The question starts with the issues I was having with WSUS to show you how I arrived at the my real question. I can save the WSUS question for another post, just wanted to give some background info in case it's relevant.
The other week I realized I could no longer open the WSUS console on one of our 2008 servers (Antelope).
Error: MMC has detected an error in a snap-in and will unload it.
When I chose to “Unload the snap-in and continue running” I received the message box:
End Snap-in. The snap-in is not responding.
I’d choose “End Now” and receive an “Unhandled Exception in Managed Code Snap-in."
I tried a few things, including removing the WSUS file, but couldn’t get it to work. I ended up uninstalling/reinstalling ASP.net and WSUS. However, once WSUS was installed again, it no longer showed up under the Admin Tools menu… I had to access it via Server Manager. Every time server manager was closed, all the Classifications I had chosen no longer showed up under the Updates section. The default Updates showed up: All Updates, Critical Updates, Security Updates and WSUS Updates, and all the other classifications are still checked in the Products and Classifications window, but I need to uncheck them, hit apply, check and apply again. I also noticed that the few Windows 7 boxes we have show up as an OS of Windows 6.1. I finally decided to see if I could correct these things and ran into some more problems…
This server became a Domain Controller and AD was installed during the brief time WSUS was uninstalled, so I figured uninstalling AD would be a good place to start. The PDC was a 2003 server (Maze). I believe this caused the IUSR accounts to be removed and it’s the reason I get this error in the event log:
Self-update is not working.
I tried using the script here: http://support.microsoft.com/?kbid=946139
but it gives me the error:
There was an error attempting to retrieve the localhost RootDSE object.
Perhaps this machine is not a Domain Controller on the network?
I’ve gathered this info: LDAP_SERVER_DOWN This error code occurs when the addressed server is unreachable during a BIND authentication in the directory. This can occur due to underlying network problems. A firewall may block the used LDAP port, or the LDAP service isn't active on the destination host.
I pulled up ldp.exe and was able to connect (and bind to the server by using its own name, Antelope, but not when using the term “localhost.” I assumed MS wanted me to change “localhost” to the name of my server, so I did. The script got further this time, I forget the exact wording of the message I got, but it seemed as if it was working. After a while I checked and the IUSR accounts were still missing. I ended up promoting another 2008 server (Dividedsky) to the PDC role to hopefully avoid future problems.
I also tried restarting the IIS Admin Service, once Dividedsky was the PDC, but still no IUSR accounts.
So anyway, I wanted to remove Antelope as a DC and remove AD. I start by using dcpromo.exe to remove Antelope from DC status but get an error after the “Delete the Domain” window:
Failed to examine the Active Directory forest. The error was: The operation cannot continue because LDAP connect/bind operation failed: 58 (the specified server cannot perform the requested operation.).
Google was little help with this error, except for what I found here:
(under ‘Splain This heading). So, I disabled the local admin account, but no dice, still got the same error.
Looking at the dcpromoui.log doesn’t give me much help, but hopefully someone sees something of use. I've attached it.
I think another big piece to this puzzle may be the fact that the Intersite Messaging service fails to start at startup, or when I try to do it manually. When tried manually I get a pop-up that says “Failed to start Intersite Messaging The service changed to an unexpected state.” In the system event viewer: The Intersite Messaging service terminated with the following error: The specified server cannot perform the requested operation. No errors about this in the application event viewer (I saw someone online w/ this problem who had an error in here too).
Anyone have any ideas as to why I’m having trouble removing Antelope as a DC?