Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Need a little info on a Domain Controller Time Server Issue.

Posted on 2008-10-05
6
Medium Priority
?
483 Views
Last Modified: 2012-05-05
Hello to all.

Need a little info on a domain controller issue I had this morning. I had my 2003 Domain controller go off line today. I went in and rebooted it and she came back up. "Thank God"

I have two sites connected with a wirless bridge, and a Domain Controller at each site. I also have an exchange server at the same site as the Primary DC.

The Main DC went off line, Email failed as a result of this I am not sure why. Both DC are DNS servers, I would have expected it to pick up of the other DC.

The Errors in the Event Log point to the Microsoft Time Server not being able to be reached, Since then I added another Outside Time server and resynched, All seems fine.

Is it possible that the DC would have locked or froze or Active Driectrory failed because of the time server issue. I see the logs on the other Domain Controller or mentioning that replication failed as the domain controler was unavailable.

Is there a way to verify my new time server is good, is it possible to add a second.

Please input.   Thanks Guys!
0
Comment
Question by:tcmadmin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 

Author Comment

by:tcmadmin
ID: 22646726
Also one other thing, I would have expected email to function properly as it should have been using the other DC for authentication and DNS. The other DC is on a seperate subnet, but it is routed peroperly.

The error in the event log is as follows.

Event Type:      Error
Event Source:      CertSvc
Event Category:      None
Event ID:      44
Date:            10/5/2008
Time:            10:39:08 AM
User:            N/A
Computer:      PSB01
Description:
The "Windows default" Policy Module "Initialize" method returned an error. The specified domain either does not exist or could not be contacted. The returned status code is 0x8007054b (1355).  The Active Directory containing the Certification Authority could not be contacted.


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


Is it p-ossible to have the certificate authority to be on 2 domain controlers so exchange will stay up if one of them goes down?

Thanks
0
 
LVL 8

Expert Comment

by:mikainz
ID: 22647838
Exchange Server relies on having a Global catalog server beeing online.
Can verify that both DC are global catalog server.
You can check thin in the MMC snap in "Active Directory sites and services"
Right click on the "NTDS settings" object of the server object.
0
 

Author Comment

by:tcmadmin
ID: 22649015
Thank you for the fast response, I did check to see if they where both set as global catalog servers and they both are. Could it have anythting to do with replication time, I have them set to replicate every hour as per default.
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
LVL 6

Expert Comment

by:JimsZ
ID: 22649163
should not be anything to do with replication times.  

Sounds like only the main domain controller is the certificate authority & the secondary is not allowed to verify certs.


I would definately say this is a certificate issue & not so much as a time or replication issue!
0
 

Author Comment

by:tcmadmin
ID: 22658164
if you have two domain controllers in two sepertate sites, what is best practice for setting the roles for them, should some roles be moved to the secondary domain controller.

Both are set as Global Catologs?

Thanks
0
 

Accepted Solution

by:
tcmadmin earned 0 total points
ID: 22764008
I am still not sure how to confirm, Is there a way to set exchange to fail over to another domain controler in a seperate site if the primary fails. Ahould roles be split up after adding the second DC?
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Let's recap what we learned from yesterday's Skyport Systems webinar.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question