<

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x

Lingering Objects Troubleshooting

Published on
6,390 Points
2,990 Views
4 Endorsements
Last Modified:
Hi,

It seems that most of people face problems with lingering objects in domain and because of incorrect troubleshooting involving AD replication, tombstone lifetime problem increases.

I request everybody to read the following information to avoid such issues:

Problem: Event id 2042
You have AD replication issues. Example: 10 DCs and one of them fails to replicate. The box has crossed the TSL (Tombstone Lifetime) time period.

Behaviour
By design, Server do not replicate beyond Tombstone time period as it can introduce lingering objects.

Checks:
Do we have Strict Replication Consistency enabled?:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTDS\Parameters
Value Name: Strict Replication Consistency
Data type: REG_DWORD
Value data: 1
Note: By default, W2k3 domain upgraded from W2k will have loose replication.

Enable strict replication consistency on All DCs
More info on: http://technet2.microsoft.com/WindowsServer/en/library/ea3330c4-1d58-457e-9ad6-97f1573999ff1033.mspx?mfr=true

Find what caused the replication problem? Was it DNS?? If yes, you may want to fix it first..

W2k3 domain with W2k3 DCs:
You have two options:
Set the Strict Repl Cons to 1 on all the boxes and put in the following value and set it to 1:
HKLM\System\CurrentControlSet\Services\NTDS\Parameters
REG_DWORD Value: Allow Replication With Divergent and Corrupt Partner
At this point you could use repadmin /removelingeringobejcts to remove the lingering objects on problem server which should solve your problem.
2 nd option:      Demote the server, try to avoid this as above tool fixes the problem.

Incase of W2k domain with W2k DCs:
Enable strict consistency first and then fix the DNS etc At this point if there are no lingering objects, replication should proceed. If there are lingering objects then we will get error messages pointing out the lingering object. Here, we can decide on any of our available lingering object removal options for W2K replfix or Kb314282. Lingering object commands
4
Comment
2 Comments
LVL 21

Expert Comment

by:alainbryden
You article needs to be greatly expanded. You lack context and elaboration, the grammar used is ambiguous and erroneous in some cases, and you jump right into acronyms like AD replication without ever defining them. What is AD replication, what are tombstones, who has to worry about such problems (why only domain users, what kind of domains, how do they creep up?) What defines a replication problem, and why is it a problem? I could go on an on and on. One would be an expert in domains just to figure out how to follow the steps you cite, and if they have that much expertise, they probably don't even need the advice. Meet novice users half way so that they have a chance of making use of your advice.
0
LVL 5

Expert Comment

by:GG VP
Yes, the article needs more in depth explanation!
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Join & Write a Comment

This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

Keep in touch with Experts Exchange

Tech news and trends delivered to your inbox every month