Link to home
Start Free TrialLog in
Avatar of RSI808
RSI808

asked on

active directory could not replicate the directory partition

I have a single domain environment with a single server running 2003.  This server is the PDC, DNS, DHCP server.

I am migrating to a new server 2008r2 server, that will assume all roles of the old server.

My problem:

During DCpromo, the new server throws an error about not being able to replicate the directory partition.  
Even though the DCpromo fails, I can go into Active Directory Users and Computers and it shows all of what Would be replicated...it's all there.  But it just wont become a domain controller.

I have ran all of the adprep commands.
Im currently looking through DCDiag on the old server to see if anything is failing--so far the only part that doesnt pass is in the very beginning:
"warning: could not confirm the identity of this server in the directory versus the names returned by dns........."

I have reset the flag in the registry to resolve the Ntfrs failure that was occuring (it fixed that issue).
Avatar of Darius Ghassem
Darius Ghassem
Flag of United States of America image

Did the promotion go through at all? If it did demote the server then run metadata cleanup.

Run dcdiag on 2003 server post.

Make sure you are pointing to 2003 Server for DNS.

Go through the promotion again post the exact error you are getting.
Avatar of RSI808
RSI808

ASKER

DCPromo gets to the very end to the point where it stops the Netlogon service and starts trying to replicate the shcema partition.

User generated image

this is the dcdiag:

Domain Controller Diagnosis

Performing initial setup:
   * Verifying that the local machine grelotserver, is a DC.
   * Connecting to directory service on server grelotserver.
   * Collecting site info.
   * Identifying all servers.
   * Identifying all NC cross-refs.
   * Found 1 DC(s). Testing 1 of them.
   Done gathering initial info.

Doing initial required tests
   
   Testing server: Default-First-Site-Name\GRELOTSERVER
      Starting test: Connectivity
         * Active Directory LDAP Services Check
            *** Warning: could not confirm the identity of this server in
               the directory versus the names returned by DNS servers.
               If there are problems accessing this directory server then
               you may need to check that this server is correctly registered
               with DNS
         * Active Directory RPC Services Check
         ......................... GRELOTSERVER passed test Connectivity

Doing primary tests
   
   Testing server: Default-First-Site-Name\GRELOTSERVER
      Starting test: Replications
         * Replications Check
         * Replication Latency Check
         ......................... GRELOTSERVER passed test Replications
      Test omitted by user request: Topology
      Test omitted by user request: CutoffServers
      Starting test: NCSecDesc
         * Security Permissions check for all NC's on DC GRELOTSERVER.
         * Security Permissions Check for
           DC=ForestDnsZones,DC=grelotdental,DC=local
            (NDNC,Version 2)
         * Security Permissions Check for
           DC=DomainDnsZones,DC=grelotdental,DC=local
            (NDNC,Version 2)
         * Security Permissions Check for
           CN=Schema,CN=Configuration,DC=grelotdental,DC=local
            (Schema,Version 2)
         * Security Permissions Check for
           CN=Configuration,DC=grelotdental,DC=local
            (Configuration,Version 2)
         * Security Permissions Check for
           DC=grelotdental,DC=local
            (Domain,Version 2)
         ......................... GRELOTSERVER passed test NCSecDesc
      Starting test: NetLogons
         * Network Logons Privileges Check
         Verified share \\GRELOTSERVER\netlogon
         Verified share \\GRELOTSERVER\sysvol
         ......................... GRELOTSERVER passed test NetLogons
      Starting test: Advertising
         The DC GRELOTSERVER is advertising itself as a DC and having a DS.
         The DC GRELOTSERVER is advertising as an LDAP server
         The DC GRELOTSERVER is advertising as having a writeable directory
         The DC GRELOTSERVER is advertising as a Key Distribution Center
         The DC GRELOTSERVER is advertising as a time server
         The DS GRELOTSERVER is advertising as a GC.
         ......................... GRELOTSERVER passed test Advertising
      Starting test: KnowsOfRoleHolders
         Role Schema Owner = CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local
         Role Domain Owner = CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local
         Role PDC Owner = CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local
         Role Rid Owner = CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local
         ......................... GRELOTSERVER passed test KnowsOfRoleHolders
      Starting test: RidManager
         * Available RID Pool for the Domain is 1610 to 1073741823
         * grelotserver is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 1110 to 1609
         * rIDPreviousAllocationPool is 1110 to 1609
         * rIDNextRID: 1176
         ......................... GRELOTSERVER passed test RidManager
      Starting test: MachineAccount
         Checking machine account for DC GRELOTSERVER on DC GRELOTSERVER.
         * SPN found :LDAP/grelotserver/grelotdental.local
         * SPN found :LDAP/grelotserver
         * SPN found :LDAP/GRELOTSERVER
         * SPN found :LDAP/grelotserver/GRELOTDENTAL
         * SPN found :LDAP/c7e7fdad-ed36-494c-a22d-afc67746ec82._msdcs.grelotdental.local
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/c7e7fdad-ed36-494c-a22d-afc67746ec82/grelotdental.local
         * SPN found :HOST/grelotserver/grelotdental.local
         * SPN found :HOST/grelotserver
         * SPN found :HOST/GRELOTSERVER
         * SPN found :HOST/grelotserver/GRELOTDENTAL
         * SPN found :GC/grelotserver/grelotdental.local
         ......................... GRELOTSERVER passed test MachineAccount
      Starting test: Services
         * Checking Service: Dnscache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: RpcSs
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... GRELOTSERVER passed test Services
      Test omitted by user request: OutboundSecureChannels
      Starting test: ObjectsReplicated
         GRELOTSERVER is in domain DC=grelotdental,DC=local
         Checking for CN=GRELOTSERVER,OU=Domain Controllers,DC=grelotdental,DC=local in domain DC=grelotdental,DC=local on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local in domain CN=Configuration,DC=grelotdental,DC=local on 1 servers
            Object is up-to-date on all servers.
         ......................... GRELOTSERVER passed test ObjectsReplicated
      Starting test: frssysvol
         * The File Replication Service SYSVOL ready test
         File Replication Service's SYSVOL is ready
         ......................... GRELOTSERVER passed test frssysvol
      Starting test: frsevent
         * The File Replication Service Event log test
         ......................... GRELOTSERVER passed test frsevent
      Starting test: kccevent
         * The KCC Event log test
         Found no KCC errors in Directory Service Event log in the last 15 minutes.
         ......................... GRELOTSERVER passed test kccevent
      Starting test: systemlog
         * The System Event log test
         An Error Event occured.  EventID: 0xC000271A
            Time Generated: 03/02/2012   16:10:12
            (Event String could not be retrieved)
         An Error Event occured.  EventID: 0xC000271A
            Time Generated: 03/02/2012   16:10:42
            (Event String could not be retrieved)
         ......................... GRELOTSERVER failed test systemlog
      Test omitted by user request: VerifyReplicas
      Starting test: VerifyReferences
         The system object reference (serverReference)

         CN=GRELOTSERVER,OU=Domain Controllers,DC=grelotdental,DC=local and

         backlink on

         CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local

         are correct.
         The system object reference (frsComputerReferenceBL)

         CN=GRELOTSERVER,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=grelotdental,DC=local

         and backlink on

         CN=GRELOTSERVER,OU=Domain Controllers,DC=grelotdental,DC=local are

         correct.
         The system object reference (serverReferenceBL)

         CN=GRELOTSERVER,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=grelotdental,DC=local

         and backlink on

         CN=NTDS Settings,CN=GRELOTSERVER,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=grelotdental,DC=local

         are correct.
         ......................... GRELOTSERVER passed test VerifyReferences
      Test omitted by user request: VerifyEnterpriseReferences
      Test omitted by user request: CheckSecurityError
   
   Running partition tests on : ForestDnsZones
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
   
   Running partition tests on : DomainDnsZones
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
   
   Running partition tests on : Schema
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
   
   Running partition tests on : Configuration
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
   
   Running partition tests on : grelotdental
      Starting test: CrossRefValidation
         ......................... grelotdental passed test CrossRefValidation
      Starting test: CheckSDRefDom
         ......................... grelotdental passed test CheckSDRefDom
   
   Running enterprise tests on : grelotdental.local
      Starting test: Intersite
         Skipping site Default-First-Site-Name, this site is outside the scope

         provided by the command line arguments provided.
         ......................... grelotdental.local passed test Intersite
      Starting test: FsmoCheck
         GC Name: \\grelotserver
         Locator Flags: 0xe00003fd
         PDC Name: \\grelotserver
         Locator Flags: 0xe00003fd
         Time Server Name: \\grelotserver
         Locator Flags: 0xe00003fd
         Preferred Time Server Name: \\grelotserver
         Locator Flags: 0xe00003fd
         KDC Name: \\grelotserver
         Locator Flags: 0xe00003fd
         ......................... grelotdental.local passed test FsmoCheck
      Test omitted by user request: DNS
      Test omitted by user request: DNS
Is your 2008 Server only pointing to Windows 2003 Server for DNS in the TCP\IP properties?

Post ipconfig /all from both servers
Make sure you have proper DNS suffix listed on both servers
Check DNS & PTR Entry is created properly or not for this server
Avatar of RSI808

ASKER

The 2008 machine is pointing to the 2003 machine for DNS.
There are PTRs for both machines in DNS, as well as host records for both machines.
Zone transfers for DNS are working and Dynamic Updates are enabled.

DCpromo fails at the very end...but if I go to active directory users and comps on the 2008 machine--even though dcpromo doesnt complete--all of the active directory objects, users, comps are there.
It just wont allow promotion to DC.  Which prevents me from migrating over.
Please post ipconfig /all from both servers
Avatar of RSI808

ASKER

2008 machine:


Windows IP Configuration

   Host Name . . . . . . . . . . . . : GSERVER
   Primary Dns Suffix  . . . . . . . : grelotdental.local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : grelotdental.local

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . : grelotdental.local
   Description . . . . . . . . . . . : Intel(R) 82574L Gigabit Network Connection
   Physical Address. . . . . . . . . : 00-1E-67-25-C6-A4
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::509c:9fa9:fcbc:52ef%11(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.35(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.254
   DHCPv6 IAID . . . . . . . . . . . : 234888807
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-7E-5C-84-00-1E-67-25-C6-A4
   DNS Servers . . . . . . . . . . . : ::1
                                       192.168.1.9
                                       127.0.0.1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.grelotdental.local:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : grelotdental.local
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
------------------------------------------------------------------------------
2003 machine:



Windows IP Configuration



   Host Name . . . . . . . . . . . . : grelotserver

   Primary Dns Suffix  . . . . . . . :

   Node Type . . . . . . . . . . . . : Hybrid

   IP Routing Enabled. . . . . . . . : No

   WINS Proxy Enabled. . . . . . . . : No

   DNS Suffix Search List. . . . . . : grelotdental.local



Ethernet adapter Server Local Area Connection:



   Connection-specific DNS Suffix  . : grelotdental.local

   Description . . . . . . . . . . . : Intel(R) 82566DM-2 Gigabit Network Connection

   Physical Address. . . . . . . . . : 00-1C-C0-BD-FC-05

   DHCP Enabled. . . . . . . . . . . : No

   IP Address. . . . . . . . . . . . : 192.168.1.9

   Subnet Mask . . . . . . . . . . . : 255.255.255.0

   Default Gateway . . . . . . . . . : 192.168.1.254

   DNS Servers . . . . . . . . . . . : 192.168.1.9

   Primary WINS Server . . . . . . . : 192.168.1.9
You are missing primary DNS suffix on 2003 server.

Remove 127.0.0.1 you should have the actual IP address but for now don't have anything filled in
Avatar of RSI808

ASKER

i removed the loopback from the 2008 machine.

on the 2003 machine, under local area connection properties>DNS tab:

User generated image

i ran ipconfig /registerdns, but it still doesnt show up in ipconfig /all.
ASKER CERTIFIED SOLUTION
Avatar of Darius Ghassem
Darius Ghassem
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial