<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Follow up discussion on the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/03/26/39841.aspx</link><description>In my Blog about DHCP, DNS and the DNSUpdateProxy-Group I was stating that for security reasons you really don't need to use the DNSUpdateProxy-Groups for most scenarios. However Bob has asked a very good question, which is worth another entry in this</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>2K3 - Register PTR nur unsicher m?glich - Seite 2 - MCSEboard.de MCSE Forum</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/03/26/39841.aspx#1572386</link><pubDate>Fri, 04 Apr 2008 22:09:33 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1572386</guid><dc:creator>2K3 - Register PTR nur unsicher m?glich - Seite 2 - MCSEboard.de MCSE Forum</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;2K3 - Register PTR nur unsicher m?glich - Seite 2 - MCSEboard.de MCSE Forum&lt;/p&gt;
&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1572386" width="1" height="1"&gt;</description></item><item><title>re: Follow up discussion on the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/03/26/39841.aspx#60065</link><pubDate>Sun, 31 Jul 2005 22:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:60065</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>Hello Michel-Vincent,&lt;br&gt;&lt;br&gt;as I stated in &lt;a target="_new" href="http://msmvps.com/ulfbsimonweidner/archive/2004/11/15/19325.aspx"&gt;http://msmvps.com/ulfbsimonweidner/archive/2004/11/15/19325.aspx&lt;/a&gt; you are able to define an account which is used for the registration of the DNS-Records under WS2k3 and W2k SP2. In WS2k3 you can specify the account directly in the DHCP-Server Properties, in W2k you can let the service run under that account.&lt;br&gt;&lt;br&gt;So there's no need to put the DC in the DNSUpdateProxy-Group - just let DHCP register the records using a predefined account.&lt;br&gt;&lt;br&gt;Ulf&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=60065" width="1" height="1"&gt;</description></item><item><title>re: Follow up discussion on the DNSUpdateProxy-Group</title><link>http://msmvps.com/blogs/ulfbsimonweidner/archive/2005/03/26/39841.aspx#57953</link><pubDate>Mon, 18 Jul 2005 16:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:57953</guid><dc:creator>Ulf B. Simon-Weidner</dc:creator><description>Hello Simon&lt;br&gt;&lt;br&gt;Your description of the DNSUpdateProxy issue is clear.&lt;br&gt;But is there a solution to the DHCP + DC issue?&lt;br&gt;I understand one should not install an AD-integrated DNS on a W2K(3) server and have that server account be a member of the DNSUpdateProxy group, as critical entries in the _mscdcs zone will be unsecure.&lt;br&gt;&lt;br&gt;In other words, you cannot have the best of both worlds: if the DHCP/DC is a member of DNSUpdateProxy, it creates a security gap; if it is not, its computer account will become the sole owner of the clients record(s), and no one else will be able to update those records. Is this statement correct?&lt;br&gt;&lt;br&gt;Any solution/workaround to this issue? &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=57953" width="1" height="1"&gt;</description></item></channel></rss>