Win2k3_Srv Active Directory not replicated
Posted on 2006-07-06
Previously i have two DC (named DC1 and DC2) on Win2k3_SRV in the same subnet for one domain, and the third DC (named DC3) on Win2K_Srv in the same forest, but in the other subnet and for other domain.
Now DC2 crashed.
I have no backup for it.
I holding all FSMO roles to DC1 (first DC in the forest), remove DC2 account from Active directory, and all be fine (DC1 and DC3 replicating and no errors in the EventLogs.
Now I want to install second DC (DC2) in the first domain.
Dcpromo completed successfuly.
But when I restarted new DC (after dcpromo), it restarted, but not replicated.
NTDS Settings for both servers auto-generated.
DNS aliases for this connections are present in DNS (nslookup resolved on both machines)
On the new DC generating Errors:
Event ID: 1097, Userenv:
Windows cannot find the machine account, The local security authority cannot be contacted.
Event ID: 1030, Userenv:
Windows cannot query for the list of Group Policy Objects
On the old DC (DC1) Event logged folowing:
Event ID: 1039, NTDS General:
Internal event: Active Directory could not process the following object.
Increase physical memory or virtual memory. If this error continues to occur, restart this domain controller.
REMARK: This record I was deleted one day before. Previously it was in the container of one non-critical Service, which i turned off (This Service turned off on Win2k3 by default)
DC1 always have 512M RAM and 2GB Virtual Memory on HDD.
When i demounting DC2 from AD Controllers to Domain member servers, errors disappear.
I tried create second controller with name diferent from DC2, same result.
1 Question is: How can i install (or troubleshuting) second DC? (generaly question)
2 Question is: If i changing TombStoneLifetime to 1 day, clearing garbage on the DC1, and then restoring TombStoneLifetime to default setting, deleted record must be phisicaly deleted from my DIT-file, isn't? But how this operation will affect other DC in the forest?