Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Replication Failure, machine account issues.

Posted on 2006-07-12
5
Medium Priority
?
1,270 Views
Last Modified: 2010-08-05
I have created a rather large problem.

In an attempt to create a copy of our AD in a vitual envo, I mistakenly promoted a virtual server, with the same name as an existing server, to our production AD.

When I discovered my mistake, I attempted to correct it by depromoting it. The account for the original server, known here after as "Server2" remained in AD, but it was not able to comunicate with the remaining DC, "Server1". I reset the machine account on Server2 using

netdom resetpwd /server:Server1 /userd:OURCOMPANY\administrator_id /passwordd:*

Now Server2 can replicate to Server1, but Server1 cannot replicate to Server2. The machine accounts are still not right. The output from DCDIAG is attached below.

At this point my only idea is to attempt to depromote Server2, join it to a workgroup, then rejoin the domain and repromote. Is there a way to fix the machine account some other way that I'm missing?

Also ran dcdiag /s:localhost /repairmachineaccount .... output follows
------------------------------------------------
Relevent portion of out put is...
-----------------------------------------------
Starting test: MachineAccount
         * Server2 is not a server trust account
         ......................... Server2 failed test MachineAccount

=======================================
Full output is.....
=======================================
Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: NOC\Server2
      Starting test: Connectivity
         ......................... Server2 passed test Connectivity

Doing primary tests

   Testing server: NOC\Server2
      Starting test: Replications
         [Replications Check,Server2] A recent replication attempt failed:
            From Server1 to Server2
            Naming Context: CN=Schema,CN=Configuration,DC=MYCOMPANY,DC=com
            The replication generated an error (8453):
            Replication access was denied.
            The failure occurred at 2006-07-12 16:48.26.
            The last success occurred at 2006-07-11 10:52.20.
            41 failures have occurred since the last success.
            The machine account for the destination Server2.
            is not configured properly.
            Check the userAccountControl field.
            Kerberos Error.
            The machine account is not present, or does not match on the.
            destination, source or KDC servers.
            Verify domain partition of KDC is in sync with rest of enterprise.
            The tool repadmin/syncall can be used for this purpose.
         [Replications Check,Server2] A recent replication attempt failed:
            From Server1 to Server2
            Naming Context: CN=Configuration,DC=MYCOMPANY,DC=com
            The replication generated an error (8453):
            Replication access was denied.
            The failure occurred at 2006-07-12 17:01.52.
            The last success occurred at 2006-07-11 10:52.28.
            311 failures have occurred since the last success.
            The machine account for the destination Server2.
            is not configured properly.
            Check the userAccountControl field.
            Kerberos Error.
            The machine account is not present, or does not match on the.
            destination, source or KDC servers.
            Verify domain partition of KDC is in sync with rest of enterprise.
            The tool repadmin/syncall can be used for this purpose.
         [Replications Check,Server2] A recent replication attempt failed:
            From Server1 to Server2
            Naming Context: DC=MYCOMPANY,DC=com
            The replication generated an error (8453):
            Replication access was denied.
            The failure occurred at 2006-07-12 17:05.59.
            The last success occurred at 2006-07-11 11:00.22.
            525 failures have occurred since the last success.
            The machine account for the destination Server2.
            is not configured properly.
            Check the userAccountControl field.
            Kerberos Error.
            The machine account is not present, or does not match on the.
            destination, source or KDC servers.
            Verify domain partition of KDC is in sync with rest of enterprise.
            The tool repadmin/syncall can be used for this purpose.
         ......................... Server2 passed test Replications
      Starting test: NCSecDesc
         ......................... Server2 passed test NCSecDesc
      Starting test: NetLogons
         ......................... Server2 passed test NetLogons
      Starting test: Advertising
         ......................... Server2 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... Server2 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... Server2 passed test RidManager
      Starting test: MachineAccount
         * Server2 is not a server trust account
         ......................... Server2 failed test MachineAccount
      Starting test: Services
         ......................... Server2 passed test Services
      Starting test: ObjectsReplicated
         ......................... Server2 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... Server2 passed test frssysvol
      Starting test: kccevent
         ......................... Server2 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x00000457
            Time Generated: 07/12/2006   16:38:33
            Event String: Driver hp psc 2200 series required for printer
         An Error Event occured.  EventID: 0x00000452
            Time Generated: 07/12/2006   16:38:33
            Event String: The printer could not be installed.
         An Error Event occured.  EventID: 0x00001659
            Time Generated: 07/12/2006   16:50:27
            Event String: The session setup to the Windows NT or Windows
         ......................... Server2 failed test systemlog

   Running enterprise tests on : MYCOMPANY.com
      Starting test: Intersite
         ......................... MYCOMPANY.com passed test Intersite
      Starting test: FsmoCheck
         ......................... MYCOMPANY.com passed test FsmoCheck
0
Comment
Question by:Canisrufas
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
5 Comments
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17097664
when you demoted your other DC did it demote gracefully or did you have to force remove it
0
 

Author Comment

by:Canisrufas
ID: 17111134
it demoted gracefully. turned out the machine acount type was damaged, still showed as a member server in AD. used ADSIedit to correct.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 17112888
ah glad all is well,

well done
0
 

Accepted Solution

by:
ee_ai_construct earned 0 total points
ID: 17306408
PAQ / Refund
ee ai construct, community support moderator
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
If you are a mobile app developer and especially develop hybrid mobile apps then these 4 mistakes you must avoid for hybrid app development to be the more genuine app developer.
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question