asked on
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = AD5
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: KansasCity9800\AD5
Starting test: Connectivity
......................... AD5 passed test Connectivity
Doing primary tests
Testing server: KansasCity9800\AD5
Starting test: Advertising
......................... AD5 passed test Advertising
Starting test: FrsEvent
......................... AD5 passed test FrsEvent
Starting test: DFSREvent
......................... AD5 passed test DFSREvent
Starting test: SysVolCheck
......................... AD5 passed test SysVolCheck
Starting test: KccEvent
......................... AD5 passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... AD5 passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... AD5 passed test MachineAccount
Starting test: NCSecDesc
Error Enterprise Read Only Domain Controllers doesn't have
Replicating Directory Changes
access rights for the naming context:
CN=Configuration,DC=abacus-corp,DC=com
......................... AD5 failed test NCSecDesc
Starting test: NetLogons
......................... AD5 passed test NetLogons
Starting test: ObjectsReplicated
......................... AD5 passed test ObjectsReplicated
Starting test: Replications
......................... AD5 passed test Replications
Starting test: RidManager
......................... AD5 passed test RidManager
Starting test: Services
......................... AD5 passed test Services
Starting test: SystemLog
......................... AD5 passed test SystemLog
Starting test: VerifyReferences
......................... AD5 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : abacus-corp
Starting test: CheckSDRefDom
......................... abacus-corp passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... abacus-corp passed test CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
This cross-ref has a non-standard dNSRoot attribute.
Cross-ref DN:
CN=72502b55-ef5c-4cea-a7af-2563b748787d,CN=Partitions,CN=Configuration,
DC=abacus-corp,DC=com
nCName attribute (Partition name):
DC=DomainDnsZones,DC=abacus-winhost,DC=com
Bad dNSRoot attribute: ADAM.abacus-winhost.com
Check with your network administrator to make sure this dNSRoot
attribute is correct, and if not please change the attribute to the
value below.
dNSRoot should be: DomainDnsZones.abacus-winhost.com
It appears this partition
(DC=DomainDnsZones,DC=abacus-winhost,DC=com) failed to get
completely created. This cross-ref
(CN=72502b55-ef5c-4cea-a7af-2563b748787d,CN=Partitions,CN=Configurat
ion,DC=abacus-corp,DC=com)
is dead and should be removed from the directory.
......................... DomainDnsZones failed test
CrossRefValidation
Running enterprise tests on : abacus-corp.com
Starting test: LocatorCheck
......................... abacus-corp.com passed test LocatorCheck
Starting test: Intersite
......................... abacus-corp.com passed test Intersite
ASKER
ASKER
ASKER
ASKER
ASKER
ASKER
ASKER
C:\Users\davidf>repadmin /showreps
WinHost\ADAM
DSA Options: IS_GC
Site Options: IS_INTER_SITE_AUTO_TOPOLOGY_DISABLED
DSA object GUID: 4ce6ac13-98b9-48c2-a911-5ed22c33018c
DSA invocationID: a3502141-943f-4c51-b03e-d1b058b73b03
==== INBOUND NEIGHBORS ======================================
CN=Configuration,DC=abacus-corp,DC=com
SanDiego\AD2 via RPC
DSA object GUID: 098a94ad-bbcc-4625-b604-53f572384c5f
Last attempt @ 2009-01-27 22:30:59 was successful.
CN=Schema,CN=Configuration,DC=abacus-corp,DC=com
SanDiego\AD2 via RPC
DSA object GUID: 098a94ad-bbcc-4625-b604-53f572384c5f
Last attempt @ 2009-01-27 22:30:59 was successful.
DC=ForestDnsZones,DC=abacus-corp,DC=com
SanDiego\AD2 via RPC
DSA object GUID: 098a94ad-bbcc-4625-b604-53f572384c5f
Last attempt @ 2009-01-27 22:30:59 was successful.
DC=abacus-corp,DC=com
SanDiego\AD2 via RPC
DSA object GUID: 098a94ad-bbcc-4625-b604-53f572384c5f
Last attempt @ 2009-01-27 22:30:59 was successful.
C:\Users\davidf>repadmin /syncall
CALLBACK MESSAGE: Error contacting server 4ce6ac13-98b9-48c2-a911-5ed22c33018c._
msdcs.abacus-corp.com (network error): 5 (0x5):
Access is denied.
SyncAll exited with fatal Win32 error: 8440 (0x20f8):
The naming context specified for this replication operation is invalid.
C:\Users\davidf>
ASKER
ASKER
ASKER
ASKER
Starting test: NCSecDesc
Error Enterprise Read Only Domain Controllers doesn't have
Replicating Directory Changes
access rights for the naming context:
DC=abacus-winhost,DC=com
Error Enterprise Read Only Domain Controllers doesn't have
Replicating Directory Changes
Replicating Directory Changes All
Replicating Directory Changes In Filtered Set
access rights for the naming context:
CN=Schema,CN=Configuration,DC=abacus-corp,DC=com
Error Enterprise Read Only Domain Controllers doesn't have
Replicating Directory Changes
access rights for the naming context:
CN=Configuration,DC=abacus-corp,DC=com
Error Enterprise Read Only Domain Controllers doesn't have
Replicating Directory Changes
access rights for the naming context:
DC=abacus-corp,DC=com
......................... ADAM failed test NCSecDesc
Active Directory (AD) is a Microsoft brand for identity-related capabilities. In the on-premises world, Windows Server AD provides a set of identity capabilities and services, and is hugely popular (88% of Fortune 1000 and 95% of enterprises use AD). This topic includes all things Active Directory including DNS, Group Policy, DFS, troubleshooting, ADFS, and all other topics under the Microsoft AD and identity umbrella.
TRUSTED BY
Still looking into the second error;