Solved

Replication Issue

Posted on 2011-02-22
11
330 Views
Last Modified: 2012-05-11
Client reports that AD replication between PDC and another DC always fails
with error "Access Denied". When forcing replication using ADSS on the DC, error
"The target principal name is incorrect"; secondly when forcing replication from
PDC console, error is "access is denied"
What needs to be check in this case & should be done to resolve?
A. Reset secure channel with the PDC may fix this issue
B. Check SPN related errors using dcdiag
C. Check DNS related errors using dcdiag
D. Check time difference between 2 domain controllers

/////////////////////////////////

I do not agree with the above to be very clear I do not know SPN related errors, also dns errors canot cause it. I believe that it is d) reason the time difference because if the time difference is not agreeing then the replication cannot be done.
0
Comment
Question by:kunalclk
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 20

Accepted Solution

by:
woolnoir earned 250 total points
ID: 34950503
http://support.microsoft.com/kb/288167

followed this one ? specifically the netdom resetpwd part ?
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950505
Ive seen the situation as you describe above exactly on EE before, and in my environment and the link above fixed it, so its worth a look.
0
 
LVL 17

Expert Comment

by:Sikhumbuzo Ntsada
ID: 34950510
I would say D - when you point a PC\Client to authenticate to the BDC while it has a wrong time you will not be able to log in, thus the time difference is the culprit. After you change the time it will then allow authentication because it is now able to communicate with the PDC.


0
NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 34950542
I would say A, reset secure channel to PDC :) Access Denied would suggest that there is problem with secure channel

Regards,
Krzysztof
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950579
Yep, A is the option which my link above fixes - give it a try and let us know.
0
 
LVL 2

Author Comment

by:kunalclk
ID: 34950596
Then why The target principal name is incorrect is the error and what is SPN error. Why the time difference cannot cause it. I have tried it on client server the same error comes acces denied.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 34950597
@woolnoir: it's difficult to check because it's a test question from 290 exam :)
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950599
In that case, i'd pick A :) 100%
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950601
check the link above, its from a MS knowledge-base article and those derive a lot of the Exam Q's :)
0
 
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 250 total points
ID: 34950624
In domain environment all DCs are synchronizing time with forest root PDC, so if time difference is present there is problem with PDC. So, then you know that there is another issue. DNS error would reply with different error messages like cannot contact to <domain name> or something like that.

SPN is related with user rather than DC.

Krzysztof
0
 
LVL 2

Author Closing Comment

by:kunalclk
ID: 34950687
tnx
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article runs through the process of deploying a single EXE application selectively to a group of user.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question