Solved

How to reconnect a child domain in a failed PDC

Posted on 2004-09-10
6
483 Views
Last Modified: 2008-01-09
I have single server acting as PDC for the forest and multiple child domains.
The PDC of the forest failed, so I reintalled the operating system, but I am unable to reconnect the child domains to the new PDC.
Please help
0
Comment
Question by:riyami
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 5

Expert Comment

by:tstaddon
ID: 12026257
Have you restored the System State Data from backup?

If you had only one domain controller at the top level of your Active Directory, and you have no backup of its System State Data, then I would imagine you're in rather a lot of trouble.

Think about it this way: all your other domain controllers, workstations and so on, all recognize that machine as the ONLY authoritative description of the directory and it is the only server which can tell them where they reside within the directory. Also, they identify the server by its SID, not by whatever alphabetical name you give it.

Simply put, your child DCs will NOT function properly - not even between each other - until that server's System State Data cannot be retrieved. So, if you do not have that information backed up, you are really going to have to consider rebuilding your directory.
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 12026698
i agree with tstaddon 100%,,, you can't just rebuild the DC and think it will magically work again,, you have to restore the AD database from backup,,, without doing that,, the newly rebuild DC "knows" nothing about the child domains, workstations, user accounts etc,,, it thinks its a new domain.
0
 

Author Comment

by:riyami
ID: 12028833
I have system state, the problem is that the original server physically damaged. I reinstalled the OS then did the system state restore, but when rebooting the machine hang. So I thought the system state is useless since the actual server is diffirent (Hardware wise) then the server I am using as a replacement.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 4

Accepted Solution

by:
vnicolae earned 500 total points
ID: 12029753
You have no choice but to restore the system state. (to my knowledge) There is no way to recreate the implicit trust that exist between a parent and a child domain. If you do not want to restore everything, do a non-autoritative restore and select what exactly you want to recover.


Vlad
0
 

Author Comment

by:riyami
ID: 12050982
It is almost true that there is no way but recreate all the trust relation, the problem is that we can not add child domains to the new domain except if we made the childs clean of AD. But what we did is that we installed windows 2k srv on a new machine then used program called newsid.exe to make the new machine SID as the failed server then installed new AD with the same name as the old then used the system state to restore. That steps gave us some time to plan our down time for creating the new domain because the restore is not perfect, we are unable to add users, machines or even look at the users, the restored AD machine complain that there is:
1- NO DNS
2- NO GC
3- NO SYSVOL
I was able to correct 1,3 but 2 the system comlain that it does not have enogh rights to write to it.
in short i did not mind since I will plan my down time.
*** By the way any body knows what went wrong with our original AD server to act that way, not accept system state retore at once, we had to tweak it for more that 2 days.



0
 
LVL 4

Expert Comment

by:vnicolae
ID: 12053895
just a quick note... I was never able to restore the AD (system state) with ArcServe. On different ocasions, I was able to do it with NetBackup and with the integrated NTBackup. Not to bitch... but CA's tech support is lousy and they too were unable to help with restoring from ArcServe. The backups were ok, I was able to restore files but not the AD....

Vlad
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Just about everyone has an old PC laying around.  Ask anyone in the IT industry, whether they are a professional or play in it as a hobby.  From outdated Desktops to cheap "throwaway" laptops, they are all around and not as hard to "fix up" as you m…
Sometimes a user will call me frantically, explaining that something has gone wrong and they have tried everything (read - they have messed it up more and now need someone to clean up) and it still does no good, can I help them?!  Usually the standa…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question