Solved

Can't add Windows AD users to local group on MySQL server

Posted on 2013-11-24
8
398 Views
Last Modified: 2013-12-03
This is a strange one.

I have an App server, a DNS server, and a DB server.  All are VMs.  I built the App server with a clean install of Windows Server 2008 R2 Datacenter Edition, plus all Windows Updates.  I did not join the server to a domain.  I also installed Symantec Endpoint Protection 12.  Windows Firewall was turned off.

I cloned the App server to create the DNS and DB servers.  Then I installed MySQL 5.6.10 on the DB server.  Everything worked perfectly.

Today I decided to join all three servers to a domain (acme.local).  The App and DNS servers are fine.  But the DB server is not communicating properly with the domain.  When I look in the local Administrators group, ACME\Domain Admins is not listed, as it is on the other two servers.

If I attempt to add Domain Admins, it takes a long time to retrieve the AD object.  And it displays as ACME\Domain Admins (S-1-5-21-332...).  And when I click Apply I see "Domain Admins" is already a member of the group "Administrators", and it disappears from the list.

I have three other sets of servers (App, DNS, and DB) that I have also joined to acme.local, with the same odd behavior on the MySQL DB server only.

This problem is preventing me from accessing the DB servers remotely using a domain account.  Any comments or suggestions are welcome.
0
Comment
Question by:LimeRidge29
  • 4
  • 4
8 Comments
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
Check what you have as DNS servers on your problem server. Normally when they just show the log GUIDs like that it is a DNS issue, or lack of correct DNS servers. I would match the primary and secondary DNS server entries on the problem server to match those of a working server.
0
 

Author Comment

by:LimeRidge29
Comment Utility
I have confirmed that the DNS settings are correct.  The two Domain Controllers are the DNS servers.  This matches the DNS settings on all of the other the known good servers.
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
Have you tried removing and rejoining that server to the domain?
0
 

Author Comment

by:LimeRidge29
Comment Utility
Yes, I removed and rejoined the domain.  Same issue.
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 30

Accepted Solution

by:
Gareth Gudger earned 400 total points
Comment Utility
When you cloned the server, did you sysprep it? Or in some way rewrite the SID?
0
 

Author Comment

by:LimeRidge29
Comment Utility
I did not run sysprep on any of the servers.  That could certainly explain the issue -- but why are only the MySQL servers affected?
0
 

Author Closing Comment

by:LimeRidge29
Comment Utility
Sysprep solved the domain issue.  But it caused the D drive to disappear.  It was in Disk Manager, but could not be enabled.  The VHD was blocked by Windows Firewall.  I got it back, as the E drive, and had to reassign drive letters.  So it all works now, thanks.
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
That's odd that happened but glad you got your data back. Rather than Sysprep, if you are cloning with VMware you can also tell it to write a new SID during the cloning process.
0

Featured Post

Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

Join & Write a Comment

Many admins will agree: WSUS is is a nice invention but using it on the client side when updating a newly installed computer is still time consuming as you have to do several reboots and furthermore, the procedure of installing updates, rebooting an…
Does the idea of dealing with bits scare or confuse you? Does it seem like a waste of time in an age where we all have terabytes of storage? If so, you're missing out on one of the core tools in every professional programmer's toolbox. Learn how to …
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now