Solved

Replication Issue

Posted on 2011-02-22
11
304 Views
Last Modified: 2012-05-11
Client reports that AD replication between PDC and another DC always fails
with error "Access Denied". When forcing replication using ADSS on the DC, error
"The target principal name is incorrect"; secondly when forcing replication from
PDC console, error is "access is denied"
What needs to be check in this case & should be done to resolve?
A. Reset secure channel with the PDC may fix this issue
B. Check SPN related errors using dcdiag
C. Check DNS related errors using dcdiag
D. Check time difference between 2 domain controllers

/////////////////////////////////

I do not agree with the above to be very clear I do not know SPN related errors, also dns errors canot cause it. I believe that it is d) reason the time difference because if the time difference is not agreeing then the replication cannot be done.
0
Comment
Question by:kunalclk
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 20

Accepted Solution

by:
woolnoir earned 250 total points
Comment Utility
http://support.microsoft.com/kb/288167

followed this one ? specifically the netdom resetpwd part ?
0
 
LVL 20

Expert Comment

by:woolnoir
Comment Utility
Ive seen the situation as you describe above exactly on EE before, and in my environment and the link above fixed it, so its worth a look.
0
 
LVL 17

Expert Comment

by:Sikhumbuzo Ntsada
Comment Utility
I would say D - when you point a PC\Client to authenticate to the BDC while it has a wrong time you will not be able to log in, thus the time difference is the culprit. After you change the time it will then allow authentication because it is now able to communicate with the PDC.


0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
I would say A, reset secure channel to PDC :) Access Denied would suggest that there is problem with secure channel

Regards,
Krzysztof
0
 
LVL 20

Expert Comment

by:woolnoir
Comment Utility
Yep, A is the option which my link above fixes - give it a try and let us know.
0
Do email signature updates give you a headache?

Do you feel like you are constantly making changes to email signatures? Are the images not formatting how you want them to? Want high-quality HTML signatures on all devices, including on mobiles and Macs? Then, let Exclaimer solve all your email signature problems today.

 
LVL 2

Author Comment

by:kunalclk
Comment Utility
Then why The target principal name is incorrect is the error and what is SPN error. Why the time difference cannot cause it. I have tried it on client server the same error comes acces denied.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
Comment Utility
@woolnoir: it's difficult to check because it's a test question from 290 exam :)
0
 
LVL 20

Expert Comment

by:woolnoir
Comment Utility
In that case, i'd pick A :) 100%
0
 
LVL 20

Expert Comment

by:woolnoir
Comment Utility
check the link above, its from a MS knowledge-base article and those derive a lot of the Exam Q's :)
0
 
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 250 total points
Comment Utility
In domain environment all DCs are synchronizing time with forest root PDC, so if time difference is present there is problem with PDC. So, then you know that there is another issue. DNS error would reply with different error messages like cannot contact to <domain name> or something like that.

SPN is related with user rather than DC.

Krzysztof
0
 
LVL 2

Author Closing Comment

by:kunalclk
Comment Utility
tnx
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now