We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you two Citrix podcasts. Learn about 2020 trends and get answers to your biggest Citrix questions!Listen Now

x

error occured while contacting the global catalog

Medium Priority
1,874 Views
Last Modified: 2012-06-21
Hi
I can not create users in my active directory, I am using replication on two servers "well I inherited the setup so I am not sure what was done here" and when I try to create a user the following error appears :

Windows cannot verify that the user name is unique because the following error occured while contacting the global catalog: A local error has occured
Comment
Watch Question

Commented:
Is your Global Catalog Server online Check your FSMO roles to see what role lies on what server.. This would be a great starting place.
Top Expert 2008

Author

Commented:
Hmm.. how to chekc those ?
Thanks
CERTIFIED EXPERT
Top Expert 2013

Commented:
Have you tried to create the user on both domain controllers?  Is it just one DC or both DCs that are giving you this error message?
To quickly tell what boxes are the GC's run
dsquery server -forest -isgc
Is the box you are getting this error on a GC?
Thanks
Mike
 

Commented:
Check FSMO roles by using "netdom query fsmo".  It may also be that your RID (Reflexive ID) Master is not working.  This is one of the five FSMO roles assigned to DCs.
Chris HudsonCloud Security Architect
CERTIFIED EXPERT

Commented:
First make sure that there is one GC available.To check whether Ur Dc is really acting as GC there are 2 tests.
1) Run ldp >Connect to Ur DC.
    on right hand side of Ur ldp window,U will Global Catalgue Readt: true/false
2)Run ldp and try to connect to the GC port 3268 of Ur DC

If your DC is working as GC ,check the GC srv record are there in DC or not.
If you cannot connect to the GC port via ldp,eventhough the check mark is there in dssite.msc,ntds settings property of DC,check the "Directory Services"  events.If you don't have a GC in Ur domain ,please configure one Dc as GC.The domain naming master shud be a GC.There are some scenarios where GC promotion will fail if there are some orphan domains,in that case do a metadata cleanup to remove orphan domain and promote the DC as GC.While you promote the DC as GC,make sure that U get the event id "1119" in Directory service log
Top Expert 2008

Author

Commented:
This command dsquery server -forest -isgc
Shows both servers :

C:\Documents and Settings\Techsupport>dsquery server -forest -isgc
"CN=CHHPX61,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=school
ofhealth,DC=edu"
"CN=SHCSERVEREDB,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=s
choolofhealth,DC=edu"


I can create users on the first server but not on the second
CERTIFIED EXPERT
Top Expert 2013

Commented:
run a dcdiag and repadmin /showreps on your 2nd DC that is having issues.
Can you post those results if possible?
Thanks
Mike
Cloud Security Architect
CERTIFIED EXPERT
Commented:
It looks like the 2nd DC cannot contact GC.
1)Check whether replication is fine or not
If replication is fine,get a Netmon trace and filter "tcp.port==3268" and see whether any drops or resets are there

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Top Expert 2008

Author

Commented:
Will check and get back to you..sory for the delay.
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.