Solved

The role owner attribute could not be read, FSMO roles in place

Posted on 2008-06-20
6
1,100 Views
Last Modified: 2012-06-22
Hello,

I've been all over looking for a solution to this very strange problem. I am running a VM of our two DC's running windows 2000 on a host-only network to simulate the addition of two more DC's that will be running 2003. Ultimately we want to remove the 2000 DC's from our environment. But I digress. When applying the inetorgpersonprevent script, I'm getting the error "the role owner attribute cannot be read", which in all of my reading points me to investigate my FSMO roles. I ran the FSMO query command and it came back as it should. dcdiag and netdiag are clean. I even tried to seize the roles to the other DC, but I get an error that "The current FSMO holder could not be contacted", which leads me back to thinking that something is wrong with the FSMO roles. I'm getting other errors about assigning group policies and one other that I can't recall exactly here that also lead me to believe there to be something wrong with the FSMO roles, but like I said, the tests come up clean. I am not getting this on the actual DC's by the way. I'm lead to believe it might have had something to do with putting these images in a virtual network, but the only thing I changed is the IP of the servers and their corresponding DNS entries.
0
Comment
Question by:numb3rs1x
  • 2
  • 2
6 Comments
 
LVL 22

Expert Comment

by:cj_1969
ID: 21883015
Your error "The current FSMO holder could not be contacted" indicates to me that this is a networking issue ... can you connect (ping) from one VM to all of the others (on each one)?  I would expect that you can chance the IPs without incident but it is possible that something has an old IP hard coded somewhere.  If you are in an isolated VM LAN then why not change the IPs back to the originals that were on the machines?  This would rule out this error ... if the problem still exists or confirm that something is storing the actual IP of when it was installed/configured.
0
 

Author Comment

by:numb3rs1x
ID: 21887222
Still no dice. I reloaded the DC's into the VM server configured as host-only but with the same subnet as the actual subnet they are on. These were fresh installs of the VM, I did not use the same files II originally got the errors on. I did not have to change any ip settings. Shame, I really thought that was going to work. Any other suggestions?
0
 

Author Comment

by:numb3rs1x
ID: 21887303
I don't know if this will help, but I am getting errors on these two things from dcdiag:

Starting test: kccevent
    An Information Event occured.  EventID: 0x4000051C
       Time Generated: 06/27/2008   15:12:22
       (Event String could not be retrieved)
    ......................... DC03 failed test kccevent
 Starting test: systemlog
    An Error Event occured.  EventID: 0x80001778
       Time Generated: 06/27/2008   14:18:56
       Event String: The previous system shutdown at 6:29:15 AM on
    An Error Event occured.  EventID: 0xC0001B72
       Time Generated: 06/27/2008   14:19:21
       (Event String could not be retrieved)
    An Error Event occured.  EventID: 0xC0001B72
       Time Generated: 06/27/2008   14:36:04
       (Event String could not be retrieved)
    An Error Event occured.  EventID: 0xC0001B72
       Time Generated: 06/27/2008   14:41:24
       (Event String could not be retrieved)
    An Error Event occured.  EventID: 0xC0001B72
       Time Generated: 06/27/2008   15:08:35
       (Event String could not be retrieved)
    ......................... DC03 failed test systemlog
0
 

Expert Comment

by:citot
ID: 21892845
I'm having the same issue but with W2K Server VMs.  I've created a parent domain and successfully added two child domains. I got the error when attempted to add the third child domain all in a virtual network environment. I did use the same vms but changed the SID when it complained about being identical to the previous vms. This worked up until trying to add the third vm. The interesting part was that I was successful in joining the third server to the parent domain before running dcpromo to create child domain. That is when I received the same error message "the role owner attribute could not be read" I'm still checking so if I figure out something I'll write back.
0
 

Accepted Solution

by:
citot earned 500 total points
ID: 21902431
OK, So I've brought up my virtual network environment (vm files) on a different computer (home vs work- 2gb ram vs. 3gb ram) I have one Parent and three Child Domains. The DC1 (parent) DC2 child1, DC3 child2 and DC4 child3. I had the issue when attempting to bring up DC4 as Child3 domain and received the error message "the role owner attribute could not be read"  What I did differently was to use a new copy of the existing VM and change the SID. I also verified I had the correct IP addresses (I may have incorrectly refered to the IP add of DNS server)  Joined the DC4 to the Parent Domain before runing dcpromo and wala. It worked. Not sure if using a new VM or the different computer hosting the Virtual Environments was the solution or a combination of DNS / IP issues. Sometimes just starting over instead of tyring to pin point the issue is easier.  Anyway hope this helps.
Cito T
0

Join & Write a Comment

Installing a printer using group policy preferences is not that hard let’s take a look at it. First lets open up your group policy console and edit the policy you want to add it to. I recommend creating a new policy for each printer makes it a l…
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now