Solved

How to reconnect a child domain in a failed PDC

Posted on 2004-09-10
6
479 Views
Last Modified: 2008-01-09
I have single server acting as PDC for the forest and multiple child domains.
The PDC of the forest failed, so I reintalled the operating system, but I am unable to reconnect the child domains to the new PDC.
Please help
0
Comment
Question by:riyami
6 Comments
 
LVL 5

Expert Comment

by:tstaddon
ID: 12026257
Have you restored the System State Data from backup?

If you had only one domain controller at the top level of your Active Directory, and you have no backup of its System State Data, then I would imagine you're in rather a lot of trouble.

Think about it this way: all your other domain controllers, workstations and so on, all recognize that machine as the ONLY authoritative description of the directory and it is the only server which can tell them where they reside within the directory. Also, they identify the server by its SID, not by whatever alphabetical name you give it.

Simply put, your child DCs will NOT function properly - not even between each other - until that server's System State Data cannot be retrieved. So, if you do not have that information backed up, you are really going to have to consider rebuilding your directory.
0
 
LVL 25

Expert Comment

by:mikeleebrla
ID: 12026698
i agree with tstaddon 100%,,, you can't just rebuild the DC and think it will magically work again,, you have to restore the AD database from backup,,, without doing that,, the newly rebuild DC "knows" nothing about the child domains, workstations, user accounts etc,,, it thinks its a new domain.
0
 

Author Comment

by:riyami
ID: 12028833
I have system state, the problem is that the original server physically damaged. I reinstalled the OS then did the system state restore, but when rebooting the machine hang. So I thought the system state is useless since the actual server is diffirent (Hardware wise) then the server I am using as a replacement.
0
Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

 
LVL 4

Accepted Solution

by:
vnicolae earned 500 total points
ID: 12029753
You have no choice but to restore the system state. (to my knowledge) There is no way to recreate the implicit trust that exist between a parent and a child domain. If you do not want to restore everything, do a non-autoritative restore and select what exactly you want to recover.


Vlad
0
 

Author Comment

by:riyami
ID: 12050982
It is almost true that there is no way but recreate all the trust relation, the problem is that we can not add child domains to the new domain except if we made the childs clean of AD. But what we did is that we installed windows 2k srv on a new machine then used program called newsid.exe to make the new machine SID as the failed server then installed new AD with the same name as the old then used the system state to restore. That steps gave us some time to plan our down time for creating the new domain because the restore is not perfect, we are unable to add users, machines or even look at the users, the restored AD machine complain that there is:
1- NO DNS
2- NO GC
3- NO SYSVOL
I was able to correct 1,3 but 2 the system comlain that it does not have enogh rights to write to it.
in short i did not mind since I will plan my down time.
*** By the way any body knows what went wrong with our original AD server to act that way, not accept system state retore at once, we had to tweak it for more that 2 days.



0
 
LVL 4

Expert Comment

by:vnicolae
ID: 12053895
just a quick note... I was never able to restore the AD (system state) with ArcServe. On different ocasions, I was able to do it with NetBackup and with the integrated NTBackup. Not to bitch... but CA's tech support is lousy and they too were unable to help with restoring from ArcServe. The backups were ok, I was able to restore files but not the AD....

Vlad
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello I read in a discussion about a person who configured a very simple mirror RAID with two hard drives; the system and data were on the same partition. He asked how to repair the system as it was not booting up anymore. In his case running …
In this article we will discuss all things related to StageFright bug, the most vulnerable bug of android devices.
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question