Build a golden template, deploy two clones, and fix what cloning copies

applied · 60 min · Objective 2.1

Task

Turn a freshly installed Windows Server into a golden image with Sysprep, deploy two VMs from it, and prove each clone has its own identity -- computer name, machine SID and network address -- rather than a copy of the template's. Then do the Linux equivalent and find the identifiers cloning quietly duplicates.

Steps

  1. On the Windows template, run sysprep /generalize /oobe /shutdown. Once it has shut down, clone it twice in the hypervisor as clone-a and clone-b.
  2. Start both clones, complete setup with different computer names, and on each save whoami /user (for the SID) and ipconfig /all to lab/template/clone-a.txt and lab/template/clone-b.txt.
  3. Clone lin-srv without any preparation, start the clone, and compare /etc/machine-id and the SSH host key fingerprints with the original. Save both to lab/template/linux.txt.
  4. Fix the Linux clone: clear /etc/machine-id and regenerate it, and regenerate the SSH host keys. Save the new values to lab/template/linux-fixed.txt.
  5. Record in lab/template/checklist.txt the identity items a template must reset, and which tool resets each.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Eo 'S-1-5-21-[0-9-]+' lab/template/clone-a.txt | sort -u
grep -Eo 'S-1-5-21-[0-9-]+' lab/template/clone-b.txt | sort -u
cat lab/template/clone-a.txt lab/template/clone-b.txt | grep -Eo 'S-1-5-21-[0-9]+-[0-9]+-[0-9]+' | sort -u | wc -l
grep -Eic 'machine-id|host key|ssh' lab/template/checklist.txt

The two clones must report different machine SID prefixes, so the third command prints 2. If it prints 1, Sysprep did not generalise the image. In the Linux files, the unprepared clone shares the original's machine-id and host keys, and the fixed clone does not -- duplicate host keys are how two servers become indistinguishable to SSH clients.

Notes

Hypervisor and cloud templates often run these resets automatically, with cloud-init on Linux and a generalised image on Windows. Knowing what they reset is what lets you recognise a clone that skipped the step.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.