Build a golden template, deploy two clones, and fix what cloning copies
Task
Turn a freshly installed Windows Server into a golden image with Sysprep, deploy two VMs from it, and prove each clone has its own identity -- computer name, machine SID and network address -- rather than a copy of the template's. Then do the Linux equivalent and find the identifiers cloning quietly duplicates.
Steps
- On the Windows template, run
sysprep /generalize /oobe /shutdown. Once it has shut down, clone it twice in the hypervisor asclone-aandclone-b. - Start both clones, complete setup with different computer names, and on each save
whoami /user(for the SID) andipconfig /alltolab/template/clone-a.txtandlab/template/clone-b.txt. - Clone lin-srv without any preparation, start the clone, and compare
/etc/machine-idand the SSH host key fingerprints with the original. Save both tolab/template/linux.txt. - Fix the Linux clone: clear
/etc/machine-idand regenerate it, and regenerate the SSH host keys. Save the new values tolab/template/linux-fixed.txt. - Record in
lab/template/checklist.txtthe identity items a template must reset, and which tool resets each.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Eo 'S-1-5-21-[0-9-]+' lab/template/clone-a.txt | sort -u
grep -Eo 'S-1-5-21-[0-9-]+' lab/template/clone-b.txt | sort -u
cat lab/template/clone-a.txt lab/template/clone-b.txt | grep -Eo 'S-1-5-21-[0-9]+-[0-9]+-[0-9]+' | sort -u | wc -l
grep -Eic 'machine-id|host key|ssh' lab/template/checklist.txt
The two clones must report different machine SID prefixes, so the third command prints 2. If it prints 1, Sysprep did not generalise the image. In the Linux files, the unprepared clone shares the original's machine-id and host keys, and the fixed clone does not -- duplicate host keys are how two servers become indistinguishable to SSH clients.
Notes
Hypervisor and cloud templates often run these resets automatically, with cloud-init on Linux and a generalised image on Windows. Knowing what they reset is what lets you recognise a clone that skipped the step.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.