Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Windows PowerShell-based domain controller deployment repeats warnings


View products that this article applies to.

Symptoms

When you install Acrive Directory Domain Services (AD DS) on Windows Server 2012 domain controllers by using the Windows PowerShell AddsDeployment module, you receive the following message:

WARNING: Windows Server 2012 domain controllers have a default for the security setting named "Allow cryptography algorithms compatible with Windows NT 4.0" that prevents weaker cryptography algorithms when establishing security channel sessions.

For more information about this setting, see Knowledge Base article 942564
(http://go.microsoft.com/fwlink/?LinkId=104751).

WARNING: A delegation for this DNS server cannot be created because the authoritative parent zone cannot be found or it does not run Windows DNS server. If you are integrating with an existing DNS infrastructure, you should manually create a delegation to this DNS server in the parent zone to ensure reliable name resolution from outside the domain "corp.adatum.com". Otherwise, no action is required.

Then, this messages is displayed again.

↑ Back to the top


Cause

You first receive this message because of�the domain controller deployment prerequisite validation process that was added in Windows Server 2012. Then, you receive this message again�during the actual installation.�

When you install AD DS by using Windows Server 2012 Server Manager, you receive this message together with dialog boxes that make the message more understandable.�

↑ Back to the top


Resolution

To resolve this issue, ignore the message.

If you use the -SkipPreChecks:$true�argument,�you receive the message only one time. However, we do not recomment that you use this argument, because�the prerequisite checks prevent you from trying a domain controller installation that will fail.

↑ Back to the top


More information

Both messages are expected when you create a new AD DS forest. For more information about the DNS delegation warning, go to the following Microsoft TechNet website:�

↑ Back to the top


Keywords: KB2737416

↑ Back to the top

Article Info
Article ID : 2737416
Revision : 5
Created on : 9/19/2012
Published on : 9/19/2012
Exists online : False
Views : 660