Question

ADPREP /domainprep /gpprep FAIL - HELP !!!

Asked by: Eric_Gennaoui

Hello Dear Experts,

I am currently in the process of promoting a new Windows Server 2008 into my Windows server 2003 Forest. The ADPREP /forestprep ran just fine, without errors.

Now, when trying with the /domainprep /gpprep switches, I have this following error :

"D:\sources\adprep>adprep.exe /domainprep /gpprep
Running domainprep ...

Domain-wide information has already been updated.
[Status/Consequence]
Adprep did not attempt to rerun this operation.

Adprep was unable to complete because the call back function failed.
[Status/Consequence]
Error message: (null)
[User Action]
Check the log file ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\2009092919255
7 directory for more information."

I looked at "'http://technet.microsoft.com/en-us/library/dd464018%28WS.10%29.aspx" and they say we have to disable the Anti-Virus, if there's one. i disable it, reran the command but still, no success.

I also looked at a post here "http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/Q_24478699.html?sfQueryTermInfo=1+adprep+domainprep+fail+gpprep" and the admin got whats look like the same error message than me. When looking at my 'policies' folder in my SYSVOL, everything seems to be fine. no error in the Event Viewers whatsoever....

One thing I must mention; I recently had to restore the policies on this server using a backup (due to some 1030/1058 errors), but not ALL the policies I had on the backup needed to be restored ( I stopped restoring when my server gave me  the event 1704 "Security policy in the Group policy objects has been applied successfully").

Here the most recent ADPREP log :

Adprep created the log file ADPrep.log under C:\WINDOWS\debug\adprep\logs\20090929192557 directory.


Adprep copied file D:\sources\adprep\schema.ini from installation point to local machine under directory C:\WINDOWS.


Adprep copied file D:\sources\adprep\schupgrade.cat from installation point to local machine under directory C:\WINDOWS\system32.


Adprep copied file D:\sources\adprep\PAS.ldf from installation point to local machine under directory C:\WINDOWS\system32.


Adprep successfully made the LDAP connection to the local Active Directory Domain Controller FS1.


Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is (null).


LDAP API ldap_search_s() finished, return code is 0x0


Adprep successfully retrieved information from the local Active Directory Domain Services.


Adprep successfully initialized global variables.[Status/Consequence]Adprep is continuing.


Domain-wide information has already been updated.[Status/Consequence]Adprep did not attempt to rerun this operation.


Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.


LDAP API ldap_search_s() finished, return code is 0x20


Adprep verified the state of operation cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local. [Status/Consequence]The operation has not run or is not currently running. It will be run next.


Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.


LDAP API ldap_search_s() finished, return code is 0x0


Adprep checked to verify whether operation cn=446f24ea-cfd5-4c52-8346-96e170bcb912,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local has completed.[Status/Consequence]The operation GUID already exists so Adprep did not attempt to rerun this operation but is continuing.


Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.


LDAP API ldap_search_s() finished, return code is 0x0


Adprep checked to verify whether operation cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local has completed.[Status/Consequence]The operation GUID already exists so Adprep did not attempt to rerun this operation but is continuing.


Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.


LDAP API ldap_search_s() finished, return code is 0x20


Adprep verified the state of operation cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local. [Status/Consequence]The operation has not run or is not currently running. It will be run next.


Adprep was unable to complete because the call back function failed. [Status/Consequence]Error message: (null)[User Action] Check the log file ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\20090929192557 directory for more information.


Adprep was unable to update domain information. [Status/Consequence]Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation.[User Action] Check the log file, ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\20090929192557 directory for more information.

I recently experienced other problems, seeing this post might give you clues for what is happenening now : http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_24745924.html

Now Im all lost regarding next actions to take....

Thanks in advance

Eric

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-09-29 at 16:48:54ID24772060
Tags

Windows Server 2008

,

Windows Server 2003

,

ADPREP

Topics

Windows 2003 Server

,

Windows Server 2008

,

Active Directory

Participating Experts
4
Points
500
Comments
18

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Adprep /domainprep fails. Please help!
    Hi all I have a single windows 2000 server as my DC exchange 2000 is also installed on this machine. I was able to run adprep \forestprep without a problem, but domainprep failed. Here are the details of the failure Adprep created the log file ADPrep.log under C:\WINNT\syst...
  2. adprep /domainprep problems adding 2003 server to 2…
    I am pulling my hair out over this one. I am trying to add a 2003 server to a 2000 domain. adprep /forestprep ran with no errors adprep /domainprep runs with the following error: Adprep created the log file ADPrep.log under C:\WINNT\system32\debug\adprep\logs\2004102109...
  3. Windows 2000 adprep /domainprep error
    Were running adprep on our Windows 2000 domain controller, so we can add a 2003 domain controller into a child domain. adprep /forestprep ran with no problems, everything completed successfully. adprep /domainprep produced the following error: This is the error returned...
  4. adprep /domainprep problem
    I am getting an error maessage when running adprep /domainprep on my infrastructure master. It is instructing me to connect to my schema master and run forestprep which I already did. I got the message that it completed successfully. here is the adprep.log: Adprep created...
  5. Verify adprep /forestprep and adprep /domainprep replic…
    We are adding two 2003 DCs (new install on new boxes) to our W2K domain this weekend. The only thing that I am unclear about is how to verify adprep /forestprep and then adprep /domainprep before proceeding to the next step. We currently have two W2K DCs here (including the ...
  6. Adprep /domainprep
    ok so I have read all the posts on here about this and it still will not finish. I have a problem though there is nol onger a win2k dc in the site. It crashed and I'm awaitng replacement parts from dell. We currently have a 2003 DC up and running with Exchange 2003 on it and ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: CynepMeHPosted on 2009-09-29 at 17:40:15ID: 25454743

As per log details, confirm your "infrastructure master" FSMO holder server is accessible. If it is not, find out why and bring it online. If you can't, seize infrastructure master role from another box and try running it again. Also try running DCDiag and NetDIAG.

 

by: CynepMeHPosted on 2009-09-29 at 17:41:40ID: 25454747

erm, I meant seize infrastructure master role from another DC (not just a box) :)  

 

by: defkamelPosted on 2009-09-29 at 18:25:51ID: 25454907

seems like the server you are running ADprep on can't find the infrastructure master role..

 "Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation."

go to command prompt and run  netdom query fsmo
see what server has the infrastructure master role. Make sure you can ping that server.. Make sure dns on the server you are running adprep from is pointing to a domain controller for DNS.

If this doesn't fix the issue run DCdiag  from a command prompt and try to resolve any issues that it reports..

 

by: dariusgPosted on 2009-09-29 at 19:09:06ID: 25455178

First thing run a dcdiag and post results with a ipconfig /all as well.

 

by: Eric_GennaouiPosted on 2009-09-29 at 19:16:33ID: 25455248


Hi and thanks for your quick reply,

I am working on the only available D.C on the network atm, it has all the roles since I had to seize em few weeks ago due to previous master D.C failure.
I ran a DcDiag. NetDiag, queried FSMO and even ipconfig /all, I could not find any error ! Here are the results (on 2 posts) :

FSMO HOLDER
----------------
C:\>netdom query fsmo
Schema owner                 FS1.domain.local

Domain role owner           FS1.domain.local

PDC role                          FS1.domain.local

RID pool manager            FS1.domain.local

Infrastructure owner        FS1.domain.local

The command completed successfully.
-----------------------------------

NETDIAG
-----------------------------------
C:\Program Files\Support Tools>netdiag

.....................................

    Computer Name: FS1
    DNS Host Name: FS1.domain.local
    System info : Microsoft Windows Server 2003 (Build 3790)
    Processor : x86 Family 6 Model 15 Stepping 11, GenuineIntel
    List of installed hotfixes :
        KB923561
        KB924667-v2
        KB925398_WMP64
        KB925902
        KB926122
        KB927891
        KB929123
        KB930178
        KB931784
        KB931836
        KB932168
        KB933729
        KB933854
        .... etc etc  
         
Netcard queries test . . . . . . . : Passed

Per interface results:

    Adapter : Local Area Connection 2

        Netcard queries test . . . : Passed

        Host Name. . . . . . . . . : FS1
        IP Address . . . . . . . . : 192.168.0.250
        Subnet Mask. . . . . . . . : 255.255.255.0
        Default Gateway. . . . . . : 192.168.0.1
        Dns Servers. . . . . . . . : 192.168.0.250
                                             192.168.0.254


        AutoConfiguration results. . . . . . : Passed

        Default gateway test . . . : Passed

        NetBT name test. . . . . . : Passed

        WINS service test. . . . . : Skipped
            There are no WINS servers configured for this interface.


Global results:

Domain membership test . . . . . . : Passed

NetBT transports test. . . . . . . : Passed
    List of NetBt transports currently configured:
        NetBT_Tcpip_{D3796B1F-84D7-4125-B19F-3358A75C9053}
    1 NetBt transport currently configured.

Autonet address test . . . . . . . : Passed

IP loopback ping test. . . . . . . : Passed

Default gateway test . . . . . . . : Passed

NetBT name test. . . . . . . . . . : Passed

Winsock test . . . . . . . . . . . : Passed

DNS test . . . . . . . . . . . . . : Passed
    PASS - All the DNS entries for DC are registered on DNS server '192.168.0.250'.
    PASS - All the DNS entries for DC are registered on DNS server '192.168.0.254'.

Redir and Browser test . . . . . . : Passed
    List of NetBt transports currently bound to the Redir
        NetBT_Tcpip_{D3796B1F-84D7-4125-B19F-3358A75C9053}
    The redir is bound to 1 NetBt transport.

    List of NetBt transports currently bound to the browser
        NetBT_Tcpip_{D3796B1F-84D7-4125-B19F-3358A75C9053}
    The browser is bound to 1 NetBt transport.

DC discovery test. . . . . . . . . : Passed

DC list test . . . . . . . . . . . : Passed

Trust relationship test. . . . . . : Skipped

Kerberos test. . . . . . . . . . . : Passed

LDAP test. . . . . . . . . . . . . : Passed

Bindings test. . . . . . . . . . . : Passed

WAN configuration test . . . . . . : Skipped
    No active remote access connections.

Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

    Note: run "netsh ipsec dynamic show /?" for more detailed information

The command completed successfully
--------------------------------------

IPCONFIG
-------------------------------------
Windows IP Configuration

   Host Name . . . . . . . . . . . . : FS1
   Primary Dns Suffix  . . . . . . . : domain.local
   Node Type . . . . . . . . . . . . : Unknown
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : domain.local

Ethernet adapter Local Area Connection 2:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : HP NC373i Multifunction Gigabit Server Ad
apter #2
   Physical Address. . . . . . . . . : 00-xx-xx-xx-xx-xx
   DHCP Enabled. . . . . . . . . . . : No
   IP Address. . . . . . . . . . . . : 192.168.0.250
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.0.1
   DNS Servers . . . . . . . . . . . : 192.168.0.250
                                                192.168.0.254
----------------------------------------


** DCDIAG will be on next post **

 

by: dariusgPosted on 2009-09-29 at 19:18:57ID: 25455257

Are both of these DCs functioning currently as DCs?

192.168.0.250
192.168.0.254

If the aren't then remove the IP address of the DNS server that isn't functioning currently run ipconfig /flushdns, ipconfig /registerdns, and dcdiag /fix.

Also, if you had a failed DC you need to run metadata cleanup to remove lingering objects in AD.

http://www.petri.co.il/delete_failed_dcs_from_ad.htm

 

by: Eric_GennaouiPosted on 2009-09-29 at 19:20:00ID: 25455264


DCDIAG
-------------------------

Domain Controller Diagnosis

Performing initial setup:
   * Verifying that the local machine FS1, is a DC.
   * Connecting to directory service on server FS1.
   * Collecting site info.
   * Identifying all servers.
   * Identifying all NC cross-refs.
   * Found 1 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\FS1
      Starting test: Connectivity
         * Active Directory LDAP Services Check
         * Active Directory RPC Services Check
         ......................... FS1 passed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\FS1
      Starting test: Replications
         * Replications Check
         * Replication Latency Check
            DC=ForestDnsZones,DC=domain,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            DC=DomainDnsZones,DC=domain,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            CN=Schema,CN=Configuration,DC=domain,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            CN=Configuration,DC=domain,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            DC=domain,DC=local
               Latency information for 1 entries in the vector were ignored.
                  1 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
         ......................... FS1 passed test Replications
      Test omitted by user request: Topology
      Test omitted by user request: CutoffServers
      Starting test: NCSecDesc
         * Security Permissions check for all NC's on DC FS1.
         * Security Permissions Check for
           DC=ForestDnsZones,DC=domain,DC=local
            (NDNC,Version 2)
         * Security Permissions Check for
           DC=DomainDnsZones,DC=domain,DC=local
            (NDNC,Version 2)
         * Security Permissions Check for
           CN=Schema,CN=Configuration,DC=domain,DC=local
            (Schema,Version 2)
         * Security Permissions Check for
           CN=Configuration,DC=domain,DC=local
            (Configuration,Version 2)
         * Security Permissions Check for
           DC=domain,DC=local
            (Domain,Version 2)
         ......................... FS1 passed test NCSecDesc
      Starting test: NetLogons
         * Network Logons Privileges Check
         Verified share \\FS1\netlogon
         Verified share \\FS1\sysvol
         ......................... FS1 passed test NetLogons
      Starting test: Advertising
         The DC FS1 is advertising itself as a DC and having a DS.
         The DC FS1 is advertising as an LDAP server
         The DC FS1 is advertising as having a writeable directory
         The DC FS1 is advertising as a Key Distribution Center
         The DC FS1 is advertising as a time server
         The DS FS1 is advertising as a GC.
         ......................... FS1 passed test Advertising
      Starting test: KnowsOfRoleHolders
         Role Schema Owner = CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
         Role Domain Owner = CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
         Role PDC Owner = CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
         Role Rid Owner = CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local
         ......................... FS1 passed test KnowsOfRoleHolders
      Starting test: RidManager
         * Available RID Pool for the Domain is 4107 to 1073741823
         * FS1.domain.local is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 3107 to 3606
         * rIDPreviousAllocationPool is 3107 to 3606
         * rIDNextRID: 3112
         ......................... FS1 passed test RidManager
      Starting test: MachineAccount
         Checking machine account for DC FS1 on DC FS1.
         * SPN found :LDAP/FS1.domain.local/domain.local
         * SPN found :LDAP/FS1.domain.local
         * SPN found :LDAP/FS1
         * SPN found :LDAP/FS1.domain.local/domain
         * SPN found :LDAP/20f9efb7-be68-4e89-a7d1-afbe84945379._msdcs.domain.local
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/20f9efb7-be68-4e89-a7d1-afbe84945379/domain.local
         * SPN found :HOST/FS1.domain.local/domain.local
         * SPN found :HOST/FS1.domain.local
         * SPN found :HOST/FS1
         * SPN found :HOST/FS1.domain.local/domain
         * SPN found :GC/FS1.domain.local/domain.local
         ......................... FS1 passed test MachineAccount
      Starting test: Services
         * Checking Service: Dnscache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: RpcSs
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... FS1 passed test Services
      Test omitted by user request: OutboundSecureChannels
      Starting test: ObjectsReplicated
         FS1 is in domain DC=domain,DC=local
         Checking for CN=FS1,OU=Domain Controllers,DC=domain,DC=local in domain DC=domain,DC=local on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local in domain CN=Configuration,DC=domain,DC=local on 1 servers
            Object is up-to-date on all servers.
         ......................... FS1 passed test ObjectsReplicated
      Starting test: frssysvol
         * The File Replication Service SYSVOL ready test
         File Replication Service's SYSVOL is ready
         ......................... FS1 passed test frssysvol
      Starting test: frsevent
         * The File Replication Service Event log test
         ......................... FS1 passed test frsevent
      Starting test: kccevent
         * The KCC Event log test
         Found no KCC errors in Directory Service Event log in the last 15 minutes.
         ......................... FS1 passed test kccevent
      Starting test: systemlog
         * The System Event log test
         Found no errors in System Event log in the last 60 minutes.
         ......................... FS1 passed test systemlog
      Test omitted by user request: VerifyReplicas
      Starting test: VerifyReferences
         The system object reference (serverReference)         CN=FS1,OU=Domain Controllers,DC=domain,DC=local and backlink on         CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local         are correct.
         The system object reference (frsComputerReferenceBL)         CN=FS1,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=domain,DC=local         and backlink on CN=FS1,OU=Domain Controllers,DC=domain,DC=local         are correct.
         The system object reference (serverReferenceBL)         CN=FS1,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=domain,DC=local         and backlink on         CN=NTDS Settings,CN=FS1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=domain,DC=local         are correct.
         ......................... FS1 passed test VerifyReferences
      Test omitted by user request: VerifyEnterpriseReferences
      Test omitted by user request: CheckSecurityError
   
   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
   
   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : domain
      Starting test: CrossRefValidation
         ......................... domain passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... domain passed test CheckSDRefDom
   
   Running enterprise tests on : domain.local
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope         provided by the command line arguments provided.
         ......................... domain.local passed test Intersite
      Starting test: FsmoCheck
         GC Name: \\FS1.domain.local
         Locator Flags: 0xe00003fd
         PDC Name: \\FS1.domain.local
         Locator Flags: 0xe00003fd
         Time Server Name: \\FS1.domain.local
         Locator Flags: 0xe00003fd
         Preferred Time Server Name: \\FS1.domain.local
         Locator Flags: 0xe00003fd
         KDC Name: \\FS1.domain.local
         Locator Flags: 0xe00003fd
         .....domain.............. domain.local passed test FsmoCheck
      Test omitted by user request: DNS
      Test omitted by user request: DNS
----------------------------------

So I am probably tired but I dont see a hint here that could help me resolv this issue... Worst thing is, I prepared myself by creating virtual labs (3 times!!) first and was successful in all my atempts. Only difference was that I did not have an anti-virus on the virtual servers.

Thanks again for your time and help  

Regards

 

by: dariusgPosted on 2009-09-29 at 19:23:32ID: 25455277

If you had a failed DC then you need to run a metadata cleanup. Have you done this? How about the DNS servers?

 

by: Eric_GennaouiPosted on 2009-09-29 at 19:25:41ID: 25455283


Hi DariusQ,

Quoting:
"Are both of these DCs functioning currently as DCs?

192.168.0.250
192.168.0.254"

Only the .250 is a D.C atm, I was in the process of promoting the .254; I installed binaries on the 2008,  then went on the 2003 to run /forestprep, which ran fine, but no the /domainprep /gpprep.

Couple of minutes before attempting the promote, I installed the DNS service on the new server and reboot both of em. Both event viewers were showing ok and replication/transfer was made without problems.

 

by: Eric_GennaouiPosted on 2009-09-29 at 19:27:53ID: 25455291


"If you had a failed DC then you need to run a metadata cleanup. Have you done this? How about the DNS servers?"

The failed D.C was cleaned out (A.D, DNS, FRS metadata cleanup) last week as on this post "http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_24745924.html" and everything was running fine since.

 

by: dariusgPosted on 2009-09-29 at 19:32:03ID: 25455302

Remove the DNS server that currently isn't a DC then run domainprep since gpprep isn't needed. Make sure you are logged on as a Enterprise Admin that is part of the Domain Admin group.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/Q_23582347.html

 

by: dariusgPosted on 2009-09-29 at 19:39:09ID: 25455327

After reading a little more into the log it states that the domainprep has already been ran which is causing the error. Domainprep will not run again so it will error out. Read through the log the call back function will not pass since it has already been run.

 

by: Eric_GennaouiPosted on 2009-09-29 at 20:09:04ID: 25455405


Hi again dariusq and thanks for taking the time to help me,

I pasted here the last lines of my FIRST "Adprep /domainprep /gpprep" log here, maybe it can explain your previous statement (id 25455327), but I honestly dont know what it means exactly  ;s   Please take a look at my comments    "<------comment"  :

"Adprep invoked the call back function UpgradeDSGPOs.

[Status/Consequence]

The call back function finished successfully.             <-----------------Are you talking about this statement ??

Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.

LDAP API ldap_add_s() finished, return code is 0x0

Adprep successfully created the Active Directory Domain Services object cn=51cba88b-99cf-4e16-bef2-c427b38d0767,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.

Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.

LDAP API ldap_search_s() finished, return code is 0x20                       <----------------- Here's were it failed I think

Adprep verified the state of operation cn=a3dac986-80e7-4e59-a059-54cb1ab43cb9,cn=Operations,cn=DomainUpdates,cn=System,DC=domain,DC=local.

[Status/Consequence]

The operation has not run or is not currently running. It will be run next.

Adprep was unable to complete because the call back function failed.                  

[Status/Consequence]

Error message: (null)                                                 <-------------- Ever encountered this one ??

[User Action]

Check the log file ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\20090929181036 directory for more information.

Adprep was unable to update domain information.

[Status/Consequence]

Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation.      <----------I am running everything from the only D.C we have that is FSMO role holder.

[User Action]

Check the log file, ADPrep.log, in the C:\WINDOWS\debug\adprep\logs\20090929181036 directory for more information.    <-------- All previous lines were taken from this log
-------------------------

As I stated, my adprep /forestprep was just fine. So I really dont know whats causing this error; should I just ignore it and try to run dcpromo on the new server ? or should I reboot and retry the /domainprep /gpprep ?

Regards

 

by: Eric_GennaouiPosted on 2009-09-29 at 21:41:33ID: 25455687


Sorry, in the hurry, |I skipped your comment ID:25455302, stating that /gpprep is not needed. So if I understand correctly my case, the /domainprep I did succeeded exception made of the /gpprep ? Does that mean I could keep going on with the dcpromo and disregard this error ?

As for the DNS installed on the server 2008, it was a nice suggestion from ChiefIT on my post  http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_24745924.html. I did some testlabs and was successful with this method (install/replicate DNS prior to install A.D), so I'm not sure uninstalling it on the windows 2008 (since the replication works well) would do the trick.

Thanks again for your patience !!


 

by: AwinishPosted on 2009-09-30 at 03:27:34ID: 25457054

Yes, gpprep is not needed.SInce you have udated adprep /forestprep it updated everything as you have single forest & single forest covered yoyr domain too.
Even you can notice from your log

"D:\sources\adprep>adprep.exe /domainprep /gpprep
Running domainprep ...

Domain-wide information has already been updated.
[Status/Consequence]

So,the command is completed & you can go ahead with configuring new dc.

 

by: Eric_GennaouiPosted on 2009-09-30 at 05:33:34ID: 25457968


Ok, I will go ahead with the dcpromo then. Is it safe to run it during business hours or should I wait after the office is closed (any impact on performance or can it cause problem since peoples are connected) ?

Im on my way to the office to try it

 

by: dariusgPosted on 2009-09-30 at 05:53:22ID: 25458222

How is it going?

 

by: Eric_GennaouiPosted on 2009-09-30 at 08:06:08ID: 25459697


Succeeded !

The new windows server 2008 is now acting as a backup D.C and DNS. I could complete the dcpromo without problems !

I only had some minor errors at first but upon rebooting, the DNS/A.D were successfully replicated.

Thanks a LOT again ALL for your time and help, I will award the points to Dariusq and Awinish (for the last minute comment that helped me)

Case closed and Bless you all !

Eric

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...