Solved

Unable to install secondary domain controller

Posted on 2014-01-06
10
853 Views
Last Modified: 2014-03-04
Dear All,

Good Day,

I have a 2003 Enterprise Edt. 32bit server as my primary DC and want to install a 2008 r2 Enterprise 64bit server as a secondary DC with a child domain.

When I run dcpromo.exe and follow the steps up to where it wants me to name the new child domain and click next, I get this error: To install a domain controller into this Active Directory forest, you must first prepare the forest using "adprep /forestprep". The Adprep utility is available on the Windows Server 2008 R2 installation media in the \support\adprep folder.

and follow the below link:

http://www.petri.co.il/prepare-for-server-2008-r2-domain-controller.htm

then its gives me the below error, could you please help me how to solve this issue ( coz before i had a backup domain controller Win Server 2003  Enterprise Edt. 32bit but now its no more its not working and i don't have backup also)

Error Message:

I:\>\support\adprep\adprep32.exe /forestprep

ADPREP WARNING:

Before running adprep, all Windows 2000 Active Directory Domain Controllers in t
he forest should be upgraded to Windows 2000 Service Pack 4 (SP4) or later.

[User Action]
If ALL your existing Windows 2000 Active Directory Domain Controllers meet this
requirement, type C and then press ENTER to continue. Otherwise, type any other
key and press ENTER to quit.


c
Adprep was unable to extend the schema.
[Status/Consequence]
The schema master did not complete a replication cycle after the last reboot. Th
e schema master must complete at least one replication cycle before the schema c
an be extended.
[User Action]
Verify that the schema master is connected to the network and can communicate wi
th other Active Directory Domain Controllers.  Use the Sites and Services snap-i
n to replicate between the schema operations master and at least one replication
 partner. After replication has succeeded, run adprep again.

Please help me how to solve this issue.

Thanks
Kumar
0
Comment
Question by:Ram Kumar Chellam
  • 4
  • 2
  • 2
  • +2
10 Comments
 
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39759394
It appears based on your error message that you are having some replicaiton issues. I would start but making sure that replicaiton is working accordingly. Run the below commands...

- dcdiag /v
- repadmin /replsum
- repadmin /showrepl

Also checking the event viewer FRS (file replication services) and Directory Services logs to ensure there are no errors. Once you have confirmed that replicaiton is working accordingly login to the DC that is holding the schema master role and run the command again. Make sure that you have "schema admins" rights as well with the account you are logged in with.

Will.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39759405
Do you still have any 2000 pre SP4 DCs?  

Check the health of your DCs and replication using dcdiag and repadmin.  I'm guessing you ar gong to find some issues there.

Are you running the forestprep on the schema master?

Thanks

Mike
0
 

Author Comment

by:Ram Kumar Chellam
ID: 39759448
Dear Will,

Thanks for your commend.

Please check the below error message from event viewer FRS (file replication services)

Error:

The File Replication Service is having trouble enabling replication from BDC001(Backup Domain Controller) to PDC01(Primary Domain Controller) for c:\windows\sysvol\domain using the DNS name bdc001.domainName FRS will keep retrying.
 Following are some of the reasons you would see this warning.
 
 [1] FRS can not correctly resolve the DNS name bdc001.DomainName from this computer.
 [2] FRS is not running on bdc001.Domain Name.
 [3] The topology information in the Active Directory for this replica has not yet replicated to all the Domain Controllers.
 
 This event log message will appear once per connection, After the problem is fixed you will see another event log message indicating that the connection has been established.

As i said my Backup Domain Controller not working any more and don't have backup also.

Please let me know what to do.

Still i didn't run your comment what you mention in your reply.

Thanks
Kumar
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 18

Expert Comment

by:Jeremy Weisinger
ID: 39759719
Did you used to have another DC in the domain named bdc001.DomainName?

If so it seems that it wasn't removed properly.

Follow this to clean up AD of the old domain controller: http://www.petri.co.il/delete_failed_dcs_from_ad.htm
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39759774
Do the following...
- Make sure that all of the services are started accordingly (services.msc)
- If no connections are automatically made by the KCC in Sites and Services, create the connections manually from one DC to another (temporarily) until replicaiton has completed.
- Make sure that your DNS settings on the BDC are correct.
- Check in DNS Manager under the internal domain zone that the BDC is a Name server for that Zone
- Also check the _msdcs folder as well to ensure that your SRV records have been created sucessfully for the BDC (gc/kerberos/ldap/etc)

Once the above steps have been completed and verified re-run the tests again making sure you have no errors.

Create Manual Connection - http://technet.microsoft.com/en-us/library/cc784644(v=ws.10).aspx

Will.
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39769227
You must do metedata cleanup to remove the old orphaned DC's, then force replication to all the other active DCs.  Then you can extend the schema.

http://social.technet.microsoft.com/Forums/windowsserver/en-US/eb13c698-b4d0-40e9-8a48-4f8cf0cb4896/failed-or-expired-domain-controllers-how-to-remove-from-domain?forum=winserverDS

Mahesh
0
 

Author Comment

by:Ram Kumar Chellam
ID: 39820607
Thanks for your comments, sorry for the delay reply, was busy with one urgent project, let me try after on Monday then update you the result.
0
 

Author Comment

by:Ram Kumar Chellam
ID: 39867255
Thanks for all your comment, after long search and fight with my Backup Domain Controller now its online, but i can't Sync the AD between Primary Domain Controller and Backup Domain Controller, i getting the below Error message from PDC while try to run replicate now from AD Sites and Services.

Error:

the following error occurred during the attempt  to synchronize naming context Domain Name from domain controller PDC to Domain controller BDC:

The AD cannot replicate with this server because the time since the last replication with this server has exceeded the tombstone lifetime.

The operation will not continue.

when i try to run netdiag on Backup domain controller all passed except DNS Test:

DNS Error:

DNs Test…… : Failed

[WARNING] The DNS entries for this DC are not registered correctly on DNS server “Local IP”. Please wait 30min for DNS server replication.
[FATAL] No DNS server have the DNS records for this DC registered.

And when i try to run replicate now from AD Sites and Services on BDC:

The following Error occurred during the attempt to contact the domain controller BDC: The target principal name is incorrect.

Waiting for your reply to solve this issue and replicate the AD between PDC and BDC.

BR
Kumar
0
 
LVL 36

Accepted Solution

by:
Mahesh earned 250 total points
ID: 39867320
The  answer is remains same as my 1st comment
Check your active directory for stale DC accounts 1st

In addition to that you need to demote BDC gracefully with dcpromo command
If its not worked, you need to demote it forcefully with dcpromo /forceremoval
Also if any FSMO roles exists on BDC server that needs to be seized

Then you need to do cleanup metadata from active directory
Also you need to clear the BDC traces from DNS _msdcs folder, NS records in dns zone, domain system volume container under domain.com\system\file replication service

Once you done that, you can promote new DC and then extend the schema

Reference links:
Forcefull removal of DC:
http://support.microsoft.com/kb/332199 (2003)
http://technet.microsoft.com/en-us/library/cc731871(v=ws.10).aspx (2008)

Metadata cleanup:
http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Seize FSMO role:
http://www.petri.co.il/seizing_fsmo_roles.htm

Mahesh
0
 

Author Closing Comment

by:Ram Kumar Chellam
ID: 39905678
Thx
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 2012 PKI in a hybrid org 3 48
Replication dns zone issue 2 26
Application Crash 2 23
Old Active Directory sync to Azure 3 7
A procedure for exporting installed hotfix details of remote computers using powershell
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question