?
Solved

Adprep was unable to update forest-wide information

Posted on 2007-10-04
5
Medium Priority
?
2,528 Views
Last Modified: 2011-08-18
I have Windows 2000 Server  environment which has two Domain controller, now I have plan to upgrade it to Windows 2003 by adding additional Server installed Windows 2003 Server and I did the following steps.

"      I Gat Adprep.exe from the CD Windows 2003 Server.
"      From the command Line I run Adprep / forestprep on the Schema operation Master Server.

The operation was failed because there is missing files like Schema.ini, then after a lot of workarounds I gat the last Log for Adprep that contain:

 Adprep created the log file ADPrep.log under C:\WINNT\system32\debug\adprep\logs\20071001161911 directory.



Adprep successfully made the LDAP connection to the local domain controller USERS-RESOURCES.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is (null).



LDAP API ldap_search_s() finished, return code is 0x0



Adprep successfully retrieved information from the local directory service.



Adprep successfully initialized global variables.
[Status/Consequence]
Adprep is continuing.



 
ADPREP WARNING:  
 
Before running adprep, all Windows 2000 domain controllers in the forest should be upgraded to Windows 2000 Service Pack 1 (SP1) with QFE 265089, or to Windows 2000 SP2 (or later).  
 
QFE 265089 (included in Windows 2000 SP2 and later) is required to prevent potential domain controller corruption.  
 
For more information about preparing your forest and domain see KB article Q331161 at http://support.microsoft.com.
 
[User Action]  
If ALL your existing Windows 2000 domain controllers meet this requirement, type C and then press ENTER to continue. Otherwise, type any other key and press ENTER to quit.



Adprep set the value of registry key System\CurrentControlSet\Services\NTDS\Parameters\Schema Update Allowed to 1



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x44



Adprep attempted to create the directory service object cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
The object exists so Adprep did not attempt to rerun this operation but is continuing.



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x44



Adprep attempted to create the directory service object cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
The object exists so Adprep did not attempt to rerun this operation but is continuing.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=3467dae5-dedd-4648-9066-f48ac186b20a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=3467dae5-dedd-4648-9066-f48ac186b20a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is CN=Sites,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x0



Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=Sites,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_modify_ext_s() finished, return code is 0x0



Adprep successfully modified the security descriptor on object CN=Sites,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
Adprep merged the existing security descriptor with the new access control entry (ACE).



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=3467dae5-dedd-4648-9066-f48ac186b20a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x0



Adprep successfully created the directory service object cn=3467dae5-dedd-4648-9066-f48ac186b20a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=33b7ee33-1386-47cf-baa1-b03e06473253,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=33b7ee33-1386-47cf-baa1-b03e06473253,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=Sam-Domain,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_modify_s() finished, return code is 0x0



Adprep modified the default security descriptor on object CN=Sam-Domain,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
Adprep merged the existing default security descriptor with the new access control entry (ACE).



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=33b7ee33-1386-47cf-baa1-b03e06473253,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x0



Adprep successfully created the directory service object cn=33b7ee33-1386-47cf-baa1-b03e06473253,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=e9ee8d55-c2fb-4723-a333-c80ff4dfbf45,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=e9ee8d55-c2fb-4723-a333-c80ff4dfbf45,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=Domain-DNS,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_modify_s() finished, return code is 0x0



Adprep modified the default security descriptor on object CN=Domain-DNS,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
Adprep merged the existing default security descriptor with the new access control entry (ACE).



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=e9ee8d55-c2fb-4723-a333-c80ff4dfbf45,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x0



Adprep successfully created the directory service object cn=e9ee8d55-c2fb-4723-a333-c80ff4dfbf45,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=ccfae63a-7fb5-454c-83ab-0e8e1214974e,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=ccfae63a-7fb5-454c-83ab-0e8e1214974e,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=organizational-Unit,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_modify_s() finished, return code is 0x0



Adprep modified the default security descriptor on object CN=organizational-Unit,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
Adprep merged the existing default security descriptor with the new access control entry (ACE).



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=ccfae63a-7fb5-454c-83ab-0e8e1214974e,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x0



Adprep successfully created the directory service object cn=ccfae63a-7fb5-454c-83ab-0e8e1214974e,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=ad3c7909-b154-4c16-8bf7-2c3a7870bb3d,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=ad3c7909-b154-4c16-8bf7-2c3a7870bb3d,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=Group-Policy-Container,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_modify_s() finished, return code is 0x0



Adprep modified the default security descriptor on object CN=Group-Policy-Container,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
Adprep merged the existing default security descriptor with the new access control entry (ACE).



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=ad3c7909-b154-4c16-8bf7-2c3a7870bb3d,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x0



Adprep successfully created the directory service object cn=ad3c7909-b154-4c16-8bf7-2c3a7870bb3d,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=26ad2ebf-f8f5-44a4-b97c-a616c8b9d09a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=26ad2ebf-f8f5-44a4-b97c-a616c8b9d09a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=Trusted-Domain,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_modify_s() finished, return code is 0x0



Adprep modified the default security descriptor on object CN=Trusted-Domain,CN=Schema,CN=Configuration,DC=aKAMA,DC=com,DC=sa.
[Status/Consequence]
Adprep merged the existing default security descriptor with the new access control entry (ACE).



Adprep was about to call the following LDAP API. ldap_add_s(). The entry to add is cn=26ad2ebf-f8f5-44a4-b97c-a616c8b9d09a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_add_s() finished, return code is 0x0



Adprep successfully created the directory service object cn=26ad2ebf-f8f5-44a4-b97c-a616c8b9d09a,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is cn=4444c516-f43a-4c12-9c4b-b5c064941d61,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.



LDAP API ldap_search_s() finished, return code is 0x20



Adprep verified the state of operation cn=4444c516-f43a-4c12-9c4b-b5c064941d61,cn=Operations,cn=ForestUpdates,CN=Configuration,DC=aKAMA,DC=com,DC=sa.  
[Status/Consequence]
The operation has not run or is not currently running. It will be run next.



Adprep was unable to complete because the call back function (null) failed.  
[Status/Consequence]
Error message: Could not find file C:\WINNT\system32\debug\adprep\data\409.csv.  (0x80004005).
[User Action]  
Check the log file Adprep.log, in the C:\WINNT\system32\debug\adprep\logs\20071001161911 directory for more information.



Adprep set the value of registry key System\CurrentControlSet\Services\NTDS\Parameters\Schema Update Allowed to 1



Adprep was unable to update forest-wide information.  
[Status/Consequence]
Adprep requires access to existing forest-wide information from the schema master in order to complete this operation.
[User Action]
Check the log file, Adprep.log, in the C:\WINNT\system32\debug\adprep\logs\20071001161911 directory for more information.



So please what can I do?

Thanks
0
Comment
Question by:Arabsoft
3 Comments
 
LVL 1

Accepted Solution

by:
gosunfire earned 1000 total points
ID: 20012559
Arabsoft

It is likely that you're using a bad version of Adprep.  Check out this Microsoft KB article that provides the details on how to get the updated version free of charge.
http://support.microsoft.com/kb/324392

If by some chance you're using Sp1 slipstreamed media, then the issue is more likely around the abillity to locate the Schema Master, communicate with the Schema Master, or insufficient permissions (though I doublt that's the case, as you're probably running it as a Schema Admin).

- Mike @ GoSunfire
0
 

Expert Comment

by:Frantz Carion
ID: 21402274
Hi, I had the same situation on a 2003 R2 to 2008 migration and this was due to the antivirus MacAffee 8.5i. After disabling it I could run my forrest prep and domainprep.

BR

FC @ Celsiusinternational
0
 

Expert Comment

by:cns13
ID: 22607818
+1 on disabling McAfee.  I just found this article as I was having the same problem.  McAfee was it.

Ben
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question