Solved

Can't restore Domain Controller, Shadow Copy expired

Posted on 2013-02-05
7
2,486 Views
Last Modified: 2013-03-28
Hi,

I'm trying to restore a Win Svr 2003 standard SP1 system using Symantec BE 12.5. The server is a Domain Controller. I'm restoring all HD partitions + Shadow copy components and the System State. I am performing the restore in Windows Directory service restore mode as recommended. The restore completes successfully, but when I reboot the system I get:

 "lsass.exe - Security accounts manager initialization failed. Directory service cannot start. Error status 0xc0000Ze1. Reboot into directory service restore mode"

I am able to boot into Directory service restore mode ok, and in Event Viewer I think I've found the source of the problem:

Event Type: Error
Event Source: NTDS Replication
Event Category: Backup
Event ID: 1918
Description: The shadow copy service cannot restore Active Directory because the shadow copy used is too old.   Shadow copy expiration date: 2012-09-02 18:23:48

It's not vital that this server is recovered at this stage because it's a Disaster Recovery machine, but I need to find a way of preventing this happening at the restore point by extending the Shadow copy expiration date.. or any other means! Any help much appreciated.
0
Comment
Question by:fred2k3
7 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 38854630
Can you check the tombstone lifetime period of your forest?

http://technet.microsoft.com/en-us/library/cc784932(v=ws.10).aspx

You may have gone over that.  Is this an old DC.

Often times in times like these it is easier to rebuild (i.e. delete object/metadata cleanup/promote again)

The DS team had a good blurb on it   http://blogs.technet.com/b/askds/archive/2012/08/24/friday-i-mean-saturday-mail-sack-very-wordy-edition.aspx#rebuildrestore

Thanks

Mike
0
 

Author Comment

by:fred2k3
ID: 38856150
Thank you for the reply Mike.

The Tombstone Lifetime for the forest is set at 180. I'm struggling to make a connection as to why this would cause a problem restoring though.. objects must get deleted all the time and 180 days isn't much considering how many years this server has been running (DR tests in the past haven't exhibited this problem). I will look into the other suggestion.. thanks again.

Does anyone know anything about this Shadow Copy expiration? Google searches haven't proved fruitful for me so far.
0
 
LVL 9

Expert Comment

by:Zenvenky
ID: 38858252
You gave us wrong error code it is not 0xc0000Ze1 it is 0xc00002e1. Check the following links  to work on the issue. I believe that is why Mike didn't gave correct resolution. However check these links.

http://support.microsoft.com/kb/830574

http://support.microsoft.com/kb/258062

Note:-  KB258062 works on 2003STD aswell.
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:fred2k3
ID: 38860616
Ah, apologies for the confusion with that error code.

Zenvenky - thanks for the links.. I have tried that hotfix but it says my Service Pack is already more upto date. Neither article relates to Event ID: 1918 which I'm now positive is the cause of the issue.

Event ID: 1918
Description: The shadow copy service cannot restore Active Directory because the shadow copy used is too old.   Shadow copy expiration date: 2012-09-02 18:23:48

If I boot into Directory service restore mode and change the system clock to before this date I don't get the lsass.exe error (I do get a Windows activation problem but that's a seperate issue) so it's definitely this shadow copy expiry causing the problem.
0
 

Expert Comment

by:TeamLogicIT-MissionViejo
ID: 39029939
Did you ever find a solution to your issue? I amhaving the same problem
0
 

Author Comment

by:fred2k3
ID: 39030190
Hi TeamLogicIT, the problem was that the backup tape was too old and therefore did not restore. Using a more recent tape solved the problem. Hope it helps.
0
 

Author Comment

by:fred2k3
ID: 39030194
I've requested that this question be closed as follows:

Accepted answer: 0 points for fred2k3's comment #a39030190

for the following reason:

No other answers were suitable.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Synchronize a new Active Directory domain with an existing Office 365 tenant
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question