Question

Main DC not recoverable - next step?

Asked by: captainmish

Hello
We had a domain with 2 DCs, one of these (the first one) was irreperably damaged, with no backups. I am having problems with various things and it seems that it is because of the FSMO roles that are still held by the dead server. I have added a new DC to bring the number of DCs up to 2, and running dcdiag shows some problems (I have cut out the tests that passed to save space):
#NEWSERVER - the DC I just promoted
#OLDSERVER - the dead, irreperable server
#server2 - the second DC, unchanged

Starting test: KnowsOfRoleHolders
         [OLDSERVER] DsBindWithSpnEx() failed with error 1722,
         Win32 Error 1722.
         Warning: OLDSERVER is the Schema Owner, but is not responding to DS RPC Bind.
         [OLDSERVER] LDAP search failed with error 58,
         Win32 Error 58.
         Warning: OLDSERVER is the Schema Owner, but is not responding to LDAP Bind.
         Warning: OLDSERVER is the Domain Owner, but is not responding to DS RPC Bind.
         Warning: OLDSERVER is the Domain Owner, but is not responding to LDAP Bind.
         Warning: OLDSERVER is the PDC Owner, but is not responding to DS RPC Bind
.
         Warning: OLDSERVER is the PDC Owner, but is not responding to LDAP Bind.          Warning: OLDSERVER is the Rid Owner, but is not responding to DS RPC Bind.
         Warning: OLDSERVER is the Rid Owner, but is not responding to LDAP Bind.
         Warning: OLDSERVER is the Infrastructure Update Owner, but is not respond
ing to DS RPC Bind.
         Warning: OLDSERVER is the Infrastructure Update Owner, but is not respond
ing to LDAP Bind.
         ......................... NEWSERVER failed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... NEWSERVER failed test RidManager
[snip]
      Starting test: frsevent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
[snip]
      Starting test: FsmoCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
         A Global Catalog Server could not be located - All GC's are down.
         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
         A Primary Domain Controller could not be located.
         The server holding the PDC role is down.
         ......................... domain.mydomain.net failed test FsmoCheck

So I now try to "sieze" the roles with the older, non-failing server. I understand that this will effectively cause the old dead server to need to be formatted if it needs to get rejoined to the network:

C:\>ntdsutil
ntdsutil: roles
fsmo maintenance: connections
server connections: connect to server server2
Binding to server2 ...
Connected to microlinkt using credentials of locally logged on user.
server connections: q
fsmo maintenance: sieze pdc
Error 80070057 parsing input - illegal syntax?
fsmo maintenance: Sieze PDC
Error 80070057 parsing input - illegal syntax?
fsmo maintenance:

Is there something else I should do? The error suggests improper syntax, but I have copied directly from the microsoft support page.
I am running a samba domain member, and this is failing because it cannot find a PDC, obviously because the PDC role server is offline. Any ideas how to get the roles transferred to the "living" servers?
Thanks

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2005-08-06 at 18:15:04ID21518295
Tags

error

,

80070057

Topic

Windows 2003 Server

Participating Experts
3
Points
500
Comments
11

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Troubles with ldap configure with samba
    I 've been trying to configure an ldap server to be a samba PDC for windows ws, but it was imposible to do with all the howtos in the net. I have a Debian distribution, with Openldap 2.1.17 and samba 3.0 (the same happen with Samba 2.2.6) and I follow the instruction of htt...
  2. exchange server on DC, DC demoted and promoted to sa…
    heh, I have a test server i have as a child domain with 2003 exchange installed. i had a issue with dns and demoted it. i then re-promoted it as the same child domain. (only dc in child domain so the domain was completely removed. exchange is upset :) any way to recover fr...
  3. ldap + samba
    Hey All, I'm trying to get ldap and samba working together. There are tons of docs out there and each one is different than the next. I have been using ldap for user names and authentication for a couple years now. I don't have any users in samba everything right now is on l...
  4. Samba PDC + samba BDC + ldap backend
    Hello, I have another samba related question.I have setup a box with Debian etch, it is currently by PDC with a backend of ldap. Both the ldap directory and samba is installed on this box. I setup another box, which will act as my BDC, this box will also host file shares f...
  5. Connecting to Samba LDAP using powershell
    I am trying to connect to my Samba LDAP I have on a apple xserver. The Powershell command I try is: $DN = "LDAP://PC1/dc=penncharter,dc=com" $de = New-Object System.DirectoryServices.DirectoryEntry($DN) and I get this error: out-lineoutput : Exception retrieving ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: alimuPosted on 2005-08-06 at 21:22:58ID: 14616346

Hi captainmish,
PeteLong's got a good description of seizing roles here: http://www.experts-exchange.com/Operating_Systems/Windows_Server_2003/Q_21263748.html#12970569

you may also want to check your spelling, that may be all that's wrong here - sieze should be seize

cheers,
alimu.

 

by: mkbeanPosted on 2005-08-06 at 22:29:56ID: 14616458

Here is another resource for seizing Operation Masters - http://www.adminprep.com/articles/default.asp?action=show&articleid=80

It is a demo so you can watch and learn at the same time.

Brian

 

by: captainmishPosted on 2005-08-07 at 04:29:51ID: 14617068

alimu, thanks I had spelled it wrong! shows what sorting these things out at 2:30am can do to you! I have changed the roles by seizing them, and the new server seems to slowly be realising it. Unfortunately the samba servers are still really confused, but that is another question I guess.
How can I now remove all the data in AD about the old dead server OLDSERVER? I saw something about some maintenance or something but cannot find it again.

 

by: captainmishPosted on 2005-08-07 at 05:55:52ID: 14617261

OK, running dcdiag again gives a few problems:
 Starting test: frsevent
    There are warning or error events within the last 24 hours after the
    SYSVOL has been shared.  Failing SYSVOL replication problems may cause
    Group Policy problems.
    ......................... NEWSERVER failed test frsevent
[snip]
 Starting test: systemlog
    An Error Event occured.  EventID: 0xC00009C9
       Time Generated: 08/07/2005   12:17:54
       Event String: The server could not bind to the transport
    An Error Event occured.  EventID: 0x825A0011
       Time Generated: 08/07/2005   12:18:14
       Event String: Time Provider NtpClient: An error occurred during
    An Error Event occured.  EventID: 0xC25A001D
       Time Generated: 08/07/2005   12:18:14
       Event String: The time provider NtpClient is configured to
    An Error Event occured.  EventID: 0x825A0011
       Time Generated: 08/07/2005   12:18:48
       Event String: Time Provider NtpClient: An error occurred during
    An Error Event occured.  EventID: 0xC25A001D
       Time Generated: 08/07/2005   12:18:48
       Event String: The time provider NtpClient is configured to
    An Error Event occured.  EventID: 0xC0001F60
       Time Generated: 08/07/2005   12:21:05
       Event String: The browser service has failed to retrieve the
    An Error Event occured.  EventID: 0xC25A001D
       Time Generated: 08/07/2005   12:25:34
       Event String: The time provider NtpClient is configured to
    An Error Event occured.  EventID: 0xC25A001D
       Time Generated: 08/07/2005   12:47:22
       Event String: The time provider NtpClient is configured to
    ......................... NEWSERVER failed test systemlog
[snip]
      Starting test: FsmoCheck
         Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
         A Global Catalog Server could not be located - All GC's are down.
         ......................... domain.mydomain.net failed test FsmoCheck
[snip]

I changed NEWSERVER to a GC in AD sites and services, and now it passes FsmoCheck, but there are a lot of errors about userenv in the application log:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
and
Windows cannot access the file gpt.ini for GPO CN={5CFEF03E-F84B-452E-B9C7-XXXXXXXXXX},CN=Policies,CN=System,DC=domain,DC=mydomain,DC=net. The file must be present at the location <\\domain.mydomain.net\SysVol\domain.mydomain.net\Policies\{5CFEF03E-F84B-452E-B9C7-XXXXXXXXXXX}\gpt.ini>. (Access is denied. ). Group Policy processing aborted.  (The names were changed and XXXs were put in SIDs to protect the innocent :)

 

by: alimuPosted on 2005-08-07 at 21:51:57ID: 14620851

So I'm not repeating what others have already said here I'm using PAQs where possible :)

Check your win32 time service is running, if yes have a look at this PAQ,
Netman66 takes a user through troubleshooting the ntp issues you're getting here:
http:/Q_21450017.html#14171197

For "the server could not bind to the transport"
Do you have the File and Print Service component installed?
See: http://support.microsoft.com/?kbid=314872

For: "The browser service has failed to retrieve the"
Can you look at your system log, find and post the corresponding error so that we have all the details?

For: gpt.ini error, this is possibly to do with SMB signing so take a look at: http://support.microsoft.com/?kbid=839499

(sorry for sending you off to links, but they say it better than I ever could :)  )

Let me know how you go, and if you post the systemlog event requested above, I'll check it out asap.

 

by: captainmishPosted on 2005-08-08 at 05:31:54ID: 14622584

Hi, sorry for the delay getting back, I have been running around fixing the "small stuff".

#####
OK, the requested system log event:
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{BLA_BLA_BLA}. The backup browser is stopping.
#####

#####
This might be related?:
C:\>browstat status
Status for domain MYDOMAIN on transport \Device\NetBT_Tcpip_{BLA_BLA_BLA}
    Browsing is active on domain.
    Master browser name is: server2
        Master browser is running build 3790
    3 backup servers retrieved from master server2
        \\server2
        \\(an old sql server - not DC)
        \\(an old 2k server - not DC)
    Unable to retrieve server list from server2: 64
#####
Why is it unable to retreive server list? (just a recap: server 2 is the old DC that did not crash, one of the 2 old ones)

#####
This was in the Directory Service log:
EVENT ID: 1307
SOURCE  : NTDS KCC
The Knowledge Consistency Checker (KCC) has detected that attempts to establish a replication link with the following domain controller has consistently failed.  
Attempts:
8
Domain controller:
CN=NTDS Settings,CN=OLDSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=microlinkhouse,DC=microlink,DC=ne
Period of time (minutes):
125
The Connection object for this domain controller will be ignored, and a new temporary connection will be established to ensure that replication continues. Once replication with this domain controller resumes, the temporary connection will be removed.
Additional Data
Error value:
1722 The RPC server is unavailable.
#####
I dont think this one is so serious, it is looking for the dead old server, which will never come back - I found something on removing this, but any suggestions welcome.


#####
Another wierd error:
This is the replication status for the following directory partition on the local domain controller.
Directory partition:
DC=DomainDnsZones,DC=mydomain,DC=mydomain,DC=net
The local domain controller has not received replication information from a number of domain controllers within the configured latency interval.
Latency Interval (Hours):
24
Number of domain controllers in all sites:
1
Number of domain controllers in this site:
1
#####
I guess this is also trying to sync with the dead OLDSERVER?

Group policy editing is a bit wierd, when I edit a GPO, it gives masses of warnings about truncating [string] for various GP entries, the [string] is the description of the various settings, ie This setting forces all users to get a clue. Default DISABLED. Is this because I have not yet installed SP1? Maybe that allowed for longer description fileds?
I have tried to just delete unneeded GPOs like login script, and make new ones, but the new ones do not seem to get applied.

Another thing is that I cannot remote desktop to the server any more. I will try to reboot tonight and see if that fixes it (it is installing SP1 now, so will need a boot anyway)

I think this is almost closed, as we seem to have a "just-about-functional" setup ATM, just these last bits.
Thanks

 

by: alimuPosted on 2005-08-08 at 23:31:50ID: 14630255

Apologies for taking so long to respond- have been in meetings all day.

Looks like replication's having problems because it thinks OLDSERVER still exists.

EVENT ID: 1307
SOURCE  : NTDS KCC
...CN=OLDSERVER
--> says your server's having trouble replicating to OLDSERVER.

There's a section at the bottom of this KB (last blue section) on what to do after forcible removal of a DC
http://support.microsoft.com/?kbid=332199
perhaps checking through these items would wipe out the remnants of OLDSERVER in AD and make sure nothing's trying to get to it anymore.

Perhaps check that your servers aren't pointing to OLDSERVER for DNS also - this is often something that isn't caught after decommissioning a DC.
Will also see if I can get hold of one of our other Experts to give this the once-over.

 

by: Netman66Posted on 2005-08-09 at 18:10:31ID: 14638371

I think you're almost there.

Make sure one of the remaining DCs is a Global Catalog and follow this article to get rid of the old DC from AD.

http://support.microsoft.com/default.aspx?scid=kb;en-us;216498

Let us know.

 

by: captainmishPosted on 2005-08-10 at 02:15:16ID: 14640049

Thanks guys - looks like it is back on track
I have made NEWSERVER a GC, by going into sites and services, and ticking the box for GC in NEWSERVER. No errors seem to be happening now. Its really funny about the spelling of that command, I came in the next day seeing that, and it got me started on a fix - its crazy how its usually always the simple things!

 

by: alimuPosted on 2005-08-10 at 02:46:46ID: 14640172

thanks for the points, fantastic that it's all sorted.
...and Netman66 - thanks for the help, knew it'd be worth you having a look-in :)

 

by: Netman66Posted on 2005-08-10 at 16:45:27ID: 14647926

Anytime!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...