[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Adding Windows Server 2008 R2 DC into 2003 domain

Posted on 2011-10-18
3
Medium Priority
?
365 Views
Last Modified: 2012-05-12
I have a Windows 2003 network (AD etc). We have two Windows Server 2003 DC's.

We have purchased 2 new servers and have installed Windows Server 2008 R2 (standard) on them.

I want to add those new servers to the exisiting domain, migrate all services from the 2003 servers to the 2008 servers, decommision the 2003 servers.

I have installed the AD Domain Services Role onto the new DC. When I run the AD DS nstallation Wizard it tells me (rightly so) that I need to run "adprep /forestprep" on the exisiting domain to enable the new 2009 R2 server to be added as DC.

So I run "adprep /forestprep"  on the old server but it reports that:
"Forest-wide information has already been updated.
[Status/Consequence]
Adprep did not attempt to rerun this operation."

Try on the 2008 R2 server but get same error message - loop time!!

Please help!!

Thanks
Mark
0
Comment
Question by:Mark Galvin
  • 2
3 Comments
 
LVL 85

Accepted Solution

by:
oBdA earned 2000 total points
ID: 36985062
You need to run adprep on the W2k3 DC from the W2k8 DVD:
Prepare a Windows 2000 or Windows Server 2003 Forest Schema for a Domain Controller That Runs Windows Server 2008 or Windows Server 2008 R2
http://technet.microsoft.com/en-us/library/cc753437(WS.10).aspx
0
 
LVL 13

Author Comment

by:Mark Galvin
ID: 36985152
Thanks for that! ForestPrep now run all fine. DomainPrep also run fine.

Now trying to run RODCPREP and getting this error:
"Adprep completed with errors. Not all partitions are updated. See the ADPrep.log
 in the C:\WINDOWS\debug\adprep\logs\20111018113553 directory for more informati
on."

Log file:
"[2011/10/18:11:33:33.962]
Adprep created the log file ADPrep.log under C:\WINDOWS\debug\adprep\logs\20111018113333 directory.
[2011/10/18:11:33:33.978]
Adprep connected to the domain FSMO: intlondc01.company.ads.
[2011/10/18:11:33:33.978]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is (null).
[2011/10/18:11:33:33.978]
LDAP API ldap_search_s() finished, return code is 0x0
[2011/10/18:11:33:33.978]
Adprep successfully retrieved information from the local Active Directory Domain Services.
[2011/10/18:11:33:33.978]
Adprep successfully initialized global variables.

[Status/Consequence]

Adprep is continuing.
[2011/10/18:11:33:33.978]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is CN=Partitions,CN=Configuration,DC=company,DC=ads.
[2011/10/18:11:33:33.978]
LDAP API ldap_search_s finished, return code is 0x0
[2011/10/18:11:33:33.978]
==============================================================================

Adprep found partition DC=ForestDnsZones,DC=company,DC=ads, and is about to update the permissions.
[2011/10/18:11:33:34.009]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is CN=Infrastructure,DC=ForestDnsZones,DC=company,DC=ads.
[2011/10/18:11:33:34.009]
LDAP API ldap_search_s finished, return code is 0x0
[2011/10/18:11:33:34.024]
Adprep could not contact a replica for partition DC=ForestDnsZones,DC=company,DC=ads.
[2011/10/18:11:33:34.024]
Adprep encountered an LDAP error.

Error code: 0x0. Server extended error code: 0x0, Server error message: (null).
[2011/10/18:11:33:34.024]
Adprep failed the operation on partition DC=ForestDnsZones,DC=company,DC=ads. Skipping to next partition.

==============================================================================
[2011/10/18:11:33:34.040]
==============================================================================

Adprep found partition DC=DomainDnsZones,DC=company,DC=ads, and is about to update the permissions.
[2011/10/18:11:33:34.040]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is CN=Infrastructure,DC=DomainDnsZones,DC=company,DC=ads.
[2011/10/18:11:33:34.040]
LDAP API ldap_search_s finished, return code is 0x0
[2011/10/18:11:33:34.040]
Adprep could not contact a replica for partition DC=DomainDnsZones,DC=company,DC=ads.
[2011/10/18:11:33:34.056]
Adprep encountered an LDAP error.

Error code: 0x0. Server extended error code: 0x0, Server error message: (null).
[2011/10/18:11:33:34.056]
Adprep failed the operation on partition DC=DomainDnsZones,DC=company,DC=ads. Skipping to next partition.

==============================================================================
[2011/10/18:11:33:34.056]
==============================================================================

Adprep found partition DC=company,DC=ads, and is about to update the permissions.
[2011/10/18:11:33:34.071]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is CN=Infrastructure,DC=company,DC=ads.
[2011/10/18:11:33:34.071]
LDAP API ldap_search_s finished, return code is 0x0
[2011/10/18:11:33:34.071]
Adprep connected to the Infrastructure FSMO: intlondc01.company.ads.
[2011/10/18:11:33:34.071]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is DC=company,DC=ads.
[2011/10/18:11:33:34.071]
LDAP API ldap_search_s() finished, return code is 0x0
[2011/10/18:11:33:34.071]
Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is DC=company,DC=ads.
[2011/10/18:11:33:34.071]
LDAP API ldap_modify_ext_s() finished, return code is 0x0
[2011/10/18:11:33:34.071]
Adprep successfully modified the security descriptor on object DC=company,DC=ads.

[Status/Consequence]

Adprep merged the existing security descriptor with the new access control entry (ACE).
[2011/10/18:11:33:34.071]
Adprep was about to call the following LDAP API. ldap_search_s(). The base entry to start the search is DC=company,DC=ads.
[2011/10/18:11:33:34.071]
LDAP API ldap_search_s() finished, return code is 0x0
[2011/10/18:11:33:34.071]
Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is DC=company,DC=ads.
[2011/10/18:11:33:34.087]
LDAP API ldap_modify_ext_s() finished, return code is 0x0
[2011/10/18:11:33:34.087]
Adprep successfully modified the security descriptor on object DC=company,DC=ads.

[Status/Consequence]

Adprep merged the existing security descriptor with the new access control entry (ACE).
[2011/10/18:11:33:34.087]
Adprep was about to call the following LDAP API. ldap_modify_s(). The entry to modify is CN=companyADS,CN=Partitions,CN=Configuration,DC=company,DC=ads.
[2011/10/18:11:33:34.087]
LDAP API ldap_modify_s() finished, return code is 0x0
[2011/10/18:11:33:34.087]
The operation on partition DC=company,DC=ads was successful.

==============================================================================
[2011/10/18:11:33:34.103]
Adprep completed with errors. Not all partitions are updated. See the ADPrep.log in the C:\WINDOWS\debug\adprep\logs\20111018113333 directory for more information.



To successfully update all partititions, the current logged on user needs to be a member of Enterprise Admins group.  If that is not the case, please correct the problem, and then restart Adprep."

Any more help would be great.

thanks
Mark
0
 
LVL 13

Author Comment

by:Mark Galvin
ID: 36985168
Hi

Forget the above - I dont want a read only dc!!

Thanks!
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Suggested Courses

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question