается ниже определенного порога, этот контроллер домена отправляет запрос на дополнительные RID владельцу роли RID Master FSMO домена. Владелец роли RID Master FSMO отвечает на запрос, извлекая RID из нераспределенного пула RID домена и назначая их пулу запрашивающего контроллера домена.
The PDC Emulator (Primary Domain Controller) This role is the most used of all FSMO roles and has the widest range of functions. The domain controller that holds the PDC Emulator role is crucial in a mixed environment where Windows NT 4.0 BDCs are still present. This is because the PDC Emulator role emulates the functions of a Windows NT 4.0 PDC. Even if all Windows NT 4.0 domain controllers have been migrated to Windows 2000 or later, the domain controller that holds the PDC Emulator role still does a lot. The PDC Emulator is the domain source for time synchronization for all other domain controllers; in a multi domain forest, the PDC Emulator in each domain synchronizes to the forest root PDC Emulator. All other domain member computers synchronize to their respective domain controllers. It is critically important that computer clocks are synchronized across the forest because excessive clock skew causes Kerberos authentication to fail. In addition, all password changes occur on the PDC Emulator and receive priority replication. The RID Master (Relative ID) This FSMO role owner is the single DC responsible for processing RID Pool requests from all DCs within a given domain. It is also responsible for moving an object from one domain to another during an interdomain object move. When a DC creates a security principal object such as a user or group, it attaches a unique SID to the object. This SID consists of a domain SID (the same for all SIDs created in a domain) and a relative ID (RID) that is unique for each security principal SID created in a domain. Each DC in a domain is allocated a pool of RIDs that it is allowed to assign to the security principals it creates. When a DC's allocated RID pool falls below a threshold, that DC issues a request for additional RIDs to the domain's RID Master FSMO role owner, the RID Master FSMO role owner responds to the request by retrieving RIDs from the domain's unallocated RID pool and assigns them to the pool of the requesting DC. The Infrastructure Master The purpose of this role is to ensure that cross domain object references are correctly handled. For example, if a user from one domain is added to a security group from a different domain, the Infrastructure Master makes sure this is done properly. However, if the Active Directory deployment has only a single domain, then the Infrastructure Master role does no work at all, and even in a multi domain environment it is rarely used except when complex user administration tasks are performed. This applies to the domain partition (default naming context) only. and will only query the domain partition. However, every application partition, including Forest and Domain level DNS domain zones has its own Infrastructure Master. The holder of this role is stored in the attribute of the object in the root of the partition, it can be modified with , for example one can modify the attribute of the object to .
Infrastructure Master (Мастер инфраструктуры) Цель этой роли – обеспечить правильную обработку междоменных ссылок на объекты. Например, если пользователь из одного домена добавлен в группу безопасности из другого домена, мастер инфраструктуры обеспечивает правильность выполнения этой операции. Однако, если развертывание Active Directory содержит только один домен, роль мастера инфраструктуры не выполняет никаких действий, и даже в многодоменной среде она редко используется, за исключением выполнения сложных задач администрирования пользователей. Это относится только к разделу домена (контекст именования по умолчанию) и будет выполняться только запрос к разделу домена. Однако каждый раздел приложения, включая зоны DNS на уровне леса и домена, имеет своего собственного мастера инфраструктуры. Владелец этой роли хранится в атрибуте объекта в корне раздела, его можно изменить с помощью , например, можно изменить атрибут объекта на .
The PDC Emulator (Primary Domain Controller) This role is the most used of all FSMO roles and has the widest range of functions. The domain controller that holds the PDC Emulator role is crucial in a mixed environment where Windows NT 4.0 BDCs are still present. This is because the PDC Emulator role emulates the functions of a Windows NT 4.0 PDC. Even if all Windows NT 4.0 domain controllers have been migrated to Windows 2000 or later, the domain controller that holds the PDC Emulator role still does a lot. The PDC Emulator is the domain source for time synchronization for all other domain controllers; in a multi domain forest, the PDC Emulator in each domain synchronizes to the forest root PDC Emulator. All other domain member computers synchronize to their respective domain controllers. It is critically important that computer clocks are synchronized across the forest because excessive clock skew causes Kerberos authentication to fail. In addition, all password changes occur on the PDC Emulator and receive priority replication. The RID Master (Relative ID) This FSMO role owner is the single DC responsible for processing RID Pool requests from all DCs within a given domain. It is also responsible for moving an object from one domain to another during an interdomain object move. When a DC creates a security principal object such as a user or group, it attaches a unique SID to the object. This SID consists of a domain SID (the same for all SIDs created in a domain) and a relative ID (RID) that is unique for each security principal SID created in a domain. Each DC in a domain is allocated a pool of RIDs that it is allowed to assign to the security principals it creates. When a DC's allocated RID pool falls below a threshold, that DC issues a request for additional RIDs to the domain's RID Master FSMO role owner, the RID Master FSMO role owner responds to the request by retrieving RIDs from the domain's unallocated RID pool and assigns them to the pool of the requesting DC. The Infrastructure Master The purpose of this role is to ensure that cross domain object references are correctly handled. For example, if a user from one domain is added to a security group from a different domain, the Infrastructure Master makes sure this is done properly. However, if the Active Directory deployment has only a single domain, then the Infrastructure Master role does no work at all, and even in a multi domain environment it is rarely used except when complex user administration tasks are performed. This applies to the domain partition (default naming context) only. and will only query the domain partition. However, every application partition, including Forest and Domain level DNS domain zones has its own Infrastructure Master. The holder of this role is stored in the attribute of the object in the root of the partition, it can be modified with , for example one can modify the attribute of the object to .
Перемещение ролей FSMO между контроллерами домена
По умолчанию AD назначает все роли операционного мастера первому контроллеру домена, созданному в лесу. Для обеспечения отказоустойчивости в каждом домене леса должно быть несколько контроллеров домена. Если в лесу создаются новые домены, первый контроллер домена в новом домене владеет всеми ролями FSMO в масштабе домена. Это не является оптимальным решением, если домен содержит большое количество контроллеров домена. Microsoft рекомендует тщательно разделять роли FSMO, имея резервные контроллеры домена, готовые к принятию каждой роли. Эмулятор PDC и мастер RID, по возможности, должны располагаться на одном контроллере домена. Мастер схемы и мастер именования доменов также должны находиться на одном контроллере домена. При передаче роли FSMO другому контроллеру домена, исходный и новый владелец роли обмениваются данными, чтобы гарантировать отсутствие потери данных в процессе передачи. Если исходный владелец роли FSMO столкнулся с необратимой ошибкой, другой контроллер домена может "перехватить" потерянные роли, однако существует риск потери данных из-за отсутствия связи. Перехват ролей у контроллера домена вместо их передачи предотвращает повторное размещение этой роли FSMO на этом контроллере домена, за исключением ролей эмулятора PDC и мастера инфраструктуры. В Active Directory может возникать повреждение данных. Роли FSMO можно легко перемещать между контроллерами домена с помощью оснасток AD в MMC или с помощью ntdsutil – инструмента командной строки.
Роли ФСМО и глобальный каталог
Некоторые роли FSMO также зависят от того, что контроллер домена (DC) является сервером глобального каталога (GC). При первоначальном создании леса первый контроллер домена по умолчанию является сервером глобального каталога. Глобальный каталог выполняет несколько функций. GC хранит информацию о данных объектов, управляет запросами к этим данным и их атрибутам, а также предоставляет данные, необходимые для сетевой аутентификации. Часто все контроллеры доменов также выступают в роли серверов глобального каталога. Если это не так, роль мастера инфраструктуры не должна размещаться на контроллере домена, который также содержит копию глобального каталога в лесу с несколькими доменами, поскольку сочетание этих двух ролей на одном хосте может привести к непредсказуемым (и потенциально опасным) последствиям в многодоменной среде. Однако роль мастера именования доменов должна размещаться на контроллере домена, который также является сервером глобального каталога.