Here is another resource for seizing Operation Masters - http://www.adminprep.com/a
It is a demo so you can watch and learn at the same time.
Brian
Main Topics
Browse All TopicsHello
We had a domain with 2 DCs, one of these (the first one) was irreperably damaged, with no backups. I am having problems with various things and it seems that it is because of the FSMO roles that are still held by the dead server. I have added a new DC to bring the number of DCs up to 2, and running dcdiag shows some problems (I have cut out the tests that passed to save space):
#NEWSERVER - the DC I just promoted
#OLDSERVER - the dead, irreperable server
#server2 - the second DC, unchanged
Starting test: KnowsOfRoleHolders
[OLDSERVER] DsBindWithSpnEx() failed with error 1722,
Win32 Error 1722.
Warning: OLDSERVER is the Schema Owner, but is not responding to DS RPC Bind.
[OLDSERVER] LDAP search failed with error 58,
Win32 Error 58.
Warning: OLDSERVER is the Schema Owner, but is not responding to LDAP Bind.
Warning: OLDSERVER is the Domain Owner, but is not responding to DS RPC Bind.
Warning: OLDSERVER is the Domain Owner, but is not responding to LDAP Bind.
Warning: OLDSERVER is the PDC Owner, but is not responding to DS RPC Bind
.
Warning: OLDSERVER is the PDC Owner, but is not responding to LDAP Bind. Warning: OLDSERVER is the Rid Owner, but is not responding to DS RPC Bind.
Warning: OLDSERVER is the Rid Owner, but is not responding to LDAP Bind.
Warning: OLDSERVER is the Infrastructure Update Owner, but is not respond
ing to DS RPC Bind.
Warning: OLDSERVER is the Infrastructure Update Owner, but is not respond
ing to LDAP Bind.
......................... NEWSERVER failed test KnowsOfRoleHolders
Starting test: RidManager
......................... NEWSERVER failed test RidManager
[snip]
Starting test: frsevent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
[snip]
Starting test: FsmoCheck
Warning: DcGetDcName(GC_SERVER_REQU
A Global Catalog Server could not be located - All GC's are down.
Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
A Primary Domain Controller could not be located.
The server holding the PDC role is down.
......................... domain.mydomain.net failed test FsmoCheck
So I now try to "sieze" the roles with the older, non-failing server. I understand that this will effectively cause the old dead server to need to be formatted if it needs to get rejoined to the network:
C:\>ntdsutil
ntdsutil: roles
fsmo maintenance: connections
server connections: connect to server server2
Binding to server2 ...
Connected to microlinkt using credentials of locally logged on user.
server connections: q
fsmo maintenance: sieze pdc
Error 80070057 parsing input - illegal syntax?
fsmo maintenance: Sieze PDC
Error 80070057 parsing input - illegal syntax?
fsmo maintenance:
Is there something else I should do? The error suggests improper syntax, but I have copied directly from the microsoft support page.
I am running a samba domain member, and this is failing because it cannot find a PDC, obviously because the PDC role server is offline. Any ideas how to get the roles transferred to the "living" servers?
Thanks
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Here is another resource for seizing Operation Masters - http://www.adminprep.com/a
It is a demo so you can watch and learn at the same time.
Brian
alimu, thanks I had spelled it wrong! shows what sorting these things out at 2:30am can do to you! I have changed the roles by seizing them, and the new server seems to slowly be realising it. Unfortunately the samba servers are still really confused, but that is another question I guess.
How can I now remove all the data in AD about the old dead server OLDSERVER? I saw something about some maintenance or something but cannot find it again.
OK, running dcdiag again gives a few problems:
Starting test: frsevent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... NEWSERVER failed test frsevent
[snip]
Starting test: systemlog
An Error Event occured. EventID: 0xC00009C9
Time Generated: 08/07/2005 12:17:54
Event String: The server could not bind to the transport
An Error Event occured. EventID: 0x825A0011
Time Generated: 08/07/2005 12:18:14
Event String: Time Provider NtpClient: An error occurred during
An Error Event occured. EventID: 0xC25A001D
Time Generated: 08/07/2005 12:18:14
Event String: The time provider NtpClient is configured to
An Error Event occured. EventID: 0x825A0011
Time Generated: 08/07/2005 12:18:48
Event String: Time Provider NtpClient: An error occurred during
An Error Event occured. EventID: 0xC25A001D
Time Generated: 08/07/2005 12:18:48
Event String: The time provider NtpClient is configured to
An Error Event occured. EventID: 0xC0001F60
Time Generated: 08/07/2005 12:21:05
Event String: The browser service has failed to retrieve the
An Error Event occured. EventID: 0xC25A001D
Time Generated: 08/07/2005 12:25:34
Event String: The time provider NtpClient is configured to
An Error Event occured. EventID: 0xC25A001D
Time Generated: 08/07/2005 12:47:22
Event String: The time provider NtpClient is configured to
......................... NEWSERVER failed test systemlog
[snip]
Starting test: FsmoCheck
Warning: DcGetDcName(GC_SERVER_REQU
A Global Catalog Server could not be located - All GC's are down.
......................... domain.mydomain.net failed test FsmoCheck
[snip]
I changed NEWSERVER to a GC in AD sites and services, and now it passes FsmoCheck, but there are a lot of errors about userenv in the application log:
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.
and
Windows cannot access the file gpt.ini for GPO CN={5CFEF03E-F84B-452E-B9C
So I'm not repeating what others have already said here I'm using PAQs where possible :)
Check your win32 time service is running, if yes have a look at this PAQ,
Netman66 takes a user through troubleshooting the ntp issues you're getting here:
http:/Q_21450017.html#1417
For "the server could not bind to the transport"
Do you have the File and Print Service component installed?
See: http://support.microsoft.c
For: "The browser service has failed to retrieve the"
Can you look at your system log, find and post the corresponding error so that we have all the details?
For: gpt.ini error, this is possibly to do with SMB signing so take a look at: http://support.microsoft.c
(sorry for sending you off to links, but they say it better than I ever could :) )
Let me know how you go, and if you post the systemlog event requested above, I'll check it out asap.
Hi, sorry for the delay getting back, I have been running around fixing the "small stuff".
#####
OK, the requested system log event:
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{BLA_B
#####
#####
This might be related?:
C:\>browstat status
Status for domain MYDOMAIN on transport \Device\NetBT_Tcpip_{BLA_B
Browsing is active on domain.
Master browser name is: server2
Master browser is running build 3790
3 backup servers retrieved from master server2
\\server2
\\(an old sql server - not DC)
\\(an old 2k server - not DC)
Unable to retrieve server list from server2: 64
#####
Why is it unable to retreive server list? (just a recap: server 2 is the old DC that did not crash, one of the 2 old ones)
#####
This was in the Directory Service log:
EVENT ID: 1307
SOURCE : NTDS KCC
The Knowledge Consistency Checker (KCC) has detected that attempts to establish a replication link with the following domain controller has consistently failed.
Attempts:
8
Domain controller:
CN=NTDS Settings,CN=OLDSERVER,CN=S
Period of time (minutes):
125
The Connection object for this domain controller will be ignored, and a new temporary connection will be established to ensure that replication continues. Once replication with this domain controller resumes, the temporary connection will be removed.
Additional Data
Error value:
1722 The RPC server is unavailable.
#####
I dont think this one is so serious, it is looking for the dead old server, which will never come back - I found something on removing this, but any suggestions welcome.
#####
Another wierd error:
This is the replication status for the following directory partition on the local domain controller.
Directory partition:
DC=DomainDnsZones,DC=mydom
The local domain controller has not received replication information from a number of domain controllers within the configured latency interval.
Latency Interval (Hours):
24
Number of domain controllers in all sites:
1
Number of domain controllers in this site:
1
#####
I guess this is also trying to sync with the dead OLDSERVER?
Group policy editing is a bit wierd, when I edit a GPO, it gives masses of warnings about truncating [string] for various GP entries, the [string] is the description of the various settings, ie This setting forces all users to get a clue. Default DISABLED. Is this because I have not yet installed SP1? Maybe that allowed for longer description fileds?
I have tried to just delete unneeded GPOs like login script, and make new ones, but the new ones do not seem to get applied.
Another thing is that I cannot remote desktop to the server any more. I will try to reboot tonight and see if that fixes it (it is installing SP1 now, so will need a boot anyway)
I think this is almost closed, as we seem to have a "just-about-functional" setup ATM, just these last bits.
Thanks
Apologies for taking so long to respond- have been in meetings all day.
Looks like replication's having problems because it thinks OLDSERVER still exists.
EVENT ID: 1307
SOURCE : NTDS KCC
...CN=OLDSERVER
--> says your server's having trouble replicating to OLDSERVER.
There's a section at the bottom of this KB (last blue section) on what to do after forcible removal of a DC
http://support.microsoft.c
perhaps checking through these items would wipe out the remnants of OLDSERVER in AD and make sure nothing's trying to get to it anymore.
Perhaps check that your servers aren't pointing to OLDSERVER for DNS also - this is often something that isn't caught after decommissioning a DC.
Will also see if I can get hold of one of our other Experts to give this the once-over.
I think you're almost there.
Make sure one of the remaining DCs is a Global Catalog and follow this article to get rid of the old DC from AD.
http://support.microsoft.c
Let us know.
Thanks guys - looks like it is back on track
I have made NEWSERVER a GC, by going into sites and services, and ticking the box for GC in NEWSERVER. No errors seem to be happening now. Its really funny about the spelling of that command, I came in the next day seeing that, and it got me started on a fix - its crazy how its usually always the simple things!
Business Accounts
Answer for Membership
by: alimuPosted on 2005-08-06 at 21:22:58ID: 14616346
Hi captainmish, e.com/Oper ating_Syst ems/ Window s_Server_2 003/Q_2126 3748.html# 12970569
PeteLong's got a good description of seizing roles here: http://www.experts-exchang
you may also want to check your spelling, that may be all that's wrong here - sieze should be seize
cheers,
alimu.