Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

windows 2003-2008- domain controller rename = no domain

Posted on 2013-12-02
7
Medium Priority
?
67 Views
Last Modified: 2015-06-23
Hello,
Big problems here.

There was a 2003 domain controller 'server2009'.
Raised from 2000 to 2003 functionality level, adprep ecc.
Added dc1 on windows 2008 r2 with dcpromo.
functional
Added a RODC "dc2zentyal" (zentyal not windows, hence read only)

Demoted server2009, rebooted, renamed to oldserver2009 = no more 2003 dc with new name.

Domain was fine working on dc1.

Then we renamed dc1 to server2009, using netdom computername dc1.domain.local /add:server2009.domain.local

Tried a /makeprimary and remove. Both failed with reason: "" (no reason)

But the only rw domain controller now has hostname server2009. Unfortunately the domain does not work, netlogon does not start error 0000064.

Tried a dns clean up renaming any occurrance of dc1 to server2009

dcdiag /fix states still dc1, failed connection to dc1.


Currently no domain controller is reachable.

dc2zentyal had completed the replica but is now disconnected before it gets screwed up too.

So I have:
a non working dc1.
no backups of system states of a working dc1,
a rodc dc2zentyal,
a demoted and renamed server2003,
a bks ntbackup system state from one month ago (no important changes). should I remove DC1 new and restore system state on the old demoted dc so it comes back as a normal dc and start over? Would that work?

What can I do? And what was wrong in renaming the dc? Should I have had another extra dc as global master ecc?

Here there are no lab procedures and no test envirnoments unfortunately, just a situation to fix
0
Comment
Question by:Gcku
7 Comments
 
LVL 17

Expert Comment

by:Chris Millard
ID: 39691857
You probably should have run ADPREP to update the active directory schema to 2008 before removing the 2003 dc.

You could try seizing the operations master role on the 2008 dc:-

http://technet.microsoft.com/en-us/library/cc816779(v=ws.10).aspx
0
 

Author Comment

by:Gcku
ID: 39691889
i did run adprep or 2008 would not have become a dc
0
 

Accepted Solution

by:
Gcku earned 0 total points
ID: 39691958
Ok here is what I've done to fix the situation:
I used netdom computername dc1 to remove alias given: failed. using server2009 works though outputting an "" error.

Used the registry to force back the dc1 name.

Then I am creating a new server2009 trial server that will become another dc.
the new server2009 will be dc and file server. (with rdp and applications on another appserver). I will promote to global master ecc. Then replicate and remove dc1 gracefully (licensing allows me only two vritual servers) and keep the rodc on dc2zentyal

Ideal solution would have infact been having files on a server2009 server on an windows in domain server or even a linux samba nas, eg on zentyal. I am not accustomed to zentyal unfortunately
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 24

Expert Comment

by:Sandeshdubey
ID: 39692198
Have you remove the old dcname by netdom command after rename operation:http://technet.microsoft.com/en-us/library/cc738341(WS.10).aspx

You also need to ensure the health of DC is good before you proceed with other DC  promotion.Run dcdiag/q and repadmin /replsum to verify the same.It is not recommended to have file server role on DC but if you have budget issue then you have no choice.You can have file server as windows/linux.

I will also recommend to have two DC in network for redundancy.
0
 
LVL 9

Expert Comment

by:VirastaR
ID: 39692429
0
 
LVL 36

Expert Comment

by:Seth Simmons
ID: 40845807
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

[Webinar] Cloud and Mobile-First Strategy

Maybe you’ve fully adopted the cloud since the beginning. Or maybe you started with on-prem resources but are pursuing a “cloud and mobile first” strategy. Getting to that end state has its challenges. Discover how to build out a 100% cloud and mobile IT strategy in this webinar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question