Here the deal
Ive got a newly installed SBS 2003 R2 Prem everything installed in perfectly working condition except for the fact that the bloody clients wont join the domain.
What I experience is this
The join command creates the machineaccount in the AD but then fails to connect the client to the account, ends up disabling the account in AD and drops me an error description like RPC failed although RPSS is running smoothly and can be easily reached through telnet.
Ive tried to join in any possible way I can think of e.g. using the SBS wizard,from the client including using netdom and even vbs scripts.
Having googled for 2 days now and throwing just about any variation of dcdiag/netdiag at my server Im at a complete loss.
Ive narrowed the problem down to 2 things I guess but dont hold back on further suggestions:
Problem 1
Netsetup.log shows terminates after this error:
NetpGetComputerObjectDn: Unable to bind to DS on '\\ABINTFS1': 0x6be
This is weird as dcdiag and netdiag shows no such problems on the server.
Problem 2
netdiag /test:DsGetDc /d:mba-aalborg.local /v
shows that DCs address as the WAN side of the server .
Ive tried to disable the WAN Side NIC which solved this problem temporarily but it didnt fix the joining issue.
Ive included some documentation from the client as well as the server, hope its sufficient otherwise please feel free to request more info.
As for how many points is at stake well whats the maximum limit?
Client:
Win XP Pro SP2 - FW disabled
C:\Programmer\Support Tools>nltest /dsgetdc:mba-aalborg.local
DC: \\abintfs1.mba-aalborg.loc
al
Address: \\10.0.0.2
Dom Guid: f66211d3-4f94-4d83-a729-7b
1205d3c635
Dom Name: mba-aalborg.local
Forest Name: mba-aalborg.local
Dc Site Name: Default-First-Site-Name
Our Site Name: Default-First-Site-Name
Flags: PDC GC DS LDAP KDC TIMESERV WRITABLE DNS_DC DNS_DOMAIN DNS_FOREST
CLOSE_SITE
The command completed successfully
C:\>ipconfig /all
Windows IP-konfiguration
Værtsnavn. . . . . . . . . . . . . . . . . . : Dorthe
Primært DNS-suffiks. . . . . . . . . . . . . :
Nodetype . . . . . . . . . . . . . . . . . . : Hybrid
IP-routing aktiveret . . . . . . . . . . . . : Nej
WINS-proxy aktiveret . . . . . . . . . . . . : Nej
Søgeliste for DNS-suffiks. . . . . . . . . . : mba-aalborg.local
Ethernet-netværkskort Trådløs netværksforbindelse:
Medietilstand. . . . . . . . . . . . . . . . : Mediet afbrudt
Beskrivelse. . . . . . . . . . . . . . . . . : Intel(R) PRO/Wireless 2915A
BG Network Connection
Fysisk adresse . . . . . . . . . . . . . . . : 00-12-F0-7D-5F-89
Ethernet-netværkskort LAN-forbindelse:
Forbindelsesspecifikt DNS-suffiks. . . . . . : mba-aalborg.local
Beskrivelse. . . . . . . . . . . . . . . . . : Marvell Yukon Gigabit Ether
net 10/100/1000Base-T Adapter, Copper RJ-45
Fysisk adresse . . . . . . . . . . . . . . . : 00-13-D4-BF-75-01
Dhcp aktiveret . . . . . . . . . . . . . . . : Ja
Automatisk konfiguration aktiveret . . . . . : Ja
IP-adresse . . . . . . . . . . . . . . . . . : 10.0.0.20
Undernetmaske. . . . . . . . . . . . . . . . : 255.255.255.0
Standardgateway. . . . . . . . . . . . . . . : 10.0.0.2
DHCP-server. . . . . . . . . . . . . . . . . : 10.0.0.2
DNS-servere. . . . . . . . . . . . . . . . . : 10.0.0.2
Primær WINS-server . . . . . . . . . . . . . : 10.0.0.2
Rettigheden opnået . . . . . . . . . . . . . : 1. februar 2007 08:32:28
Rettigheden udløber. . . . . . . . . . . . . : 9. februar 2007 08:32:28
NETSETUP.log
02/01 10:49:36 --------------------------
----------
----------
----------
---------
02/01 10:49:36 NetpDoDomainJoin
02/01 10:49:36 NetpMachineValidToJoin: 'DORTHE'
02/01 10:49:36 NetpGetLsaPrimaryDomain: status: 0x0
02/01 10:49:36 NetpMachineValidToJoin: status: 0x0
02/01 10:49:36 NetpJoinDomain
02/01 10:49:36 Machine: DORTHE
02/01 10:49:36 Domain: mbadom
02/01 10:49:36 MachineAccountOU: (NULL)
02/01 10:49:36 Account: mbadom\administrator
02/01 10:49:36 Options: 0x3
02/01 10:49:36 OS Version: 5.1
02/01 10:49:36 Build number: 2600
02/01 10:49:36 ServicePack: Service Pack 2
02/01 10:49:36 NetpValidateName: checking to see if 'mbadom' is valid as type 3 name
02/01 10:49:36 NetpCheckDomainNameIsValid
[ Exists ] for 'mbadom' returned 0x0
02/01 10:49:36 NetpValidateName: name 'mbadom' is valid for type 3
02/01 10:49:36 NetpDsGetDcName: trying to find DC in domain 'mbadom', flags: 0x1020
02/01 10:49:51 NetpDsGetDcName: failed to find a DC having account 'DORTHE$': 0x525
02/01 10:49:51 NetpDsGetDcName: found DC '\\ABINTFS1' in the specified domain
02/01 10:49:52 NetpJoinDomain: status of connecting to dc '\\ABINTFS1': 0x0
02/01 10:49:52 NetpGetLsaPrimaryDomain: status: 0x0
02/01 10:49:52 NetpGetDnsHostName: Read NV Hostname: Dorthe
02/01 10:49:52 NetpGetDnsHostName: PrimaryDnsSuffix defaulted to DNS domain name: mba-aalborg.local
02/01 10:49:52 NetpLsaOpenSecret: status: 0xc0000034
02/01 10:49:52 NetpManageMachineAccountWi
thSid: NetUserAdd on '\\ABINTFS1' for 'DORTHE$' failed: 0x8b0
02/01 10:49:52 NetpManageMachineAccountWi
thSid: status of attempting to set password on '\\ABINTFS1' for 'DORTHE$': 0x0
02/01 10:49:52 NetpJoinDomain: status of creating account: 0x0
02/01 10:49:52 NetpGetComputerObjectDn: Unable to bind to DS on '\\ABINTFS1': 0x6be
02/01 10:49:52 NetpSetDnsHostNameAndSpn: NetpGetComputerObjectDn failed: 0x6be
02/01 10:49:52 ldap_unbind status: 0x0
02/01 10:49:52 NetpJoinDomain: status of setting DnsHostName and SPN: 0x6be
02/01 10:49:52 NetpJoinDomain: initiaing a rollback due to earlier errors
02/01 10:49:52 NetpGetLsaPrimaryDomain: status: 0x0
02/01 10:49:52 NetpManageMachineAccountWi
thSid: status of disabling account 'DORTHE$' on '\\ABINTFS1': 0x0
02/01 10:49:52 NetpJoinDomain: rollback: status of deleting computer account: 0x0
02/01 10:49:52 NetpLsaOpenSecret: status: 0x0
02/01 10:49:52 NetpJoinDomain: rollback: status of deleting secret: 0x0
02/01 10:49:52 NetpJoinDomain: status of disconnecting from '\\ABINTFS1': 0x0
02/01 10:49:52 NetpDoDomainJoin: status: 0x6be
Server:
SBS 2003 R2 Prem
C:\>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : abintfs1
Primary Dns Suffix . . . . . . . : mba-aalborg.local
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : Yes
DNS Suffix Search List. . . . . . : mba-aalborg.local
Ethernet adapter WAN:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/1000 GT Desktop Adapter
Physical Address. . . . . . . . . : 00-0E-0C-B0-07-C8
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 192.168.1.102
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.100
DNS Servers . . . . . . . . . . . : 10.0.0.2
NetBIOS over Tcpip. . . . . . . . : Disabled
Ethernet adapter LAN:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom NetXtreme Gigabit Ethernet
Physical Address. . . . . . . . . : 00-30-05-C6-13-78
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2
C:\>netdiag /test:DsGetDc /d:mba-aalborg.local /v
Gathering IPX configuration information.
Querying status of the Netcard drivers... Passed
Testing Domain membership... Passed
Gathering NetBT configuration information.
Testing DC discovery.
Looking for a DC
Looking for a PDC emulator
Looking for an Active Directory DC
Tests complete.
Computer Name: ABINTFS1
DNS Host Name: abintfs1.mba-aalborg.local
DNS Domain Name: mba-aalborg.local
System info : Microsoft Windows Server 2003 (Build 3790)
Processor : x86 Family 15 Model 4 Stepping 3, GenuineIntel
Hotfixes :
Installed? Name
Yes KB893756
Yes KB896358
Yes KB896424
Yes KB896428
Yes KB898715
Yes KB899587
Yes KB899588
Yes KB899589
Yes KB899591
Yes KB900725
Yes KB901017
Yes KB901214
Yes KB902400
Yes KB904706
Yes KB904942
Yes KB905414
Yes KB908519
Yes KB908531
Yes KB908981
Yes KB909520
Yes KB910437
Yes KB911164
Yes KB911280
Yes KB911562
Yes KB911897
Yes KB911927
Yes KB912812
Yes KB912919
Yes KB914388
Yes KB914389
Yes KB914783
Yes KB917344
Yes KB917422
Yes KB917537
Yes KB917734
Yes KB917953
Yes KB918439
Yes KB918500
Yes KB920213
Yes KB920670
Yes KB920683
Yes KB920685
Yes KB921398
Yes KB921883
Yes KB922582
Yes KB922616
Yes KB922819
Yes KB923191
Yes KB923414
Yes KB923689
Yes KB923694
Yes KB923980
Yes KB924191
Yes KB924496
Yes KB925398_WMP64
Yes KB925454
Yes KB925486
Yes KB925876
Yes KB926247
Yes KB928388
Yes KB929120
Yes KB929969
Yes Q147222
Netcard queries test . . . . . . . : Passed
Information of Netcard drivers:
--------------------------
----------
----------
----------
----------
---------
Description: Intel(R) PRO/1000 GT Desktop Adapter
Device: \DEVICE\{F6D2A97E-77C3-4A2
3-8595-51C
CCEA5F4E7}
Media State: Connected
Device State: Connected
Connect Time: 00:14:55
Media Speed: 100 Mbps
Packets Sent: 41
Bytes Sent (Optional): 0
Packets Received: 77
Directed Pkts Recd (Optional): 18
Bytes Received (Optional): 0
Directed Bytes Recd (Optional): 0
--------------------------
----------
----------
----------
----------
---------
Description: Broadcom NetXtreme Gigabit Ethernet
Device: \DEVICE\{5A9AFE79-5B28-493
D-B548-DC1
B3B9150D4}
Media State: Connected
Device State: Connected
Connect Time: 00:14:56
Media Speed: 100 Mbps
Packets Sent: 3419
Bytes Sent (Optional): 0
Packets Received: 3166
Directed Pkts Recd (Optional): 3160
Bytes Received (Optional): 0
Directed Bytes Recd (Optional): 0
--------------------------
----------
----------
----------
----------
---------
[PASS] - At least one netcard is in the 'Connected' state.
Per interface results:
Adapter : LAN
Adapter ID . . . . . . . . : {5A9AFE79-5B28-493D-B548-D
C1B3B9150D
4}
Netcard queries test . . . : Passed
Adapter : WAN
Adapter ID . . . . . . . . : {F6D2A97E-77C3-4A23-8595-5
1CCCEA5F4E
7}
Netcard queries test . . . : Passed
Global results:
Domain membership test . . . . . . : Passed
Machine is a . . . . . . . . . : Primary Domain Controller Emulator
Netbios Domain name. . . . . . : MBADOM
Dns domain name. . . . . . . . : mba-aalborg.local
Dns forest name. . . . . . . . : mba-aalborg.local
Domain Guid. . . . . . . . . . : {F66211D3-4F94-4D83-A729-7
B1205D3C63
5}
Domain Sid . . . . . . . . . . : S-1-5-21-574694495-3920518
205-123123
4576
Logon User . . . . . . . . . . : Administrator
Logon Domain . . . . . . . . . : MBADOM
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{5A9AFE79-5B28
-493D-B548
-DC1B3B915
0D4}
1 NetBt transport currently configured.
DC discovery test. . . . . . . . . : Passed
Find DC in domain 'MBADOM':
Found this DC in domain 'MBADOM':
DC. . . . . . . . . . . : \\abintfs1.mba-aalborg.loc
al
Address . . . . . . . . : \\192.168.1.102
Domain Guid . . . . . . : {F66211D3-4F94-4D83-A729-7
B1205D3C63
5}
Domain Name . . . . . . : mba-aalborg.local
Forest Name . . . . . . : mba-aalborg.local
DC Site Name. . . . . . : Default-First-Site-Name
Our Site Name . . . . . : Default-First-Site-Name
Flags . . . . . . . . . : PDC emulator GC DS KDC TIMESERV WRITABLE DNS_D
C DNS_DOMAIN DNS_FOREST CLOSE_SITE 0x8
Find PDC emulator in domain 'MBADOM':
Found this PDC emulator in domain 'MBADOM':
DC. . . . . . . . . . . : \\abintfs1.mba-aalborg.loc
al
Address . . . . . . . . : \\192.168.1.102
Domain Guid . . . . . . : {F66211D3-4F94-4D83-A729-7
B1205D3C63
5}
Domain Name . . . . . . : mba-aalborg.local
Forest Name . . . . . . : mba-aalborg.local
DC Site Name. . . . . . : Default-First-Site-Name
Our Site Name . . . . . : Default-First-Site-Name
Flags . . . . . . . . . : PDC emulator GC DS KDC TIMESERV WRITABLE DNS_D
C DNS_DOMAIN DNS_FOREST CLOSE_SITE 0x8
Find Active Directory DC in domain 'MBADOM':
Found this Active Directory DC in domain 'MBADOM':
DC. . . . . . . . . . . : \\abintfs1.mba-aalborg.loc
al
Address . . . . . . . . : \\192.168.1.102
Domain Guid . . . . . . : {F66211D3-4F94-4D83-A729-7
B1205D3C63
5}
Domain Name . . . . . . : mba-aalborg.local
Forest Name . . . . . . : mba-aalborg.local
DC Site Name. . . . . . : Default-First-Site-Name
Our Site Name . . . . . : Default-First-Site-Name
Flags . . . . . . . . . : PDC emulator GC DS KDC TIMESERV WRITABLE DNS_D
C DNS_DOMAIN DNS_FOREST CLOSE_SITE 0x8
The command completed successfully
C:\>dcdiag /test:registerindns /dnsdomain:mba-aalborg.loc
al /v
Starting test: RegisterInDNS
DNS configuration is sufficient to allow this domain controller to
dynamically register the domain controller Locator records in DNS.
The DNS configuration is sufficient to allow this computer to dynamically
register the A record corresponding to its DNS name.
......................... abintfs1 passed test RegisterInDNS