Windows Server 2003 AD Directory Services Restore Mode

Attempting to restore W2K3 Domain Controller after failure.  Was able to replicate AD prior to failure. Succesfully (to a point) used Automated System Recovery to restore System State.  
Server than reboots and errors out on Rebuilding AD Indices (or something close) error is lsass.exe and wants to boot into Directory Services Restore Mode (DSRM). Boot into DSRM, when attempting to log on with Administrator and the DSRM password message pops: "cannot locate domain."

This DC is physically located in the US and is a Child of a domain where the parent is in the UK.  All servers W2k3.
Bandwith is a T1 between sites.
I have been told by "higher ups" that the distance between the sites does not matter.  

Question are: Could the distance between child and parent be an issue?
is there a specific port that uses DSRM? (Since AD was replicating the correct ports are open for that)
Is there any way around this issue short of a rebuild?
jericpaulsonAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

WeHeCommented:
the administrater password for DSRM is not a domain account.
it's the password you set while dcpromo'ing.
but i would do the following to keep downtime short:
install a plain w2k3 + hotfixes you had.
install backup software.
restore the hole DC. All drives + Systemstate.
Reboot the DC and wait untill AD Replication has done it's work.
as soon as netlogon service is started, it should be back in business again.
0
Netman66Commented:
Does following this article correct your issue?

http://support.microsoft.com/default.aspx?scid=kb;en-us;258062

It should do the trick - read it carefully - you're going to be working with important files.

Advise.

0
jericpaulsonAuthor Commented:
Thank you both for your feedback

WeHe - The name used for the DSRM is Administrator.  The password was set during dcpromo.  

My limited understanding of DSRM is that AD is not running on the box and the log on is trying to connect with the Domain that it was joined to.  During the dcpromo this machine was added as a DC in a child domain in an existing Domain etc.  So in this instance during the sign in the DSRM user/password is trying to contact the parent.  The "Log On to" option is the parent domain or workgroup.  Both options come back "Cannot Locate Domain"

Netman66- Article will prove to be helpful once I am on the machine booted into DSRM.  My issue is that I cannot get past the log on portion, please see above.
0
Upgrade your Question Security!

Your question, your audience. Choose who sees your identity—and your question—with question security.

Netman66Commented:
Your DSRM password is not stored in AD - it's stored in the local SAM.  This is why you have two different accounts - one is for the Recovery Console and one is for the Active Directory.

If you can't remember the Recovery Console account and password, I think you can boot with a Windows 2000 CD and use Recovery Console from it with no credentials.

Advise.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jericpaulsonAuthor Commented:
Netman66-  If DSRM stored in SAM than would need to log onto the local machine with the DSRM user and Password yes?

Will be trying later this afternoon at 4pm EST.  WIll let you know.  

Thank you again.
0
Netman66Commented:
Yes.
0
jericpaulsonAuthor Commented:
Netman66  thank you that got me in.  
0
Netman66Commented:
Glad to assist.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2003

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.