Solved

DC Directory Service error reporting

Posted on 2009-04-03
28
453 Views
Last Modified: 2012-05-06
Hi experts

I'm getting these several errors on my DC event viewer and I'd like to know what are these errors and what are the effects in the future on the Server, what precautions should I consider to avoid any damage to it.

First Error

I have so much errors generated on my DC, And i'm curious what are these errors are all about and what are the affections
 This is the replication status for the following directory partition on the local domain controller.  Directory partition:DC=ForestDnsZones,DC=TNT,DC=local  The local domain controller has not recently received replication information from a number of domain controllers.   The count of domain controllers is shown, divided into the following intervals.  More than 24 hours:1 More than a week:1 More than one month:1 More than two months:1 More than a tombstone lifetime:0 Tombstone lifetime (days):180  Domain controllers that do not replicate in a timely manner may encounter errors. It may miss password changes and be unable to authenticate. A DC that has not replicated in a tombstone lifetime may have missed the deletion of some objects, and may be automatically blocked from future replication until it is reconciled.  To identify the domain controllers by name, install the support tools included on the installation  CD and run dcdiag.exe. You can also use the support tool repadmin.exe to display the replication latencies of the domain controllers in the forest.   The command is "repadmin /showvector /latency <partition-dn>".For more information, see Help and Support Center at


Second Error

 This server is the owner of the following FSMO role, but does not consider it valid. For the partition which contains the FSMO, this server has not replicated successfully with any of its partners since this server has been restarted. Replication errors are preventing validation of this role.  Operations which require contacting a FSMO operation master will fail until this condition is corrected.  FSMO Role: CN=Infrastructure,DC=TNT,DC=local  User Action:  1. Initial synchronization is the first early replications done by a system as it is starting. A failure to initially synchronize may explain why a FSMO role cannot be validated. This process is explained in KB article 305476. 2. This server has one or more replication partners, and replication is failing for all of these partners. Use the command repadmin /showrepl to display the replication errors.  Correct the error in question. For example there maybe problems with IP connectivity, DNS name resolution, or se
11:01:47 PM 173808600: or security authentication that are preventing successful replication. 3. In the rare event that all replication partners being down is an expected occurance, perhaps because of maintenance or a disaster recovery, you can force the role to be validated. This can be done by using NTDSUTIL.EXE to seize the role to the same server. This may be done using the steps provided in KB articles 255504 and 324801 on http://support.microsoft.com.  The following operations may be impacted: Schema: You will no longer be able to modify the schema for this forest. Domain Naming: You will no longer be able to add or remove domains from this forest. PDC: You will no longer be able to perform primary domain controller operations, such as Group Policy updates and password resets for non-Active Directory accounts. RID: You will not be able to allocation new security identifiers for new user accounts, computer accounts or security groups. Infrastructure: Cross-domain name references, such
11:02:07 PM 173808600: as universal group memberships, will not be updated properly if their target object is moved or renamed.For more information, see Help and Support Center at


Note, there are some other errors most of them I guess are close to these ones above, and all of them are generated in 7:05 am, or 7:50 pm daily.
0
Comment
Question by:Mohammed Hamada
  • 14
  • 10
  • 2
  • +1
28 Comments
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24063794
Well you are having trouble with replication with the DCs. How long has this been going on? Run a netdiag and post results please.
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24064207
The server is windows 2003 not 2000 ? and there's no netdiag command ...?
0
 
LVL 27

Expert Comment

by:Lukasz Chmielewski
ID: 24064406
try to set cross dns zone transfer for dns servers
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24064446
Didn't understand that, can you please tell me how to do that step by step?

0
 
LVL 59

Expert Comment

by:Darius Ghassem
ID: 24065239
0
 
LVL 27

Expert Comment

by:Lukasz Chmielewski
ID: 24067999
in the properties of dns server, enter the "zone transer" tab and set the others dns server ip address, do the same on the second dns server
0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24072245
Zone transfers have nothing to do with this, sorry.

That said you've got a DC that hasn't replicated in 2+ months. Install the Support Tools for Windows (download from Microsoft), and run a repadmin /showreps. Post the results.

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24079329
Dariusq, The command doesn't work it give invalid command.

Roads_roads we only have one DNS server which is the one I have problem with ...

Bdesmond, Will do so ..

Thanks everyone.

0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24080030
Here's the result.


report.txt
0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24080064
So do you have a system on the LAN called BACKUP-SERVER?

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24080121
I did have before as a backup, but I have demoted this server .... .. though it still exists in sites & services.
0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24080185
So something didn't quite work out when you demoted it. This KB article http://support.microsoft.com/kb/216498 outlines how to do a metadata cleanup of the box. Do that and see where it gets you.

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24080395
Basically i'm not sure if i have done the demoted the server in a proper way... just for your info..  The steps i did to demote is ...
Open active directory..
Under the DC name -- > Domain Controllers --> Right clicked on the backup server and clicked on delete.
It then popped up a box saying how or why do i want to demote this server, I choose this server is no longer connected the last option..

Is that correct or there should any other commands I should apply ?
0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24080401
Yeah that doesn't count as demoting the server, unfortunately.

Is the server permanently offline?

Thanks,
Brian Desmond
Active Directory MVP
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24080493
Yes it is... How do i demote the server then please?
Thanks

0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24080499
You need to run a dcpromo /forceremoval on that server, and then you need to do the metadata cleanup from a different box.

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24080693
Unfortunately the Backup Server is permanently down and no longer exists ... It has been moved to a different location ...

The metadata cleanup returned the following error

C:\Documents and Settings\Administrator.SERVER>ntdsutil
ntdsutil: metadata cleanup
metadata cleanup: remove selected server backup-server

Binding to localhost ...Connected to localhost using credentials of locally logged on user.LDAP error 0x22(34 (Invalid DN Syntax).Ldap extended error message is 0000208F: NameErr: DSID-031001BA, problem 2006 (BAD_NAME), data 8350, best match of:        'CN=Ntds Settings,backup-server'Win32 error returned is 0x208f(The object name has bad syntax.))
Unable to determine the domain hosted by the DC (5). Please use the connection menu to specify it.Disconnecting from localhost...

metadata cleanup:


0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24080704
You need to go into the select operation target menu and specify this data. Steps 7-15 in the KB article I linked to detail this.

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24080951
Tried that ... when I try to list domains it gives me the following error .
Not connected to a server - use "Connections"

I then type connections and type Info but that doesn't do anything ...!

0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24081076
Are you following the steps in the KB article?

metadata cleanup
connections
connect to server DcThatStillWorks
quit
select op target
list domains
select domain K
list sites
select site K
list servers in site
select server K
quit
remove selected server

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24086132
Here's what I did according to the article... and to your comment.
Connections
server connections: connect to server server
Binding to server ...
Connected to server using credentials of locally logged on user.
server connections: quit
select operation target: list domains
Found 1 domain(s)
0 - DC=TNT,DC=local
select operation target: select domain 0
No current site
Domain - DC=TNT,DC=local
No current server
No current Naming Context
select operation target: list sites
Found 1 site(s)
0 - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local


However when I tried to to select site name by type the following command
select site 0 and select TNT but non works it gives me the following error
Error 80070057 parsing input - illegal syntax?
Not sure if i have done it correct or not and same thing when I type select Domain 0 or TNT.

0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24123553
You shouldn't be specifying any names.

select site 0

list servers in site
select server 0 <put the right number>

If it is still failing please paste in ALL the input/output.

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24124033
I think there's something wrong... it's not working.

Here's what i've tried.

select operation target: select site 0
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
No current server
No current Naming Context

select operation target: list server in site
Found 2 server(s)
0 - CN=SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,
DC=local
1 - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,
DC=TNT,DC=local

select operation target: select site 1
Selection out of range

select operation target: select 0
Error 80070057 parsing input - illegal syntax?

select operation target: select site 0
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
No current server
No current Naming Context

select operation target: select site 0
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
No current server
No current Naming Context

select operation target: select site 1
Selection out of range

select operation target: select server 0
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
Server - CN=SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC
=TNT,DC=local
        DSA object - CN=NTDS Settings,CN=SERVER,CN=Servers,CN=Default-First-Site
,CN=Sites,CN=Configuration,DC=TNT,DC=local
        DNS host name - server.TNT.local
        Computer object - CN=SERVER,OU=Domain Controllers,DC=TNT,DC=local
No current Naming Context

select operation target: select server 1
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
Server - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configura
tion,DC=TNT,DC=local
        DSA object - CN=NTDS Settings,CN=BACKUP-SERVER,CN=Servers,CN=Default-Fir
st-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
        DNS host name - backup-server.TNT.local
No current Naming Context



0
 
LVL 6

Expert Comment

by:bdesmond
ID: 24124036
When you get this:

select operation target: list server in site
Found 2 server(s)
0 - CN=SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,
DC=local
1 - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,
DC=TNT,DC=local


You need to do "select server 1" followed by "quit".

I see all the way at the bottom taht you have done this correctly.

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24125740
Here's an update,, It gives this msg when I type remove selected server  as you can see below.
No current domain - use "Select operation target"


select operation target: list server in site
Found 2 server(s)
0 - CN=SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,
DC=local
1 - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,
DC=TNT,DC=local

select operation target: select server 1
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
No current domain
Server - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configura
tion,DC=TNT,DC=local
        DSA object - CN=NTDS Settings,CN=BACKUP-SERVER,CN=Servers,CN=Default-Fir
st-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
        DNS host name - backup-server.TNT.local
No current Naming Context

select operation target: quit
metadata cleanup: remove selected server
No current domain - use "Select operation target"
metadata cleanup:

0
 
LVL 6

Accepted Solution

by:
bdesmond earned 500 total points
ID: 24126518
OK so you need to do the ENTIRE procedure from top to bottom. That means:

Connections
server connections: connect to server server
Binding to server ...
Connected to server using credentials of locally logged on user.
server connections: quit
select operation target: list domains
Found 1 domain(s)
0 - DC=TNT,DC=local
select operation target: select domain 0
No current site
Domain - DC=TNT,DC=local
No current server
No current Naming Context
select operation target: list sites
Found 1 site(s)
0 - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
select operation target: select site 0
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
No current server
No current Naming Context
select operation target: list server in site
Found 2 server(s)
0 - CN=SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,
DC=local
1 - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configuration,
DC=TNT,DC=local
select operation target: select server 1
Site - CN=Default-First-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
Domain - DC=TNT,DC=local
Server - CN=BACKUP-SERVER,CN=Servers,CN=Default-First-Site,CN=Sites,CN=Configura
tion,DC=TNT,DC=local
        DSA object - CN=NTDS Settings,CN=BACKUP-SERVER,CN=Servers,CN=Default-Fir
st-Site,CN=Sites,CN=Configuration,DC=TNT,DC=local
        DNS host name - backup-server.TNT.local
No current Naming Context
select operation target: quit
metadata cleanup: remove selected server

Thanks,
Brian Desmond
Active Directory MVP
0
 
LVL 23

Author Comment

by:Mohammed Hamada
ID: 24126937
Wow, finally it worked...
Thanks so much.... I will check the event viewer in the few coming days and will let u know then.

screenshot.jpg
0
 
LVL 23

Author Closing Comment

by:Mohammed Hamada
ID: 31566428
I think there's no more errors generated anymore... the problems seems to be all generated from the Backup server which was not demoted correctly from the main server...
Thanks so much for this great information & knowledge...!
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now