Solved

New Server 2008 Domain Controller missing NetLogon and SysVol Shares

Posted on 2008-10-28
2
4,709 Views
Last Modified: 2013-12-24
The old server was Server 2k and I ran adprep /forestprep and adprep /domainprep using the Server 2008 cd to be able to add the Server 2008 as a domain controller.  I then ran dcpromo to add the server as a domain controller and allowed it to replicate.  I then transferred all of the FSMO roles to the new server.  

The new server doesn't have the NetLogon and SysVol shares.  
I am getting the following errors with dcdiag:

Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation.  All rights reserved.

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = EMDServer
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\EMDSERVER
      Starting test: Connectivity
         ......................... EMDSERVER passed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\EMDSERVER
      Starting test: Advertising
         Warning: DsGetDcName returned information for
         \\TIGERSERVER.tigeroilandgas.com, when we were trying to reach
         EMDSERVER.
         SERVER IS NOT RESPONDING or IS NOT CONSIDERED SUITABLE.
         ......................... EMDSERVER failed test Advertising
      Starting test: FrsEvent
         There are warning or error events within the last 24 hours after the
         SYSVOL has been shared.  Failing SYSVOL replication problems may cause
         Group Policy problems.
         ......................... EMDSERVER passed test FrsEvent
      Starting test: DFSREvent
         ......................... EMDSERVER passed test DFSREvent
      Starting test: SysVolCheck
         ......................... EMDSERVER passed test SysVolCheck
      Starting test: KccEvent
         ......................... EMDSERVER passed test KccEvent
      Starting test: KnowsOfRoleHolders
         ......................... EMDSERVER passed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... EMDSERVER passed test MachineAccount
      Starting test: NCSecDesc
         ......................... EMDSERVER passed test NCSecDesc
      Starting test: NetLogons
         Unable to connect to the NETLOGON share! (\\EMDSERVER\netlogon)
         [EMDSERVER] An net use or LsaPolicy operation failed with error 67,
         The network name cannot be found..
         ......................... EMDSERVER failed test NetLogons
      Starting test: ObjectsReplicated
         ......................... EMDSERVER passed test ObjectsReplicated
      Starting test: Replications
         ......................... EMDSERVER passed test Replications
      Starting test: RidManager
         ......................... EMDSERVER passed test RidManager
      Starting test: Services
         ......................... EMDSERVER passed test Services
      Starting test: SystemLog
         An Warning Event occurred.  EventID: 0x8000001D
            Time Generated: 10/28/2008   12:36:42
            Event String:
            The Key Distribution Center (KDC) cannot find a suitable certificate
 to use for smart card logons, or the KDC certificate could not be verified. Sma
rt card logon may not function correctly if this problem is not resolved. To cor
rect this problem, either verify the existing KDC certificate using certutil.exe
 or enroll for a new KDC certificate.
         ......................... EMDSERVER passed test SystemLog
      Starting test: VerifyReferences
         ......................... EMDSERVER passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test
         CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test
         CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : tigeroilandgas
      Starting test: CheckSDRefDom
         ......................... tigeroilandgas passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... tigeroilandgas passed test
         CrossRefValidation

   Running enterprise tests on : tigeroilandgas.com
      Starting test: LocatorCheck
         ......................... tigeroilandgas.com passed test LocatorCheck
      Starting test: Intersite
         ......................... tigeroilandgas.com passed test Intersite

I also get the following informatoin with a nltest /dsgetdc, which is pointing towards the wrong server.

           DC: \\TIGERSERVER.tigeroilandgas.com
      Address: \\192.168.1.3
     Dom Guid: 0ca1b8fd-fb66-40ec-9885-1a48a82dc3e8
     Dom Name: tigeroilandgas.com
  Forest Name: tigeroilandgas.com
 Dc Site Name: Default-First-Site-Name
Our Site Name: Default-First-Site-Name
        Flags: GC DS LDAP KDC TIMESERV WRITABLE DNS_DC DNS_DOMAIN DNS_FOREST CLO
SE_SITE


Any help you can give me with this will be great.
0
Comment
Question by:xsawkins
2 Comments
 
LVL 18

Expert Comment

by:sk_raja_raja
Comment Utility
0
 

Accepted Solution

by:
xsawkins earned 0 total points
Comment Utility
After hasseling with this for several days I finally ended up transferring all of the roles back to the old server, demoted the new server, and reformatted the new server and started scratch by building a new domain.  
This seems to have resolved all of the issues and now we don't have anything from the old setup to worry about with the new domain.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

I annotated my article on ransomware somewhat extensively, but I keep adding new references and wanted to put a link to the reference library.  Despite all the reference tools I have on hand, it was not easy to find a way to do this easily. I finall…
Entering a date in Microsoft Access can be tricky. A typo can cause month and day to be shuffled, entering the day only causes an error, as does entering, say, day 31 in June. This article shows how an inputmask supported by code can help the user a…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now