Solved

Replication Issue

Posted on 2011-02-22
11
322 Views
Last Modified: 2012-05-11
Client reports that AD replication between PDC and another DC always fails
with error "Access Denied". When forcing replication using ADSS on the DC, error
"The target principal name is incorrect"; secondly when forcing replication from
PDC console, error is "access is denied"
What needs to be check in this case & should be done to resolve?
A. Reset secure channel with the PDC may fix this issue
B. Check SPN related errors using dcdiag
C. Check DNS related errors using dcdiag
D. Check time difference between 2 domain controllers

/////////////////////////////////

I do not agree with the above to be very clear I do not know SPN related errors, also dns errors canot cause it. I believe that it is d) reason the time difference because if the time difference is not agreeing then the replication cannot be done.
0
Comment
Question by:kunalclk
  • 5
  • 3
  • 2
  • +1
11 Comments
 
LVL 20

Accepted Solution

by:
woolnoir earned 250 total points
ID: 34950503
http://support.microsoft.com/kb/288167

followed this one ? specifically the netdom resetpwd part ?
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950505
Ive seen the situation as you describe above exactly on EE before, and in my environment and the link above fixed it, so its worth a look.
0
 
LVL 17

Expert Comment

by:Sikhumbuzo Ntsada
ID: 34950510
I would say D - when you point a PC\Client to authenticate to the BDC while it has a wrong time you will not be able to log in, thus the time difference is the culprit. After you change the time it will then allow authentication because it is now able to communicate with the PDC.


0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 34950542
I would say A, reset secure channel to PDC :) Access Denied would suggest that there is problem with secure channel

Regards,
Krzysztof
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950579
Yep, A is the option which my link above fixes - give it a try and let us know.
0
 
LVL 2

Author Comment

by:kunalclk
ID: 34950596
Then why The target principal name is incorrect is the error and what is SPN error. Why the time difference cannot cause it. I have tried it on client server the same error comes acces denied.
0
 
LVL 39

Expert Comment

by:Krzysztof Pytko
ID: 34950597
@woolnoir: it's difficult to check because it's a test question from 290 exam :)
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950599
In that case, i'd pick A :) 100%
0
 
LVL 20

Expert Comment

by:woolnoir
ID: 34950601
check the link above, its from a MS knowledge-base article and those derive a lot of the Exam Q's :)
0
 
LVL 39

Assisted Solution

by:Krzysztof Pytko
Krzysztof Pytko earned 250 total points
ID: 34950624
In domain environment all DCs are synchronizing time with forest root PDC, so if time difference is present there is problem with PDC. So, then you know that there is another issue. DNS error would reply with different error messages like cannot contact to <domain name> or something like that.

SPN is related with user rather than DC.

Krzysztof
0
 
LVL 2

Author Closing Comment

by:kunalclk
ID: 34950687
tnx
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question