[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1202
  • Last Modified:

PDC Problems.

I took over a office that is having active directory problems, the previous company added a 2003 Server standard edition. The old server was 2000, and they never properaly migrated the environment. I tried to transfer over the roles, and was unsuccessful. So as practice i seized the roles over to the server, and now I'm getting errors. The 2003 server now, is missing the PDC, RID, and infrastructure roles. It's holding the schema owner, and domain role owner, but when I run netdom query fsmo i get the first 2.

The other 3 I get system cannot find the file specified.
The command failed to complete successfully.

I've been trying to resolve each error one by one, and is not working. Is there a way I can get this server to pick up the roles without the old server being present. I'm trying to avoid recreating the whole domain, but at this point i've spent so much time. I should just start from scratch.

-I'm also getting an error when I open group policy editor,  
      "The domain controller for Group Policy operations is not available. You may cancel this operation for this session or retry for this session using one of the following domain controllers. I havent researched this error."
0
TJacoberger1
Asked:
TJacoberger1
  • 28
  • 19
  • 2
  • +2
1 Solution
 
KieranwestCommented:
In my experience unfortunately your hooped... If something was not done right in the first place there will always be a mess. I think your best option would be to recreate it from scratch. Please wait for other Experts opinions before doing the hasty act of recreating :) Good Luck..
0
 
tkfastCommented:
I would have to agree you will spend more time trying to fix that mess and it will never work right.  Start a new active directory....Sorry
0
 
KCTSCommented:
Is the original DC gone?
If fo make sure the new DC is also a global catalog server - Go to Administrative Tools, Active Directory Sites and Services, Expand ,Sites, Default first site and Servers. Right click on the new server and select properties and tick the Global Catalog checkbox. (Global catalog is essential for logon as it needs to be queried to establish Universal Group Membership)

Clear all remnents of the old DC from Active directory - http://www.petri.co.il/delete_failed_dcs_from_ad.htm
and sieze the roles http://www.petri.co.il/seizing_fsmo_roles.htm
0
Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.

 
TJacoberger1Author Commented:
The original DC is gone, but I have the system state saved. I tried to restore the system state on the old server, and when i click the new server to change the roles. I get error in PDC, RID, and infrastructure. The old server even with the system state backup is useless to me, at this point.

I did both of those links already, I cleaned all the metadata using ntdsutil. I cleaned everything out of DNS, sites and services, and users and computers. I'm still having this issue. I seized the roles from the original server to begin with and the new server did not pick them up. I dont think your asking me to seize them on the new server. I need this machine, to pick up the pdc, and the rest of the roles with out starting from scratch.
0
 
TJacoberger1Author Commented:
Is that possible?
0
 
KCTSCommented:
Restoring the system state to another server is rarely a good idea
0
 
TJacoberger1Author Commented:
I restored it to the same server, the old 2000 Server. What happened was when i seized the roles previously, I dcpromo /forceremoval. So when I noticed that the 3 other roles werent present, I restored the system back to the old server. It didnt help though, i didnt restore them to the new server.
0
 
TJacoberger1Author Commented:
So is it possible for me to get this server to pick up the PDC, RID, and infrastructure roles. Since the old server is done?
0
 
Jay_Jay70Commented:
i am highly amused at the first two posts.....of course this is fixable, its AD, and its just about doing things in the right order at this stage

your problem here is you seized roles in a live environment, this is a big mistake. Your system state restore wont do squat as the rest of the schema has already been updated/corrupted.

clarify if you will for me, which server currently holds the roles, including the GC at this moment.

A full DCDIAG from each server would be good too

0
 
TJacoberger1Author Commented:
Ok i had a 2000 server which is/was named physolsvr and the 2003 server dc2. I tried moving the roles from physolsvr to dc2, dc2 is currently holding the schema master, and domain role. It's missing PDC, RID, and infrastructure roles. I moved the roles over based exactly on theory, live or not. This is not the first time, I've done this. I've just never worked with anything so screwed up. I tried to cleanup the metadata from AD, DNS, and removing anything of this server from the new server and it just wont go away. The global catalog server is the 2003 server,  everything is passing except those 3 roles. This is the dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site\DC2
      Starting test: Connectivity
         ......................... DC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site\DC2
      Starting test: Replications
         ......................... DC2 passed test Replications
      Starting test: NCSecDesc
         ......................... DC2 passed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\DC2\netlogon)
         [DC2] An net use or LsaPolicy operation failed with error 1203, No netw
ork provider accepted the given network path..
         ......................... DC2 failed test NetLogons
      Starting test: Advertising
         Warning: DC2 is not advertising as a time server.
         ......................... DC2 failed test Advertising
      Starting test: KnowsOfRoleHolders
         Warning: CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN
=PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-Firs
t-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local is the PDC Owner, but is
deleted.
         Warning: CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN
=PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-Firs
t-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local is the Rid Owner, but is
deleted.
         Warning: CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN
=PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-Firs
t-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local is the Infrastructure Upd
ate Owner, but is deleted.
         ......................... DC2 failed test KnowsOfRoleHolders
      Starting test: RidManager
         Warning: FSMO Role Owner is deleted.
         ldap_search_sW of CN=PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda
7b,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=lo
cal for hostname failed with 2: The system cannot find the file specified.
         ......................... DC2 failed test RidManager
      Starting test: MachineAccount
         ......................... DC2 passed test MachineAccount
      Starting test: Services
         ......................... DC2 passed test Services
      Starting test: ObjectsReplicated
         ......................... DC2 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... DC2 passed test frssysvol
      Starting test: frsevent
         ......................... DC2 passed test frsevent
      Starting test: kccevent
         ......................... DC2 passed test kccevent
      Starting test: systemlog
         ......................... DC2 passed test systemlog
      Starting test: VerifyReferences
         ......................... DC2 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : PHYSOLNET
      Starting test: CrossRefValidation
         ......................... PHYSOLNET passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... PHYSOLNET passed test CheckSDRefDom

   Running enterprise tests on : PHYSOLNET.local
      Starting test: Intersite
         ......................... PHYSOLNET.local passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355
         A Primary Domain Controller could not be located.
         The server holding the PDC role is down.
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         ......................... PHYSOLNET.local failed test FsmoCheck
0
 
Jay_Jay70Commented:
ok, we arent going to get this thing replicating without losing one of the DC's....basically at this point, you have to decide which DC you want to keep as a DC...the other one if going to be disconnected for a while and have the AD side of things wiped.

We then clean up the remaining DC, seize whatever roles are missing, get the GC role happening again, get a clean DIAG and then pull the cleaned, removed DC back into AD after either a rebuild, or some thorough cleaning.....

there isnt much you can to save both DC's when they get like this, but we can save one easy enough, you have to decide which one, i would say to the 2003 box myself....but depends on you
0
 
TJacoberger1Author Commented:
I want the 2003 Box, the 2000 is done. I'm trying to get the 2003 server up and running correctly, thats what started this the 2000 server has been demoted already.
0
 
Jay_Jay70Commented:
turn off the 2000 box, fire up ntdsutil and try to seize the roles, let me know what errors occur
0
 
TJacoberger1Author Commented:
You want me to seize the roles on the 2003 box?
0
 
TJacoberger1Author Commented:
if you do, all 5 roles or the 3 that are missing?
0
 
Jay_Jay70Commented:
sorry am back :),

yes, if you can deal without the 200 box for a while, seize the roles on the 2003 so that it holds them all, lets fix that one up and then we can deal with the other box
0
 
TJacoberger1Author Commented:
So when i do the ntdsutil, u want me to connect to itself, and seize itself. Meaning my servers name is dc2

i'm going to type connect to server dc2 Then q, then sieze the roles. I'm not trying to sound retarded, just making sure.
0
 
TJacoberger1Author Commented:
I seized all 5 roles, on the server. I gave you the results, just in case you wanted to review them. it looks like the server picked them up.

Results:::::::

   seize schema master:
fsmo maintenance: seize schema master
Attempting safe transfer of schema FSMO before seizure.
FSMO transferred successfully - seizure not required.
Server "dc2" knows about 5 roles
Schema - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
Domain - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
PDC - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=PHYSOLSVR\0
ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First-Site,CN=Si
tes,CN=Configuration,DC=PHYSOLNET,DC=local
RID - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=PHYSOLSVR\0
ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First-Site,CN=Si
tes,CN=Configuration,DC=PHYSOLNET,DC=local
Infrastructure - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=
PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First
-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local
fsmo maintenance: seize domain naming master
Attempting safe transfer of domain naming FSMO before seizure.
FSMO transferred successfully - seizure not required.

Seize domain naming master:
fsmo maintenance: seize domain naming master
Attempting safe transfer of domain naming FSMO before seizure.
FSMO transferred successfully - seizure not required.
Server "dc2" knows about 5 roles
Schema - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
Domain - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
PDC - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=PHYSOLSVR\0
ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First-Site,CN=Si
tes,CN=Configuration,DC=PHYSOLNET,DC=local
RID - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=PHYSOLSVR\0
ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First-Site,CN=Si
tes,CN=Configuration,DC=PHYSOLNET,DC=local
Infrastructure - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=
PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First
-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local

seize Rid master:
fsmo maintenance: seize rid master
Attempting safe transfer of RID FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-0321093D, problem 5002 (U
AVAILABLE), data 8

Win32 error returned is 0x20af(The requested FSMO operation failed. The current
FSMO holder could not be contacted.)
)
Depending on the error code this may indicate a connection,
ldap, or role transfer error.
Transfer of RID FSMO failed, proceeding with seizure ...
Searching for highest rid pool in domain
Server "dc2" knows about 5 roles
Schema - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=C
nfiguration,DC=PHYSOLNET,DC=local
Domain - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=C
nfiguration,DC=PHYSOLNET,DC=local
PDC - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=PHYSOLSVR\
ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First-Site,CN=S
tes,CN=Configuration,DC=PHYSOLNET,DC=local
RID - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Conf
guration,DC=PHYSOLNET,DC=local
Infrastructure - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN
PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-Firs
-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local

Seize pdc:
fsmo maintenance: seize pdc
Attempting safe transfer of PDC FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-0321054C, problem 5002 (UN
AVAILABLE), data 8

Win32 error returned is 0x20af(The requested FSMO operation failed. The current
FSMO holder could not be contacted.)
)
Depending on the error code this may indicate a connection,
ldap, or role transfer error.
Transfer of PDC FSMO failed, proceeding with seizure ...
Server "dc2" knows about 5 roles
Schema - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
Domain - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
PDC - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Confi
guration,DC=PHYSOLNET,DC=local
RID - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Confi
guration,DC=PHYSOLNET,DC=local
Infrastructure - CN=NTDS Settings\0ADEL:c2895f91-9b13-4582-a3f6-fb3e330dd7c0,CN=
PHYSOLSVR\0ADEL:1c864aa3-a812-4f90-b005-4d6189bcda7b,CN=Servers,CN=Default-First
-Site,CN=Sites,CN=Configuration,DC=PHYSOLNET,DC=local

seize infrastructure master:
fsmo maintenance: seize infrastructure master
Attempting safe transfer of infrastructure FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-0321036B, problem 5002 (UN
AVAILABLE), data 8

Win32 error returned is 0x20af(The requested FSMO operation failed. The current
FSMO holder could not be contacted.)
)
Depending on the error code this may indicate a connection,
ldap, or role transfer error.
Transfer of infrastructure FSMO failed, proceeding with seizure ...
Server "dc2" knows about 5 roles
Schema - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
Domain - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Co
nfiguration,DC=PHYSOLNET,DC=local
PDC - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Confi
guration,DC=PHYSOLNET,DC=local
RID - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Confi
guration,DC=PHYSOLNET,DC=local
Infrastructure - CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site,CN=Sit
es,CN=Configuration,DC=PHYSOLNET,DC=local
0
 
TJacoberger1Author Commented:
netdom query, shows that the server is now holding all 5 roles.
0
 
TJacoberger1Author Commented:
I did a dcdiag, netlogon failed, time server failed, and some other things failed.
results:

C:\>dcdiag

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site\DC2
      Starting test: Connectivity
         ......................... DC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site\DC2
      Starting test: Replications
         ......................... DC2 passed test Replications
      Starting test: NCSecDesc
         ......................... DC2 passed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\DC2\netlogon)
         [DC2] An net use or LsaPolicy operation failed with error 1203, No net
ork provider accepted the given network path..
         ......................... DC2 failed test NetLogons
      Starting test: Advertising
         Warning: DC2 is not advertising as a time server.
         ......................... DC2 failed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... DC2 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... DC2 passed test RidManager
      Starting test: MachineAccount
         ......................... DC2 passed test MachineAccount
      Starting test: Services
         ......................... DC2 passed test Services
      Starting test: ObjectsReplicated
         ......................... DC2 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... DC2 passed test frssysvol
      Starting test: frsevent
         ......................... DC2 passed test frsevent
      Starting test: kccevent
         An Warning Event occured.  EventID: 0x8000072D
            Time Generated: 10/15/2007   19:41:29
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x80000632
            Time Generated: 10/15/2007   19:46:45
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000072D
            Time Generated: 10/15/2007   19:46:45
            (Event String could not be retrieved)
         An Warning Event occured.  EventID: 0x8000072D
            Time Generated: 10/15/2007   19:48:17
            (Event String could not be retrieved)
         ......................... DC2 failed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0xC0001B77
            Time Generated: 10/15/2007   19:46:46
            (Event String could not be retrieved)
         ......................... DC2 failed test systemlog
      Starting test: VerifyReferences
         ......................... DC2 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidatio

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidatio

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : PHYSOLNET
      Starting test: CrossRefValidation
         ......................... PHYSOLNET passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... PHYSOLNET passed test CheckSDRefDom

   Running enterprise tests on : PHYSOLNET.local
      Starting test: Intersite
         ......................... PHYSOLNET.local passed test Intersite
      Starting test: FsmoCheck
         Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
         A Time Server could not be located.
         The server holding the PDC role is down.
         ......................... PHYSOLNET.local failed test FsmoCheck
0
 
Jay_Jay70Commented:
ok, lets make sure dc2 is now a Global Catalog Server, Clear the event logs,

You will now need to clear the dead DC's out of AD with NTDSUTIL as well, need to remove any traces of the 2k box
http://www.petri.co.il/delete_failed_dcs_from_ad.htm

 reboot her, run dcdiag when she comes back up

so far so good :)
0
 
TJacoberger1Author Commented:
I cleared the event logs, and the only server now listed is dc2.... restarting her now! Thank You
0
 
Jay_Jay70Commented:
make sure you clean AD for any objects still lingering, sites and services, DNS etc
0
 
TJacoberger1Author Commented:
I ran dcdiag, and everything passed except netlogon. This is the error thats coming up

         ......................... DC2 passed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\DC2\netlogon)
         [DC2] An net use or LsaPolicy operation failed with error 1203, No netw
ork provider accepted the given network path..
0
 
TJacoberger1Author Commented:
I did that too, all done.
0
 
Jay_Jay70Commented:
Ok, thats looking healthier though :)

First, can you confirm that you can access the c:\windows\sysvol\sysvol\....directories through internet explorer, i would say they are probably out of whack due to the FRS replication problems, we may beed to look at rebuilding the permission tree
http://support.microsoft.com/kb/315457
0
 
TJacoberger1Author Commented:
ok, the other day i was having a problem and posted a question. Someone had me change the burflag to D4, could that be the problem and should change it?
0
 
Jay_Jay70Commented:
no that should be fine, having it set as 4 will make it authorative which is what we want - it will restore itself off that, however, it wont restore permissions....

just a quick check for me, jump into computer management, and make sure that the netlogon share is displayed...

then if it is, try accessing it on itself by \\localhost\netlogon from the run window...let me know what she says
0
 
TJacoberger1Author Commented:
the netlogon share is not there
0
 
Jay_Jay70Commented:
there we go :) thats our last thing to fix and she should come back up

Navigate to here, and share the directory as NETLOGON

C:\WINDOWS\SYSVOL\sysvol\YOURDOMAINHERE\SCRIPTS

Share permissions:
Administrators - Full control
Everyone - Read

Security permissions:
Administrators: Full control
Authenticated Users: Read & Execute, List, Read
Creator Owner - Defaults (mine has none)
Server Operators: Read & Execute, List, Read
System: Full Control

Also make sure there is a SYSVOL Share
C:\WINDOWS\SYSVOL\sysvol (Share as SYSVOL)

Share Permissions:
Administrators: Full Control
Authenticated Users: Full Control
Everyone: Read

Security permissions:
Administrators: Full control
Authenticated Users: Read & Execute, List, Read
Creator Owner - Defaults (mine has none)
Server Operators: Read & Execute, List, Read
System: Full Control

Restart and Run DCDIAG Again :)



0
 
TJacoberger1Author Commented:
polices, and script folders are missing from c:\windows\sysvol\sysvol\domainname
0
 
Jay_Jay70Commented:
dont spose you have a backup handy with the last sysvol backup? or we can manually grab it from the other machine...but will need to make sure its off the network if you do
0
 
TJacoberger1Author Commented:
I had a backup of the system state on the machine that is off, I can't pull the folders off. I'm doing this all remotely, and not able to turn the machine on till the morning.
0
 
TJacoberger1Author Commented:
all backups were getting done by the server that is currently off.
0
 
Jay_Jay70Commented:
OK, now we are getting into the nit and grit of AD, we are going to need to pull the SYSVOL directory off the 2000 Server tomorrow, and place it onto the 2003 server, this is some dirty work but it should come up well enough with some tweaking - FRS replicates the SYSVOL Share...Sooo we should be able to simply copy and past it back in....Im just trying to think of any other ways of recreating it without losing AD database
0
 
Jay_Jay70Commented:
right, just did some checking and the above should work ok, you will need to get in front of that 2000 box, power it up without a cable attached, and then follow this (About the same as what i said, just instead of copying across the network, pull it onto a Flas drive or somethign similar) then paste back in :)

http://technet2.microsoft.com/windowsserver/en/library/8cf7a9ab-073c-4228-ac9f-52aa969d05841033.mspx?mfr=true
0
 
TJacoberger1Author Commented:
Ok cool :) Thank You for all your help! Soon as i have it done, I will post it up.
0
 
Jay_Jay70Commented:
thats a pleasure mate, tis what we are here for :)
0
 
TJacoberger1Author Commented:
I copied the 2 folders, moved them to the correct place. I checked all permissions, restarted, and waiting. I will run dcdiag soon as it comes up.
0
 
Jay_Jay70Commented:
sweet as

Which folder did you copy?
0
 
TJacoberger1Author Commented:
No Errors my Friend, thanks to you!!!!! I do have one error in the Systemlog part, i'm looking it up on google. I pasted the results below:

Domain Controller Diagnosis

Performing initial setup:
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site\DC2
      Starting test: Connectivity
         ......................... DC2 passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site\DC2
      Starting test: Replications
         ......................... DC2 passed test Replications
      Starting test: NCSecDesc
         ......................... DC2 passed test NCSecDesc
      Starting test: NetLogons
         ......................... DC2 passed test NetLogons
      Starting test: Advertising
         ......................... DC2 passed test Advertising
      Starting test: KnowsOfRoleHolders
         ......................... DC2 passed test KnowsOfRoleHolders
      Starting test: RidManager
         ......................... DC2 passed test RidManager
      Starting test: MachineAccount
         ......................... DC2 passed test MachineAccount
      Starting test: Services
         ......................... DC2 passed test Services
      Starting test: ObjectsReplicated
         ......................... DC2 passed test ObjectsReplicated
      Starting test: frssysvol
         ......................... DC2 passed test frssysvol
      Starting test: frsevent
         ......................... DC2 passed test frsevent
      Starting test: kccevent
         ......................... DC2 passed test kccevent
      Starting test: systemlog
         An Error Event occured.  EventID: 0x0000164A
            Time Generated: 10/16/2007   20:59:55
            Event String: The Netlogon service could not create server
         An Error Event occured.  EventID: 0xC0001B58
            Time Generated: 10/16/2007   21:00:57
            (Event String could not be retrieved)
         ......................... DC2 failed test systemlog
      Starting test: VerifyReferences
         ......................... DC2 passed test VerifyReferences

   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom

   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom

   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom

   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom

   Running partition tests on : PHYSOLNET
      Starting test: CrossRefValidation
         ......................... PHYSOLNET passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... PHYSOLNET passed test CheckSDRefDom

   Running enterprise tests on : PHYSOLNET.local
      Starting test: Intersite
         ......................... PHYSOLNET.local passed test Intersite
      Starting test: FsmoCheck
         ......................... PHYSOLNET.local passed test FsmoCheck
0
 
TJacoberger1Author Commented:
I copied the script and policies folder into c:\windows\sysvol\sysvol\domain\

I shared the sysvol directory like you said, and the script folder.
0
 
Jay_Jay70Commented:
perfect, clear those event logs again, and lets run dcdiag and see what she says
0
 
TJacoberger1Author Commented:
I found this when i searched the error http://support.microsoft.com/kb/258805
0
 
TJacoberger1Author Commented:
HEY BUDDY, IT WORKED!!!!!!!!!!!!!!!!!!!! No Errors!!!!!! I so owe you drinks, if your ever in NY lol
0
 
Jay_Jay70Commented:
i would say thats an old error sitting in the logs
0
 
Jay_Jay70Commented:
Sweet as my friend, now we need to clean that 2000 server, change its name, and bring her back up as an additional DC :)
0
 
TJacoberger1Author Commented:
I'm reinstalling windows server 2000, and then bring it back to the domain later. I still have another remote server to bring up, at a remote office. It should dcpromo fine now! Thank you
0
 
Jay_Jay70Commented:
That's a pleasure mate, you have done well. Let me know if you get stuck with anything during the process

James
0
 
TJacoberger1Author Commented:
Thank you so much James, your ever in ny let me know! Drinks on me :) I appreciate all your help
0
 
Jay_Jay70Commented:
Ill hold you to it :)

All the best!

James
0

Featured Post

Restore individual SQL databases with ease

Veeam Explorer for Microsoft SQL Server delivers an easy-to-use, wizard-driven interface for restoring your databases from a backup. No expert SQL background required. Web interface provides a complete view of all available SQL databases to simplify the recovery of lost database

  • 28
  • 19
  • 2
  • +2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now