Solved

Active directory replication problem

Posted on 2014-03-07
8
41 Views
Last Modified: 2015-06-24
Hi

my PDC failed and i restored it from a backup (No BDC), once restore is completed, i see no replication takes place between my PDC and any of the child domains. from sites and services i receive the message saying :

the following error occurred during the attempt to synchronize naming context (child domain) to the domain controller ROOTPDC:
the naming context is in the process of being removed or is not replicated from the specific server.

this operation will not continue.

I have many child domains and it gives the same error for every single one of them. any idea why this happens or how to solve it?
0
Comment
Question by:hamed_masoud
8 Comments
 
LVL 21

Expert Comment

by:dan_blagut
ID: 39914311
Hello

This can be a transitive errors. If the error continue after 1 day is not good.
Anyway one DC rot the root domain wasn't an excellent ideea.

Dan
0
 

Author Comment

by:hamed_masoud
ID: 39914595
I read it in a site that this could be transitive, i waited for about a day but nothing happened. Actually there was a BDC to this PDC but even PDC and BDC in the central office could not replicate, i another site i read that if PDC and BDC could not replicate in the central site, child domains could not also replicate, and since i could not make these two domain controllers replicate, i had to demote the BDC hoping that not having BDC could make my child domains replicated and if so, i could make another BDC later. demoting PDC did not help at all. It all started when i restored the PDC from a backup and i could not login with the Enterprise admin account into the DC, my passwords and even my old password did not work, so I cracked the password and i managed to login, but now when i try to replicate it says access is denied, I also tried to change the password to the one i knew was correct to see if this is the password issue stopping the replication but still no success.
anyways, one question, lets imagine there has been no backup and PDC and BDC in the central office are both down to the metal, is there any way we can bring up a whole new domain controller and have child domains join to the new  parent?
Any luck?
0
 
LVL 26

Expert Comment

by:Leon Fester
ID: 39917522
updating...
0
Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

 
LVL 26

Expert Comment

by:Leon Fester
ID: 39917545
It all started when i restored the PDC from a backup and i could not login with the Enterprise admin account into the DC, my passwords and even my old password did not work, so I cracked the password and i managed to login, but now when i try to replicate it says access is denied, I also tried to change the password to the one i knew was correct to see if this is the password issue stopping the replication but still no success.

Considering that your current passwords were not working, this tells me that your backup was most likely an old backup.

If making any DC authoritative, the PDC Emulator as authoritative is preferable, since its SYSVOL contents are usually most up to date.

The use of the authoritative flag is only necessary if you need to force synchronization of all DCs. If only repairing one DC, simply make it non-authoritative and do not touch other servers.

http://support.microsoft.com/kb/2218556

In your case; your PDC had no peers to replicate from so it cannot retrieve the domain information from any other DC's.

Can't say that I've done this in parent-child domain as I've always had a 2nd DC in each domain, but you can try a non-authoritative restore on your PDC in the Parent site.

If that doesn't work then you'll need to run an authoritative restore as per the MS KB article.
0
 
LVL 27

Expert Comment

by:Steve
ID: 39920743
could you advise how old your backup was please?

If this was quite old, you will be unable to fix the issue due to limitations in Active Directory and the 'Tombstoning' effect.
Also, the parent AD will have effectively suffered a USN rollback, while the child domains haven't, meaning they are all out of sync.

If this is the case, there is no solution as your AD simply cannot get back in sync.

If the backup was very recent, we may be able to offer some help.

Let us know what events are being logged on the PDC, particularly AD/DNS ones.
0
 

Accepted Solution

by:
hamed_masoud earned 0 total points
ID: 40325916
thanks for the advise. the problem was resolved my re-establishing trust relationship between the DCs manually.
0
 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40848148
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Normally after a failure of Domain Controller, when promoting new DC the DC is renamed, we will discuss the options in Dcpromo to re-create the DC with the same name. Scenario: You are a small IT shop with two Domain Controllers (Domain Contr…
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now