ACSTLH
asked on
DCDiag error: LDAP Error 0x5e (94)
I have attached the DCDIAG report below: Â Should I be concerned about the error and how do I resolve it? Â I did not have this issue before raising the forest domain functional levels to 2102 R2. Â I cannot successfully revert back to 2008 R2. Â All other tests pass.
Directory Server Diagnosis
Performing initial setup:
  Trying to find home server...
  * Verifying that the local machine SAS-DC02, is a Directory Server.
  Home Server = SAS-DC02
  * Connecting to directory service on server SAS-DC02.
  * Identified AD Forest.
  Collecting AD specific global data
  * Collecting site info.
  Calling ldap_search_init_page(hld, CN=Sites,C N=Configur ation,DC=L CSAS,DC=lo cal,LDAP_S COPE_SUBTR EE,(object Category=n tDSSiteSet tings),... ....
  The previous call succeeded
  Iterating through the sites
  Looking at base site object: CN=NTDS Site Settings,CN=Default-First- Site-Name, CN=Sites,C N=Configur ation,DC=L CSAS,DC=lo cal
  Getting ISTG and options for the site
  * Identifying all servers.
  Calling ldap_search_init_page(hld, CN=Sites,C N=Configur ation,DC=L CSAS,DC=lo cal,LDAP_S COPE_SUBTR EE,(object Class=ntDS Dsa),..... ..
  The previous call succeeded....
  The previous call succeeded
  Iterating through the list of servers
  Getting information for the server CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
  objectGuid obtained
  InvocationID obtained
  dnsHostname obtained
  site info obtained
  All the info for the server collected
  Getting information for the server CN=NTDS Settings,CN=SAS-DC02,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
  objectGuid obtained
  InvocationID obtained
  dnsHostname obtained
  site info obtained
  All the info for the server collected
  * Identifying all NC cross-refs.
  * Found 2 DC(s). Testing 2 of them.
  Done gathering initial info.
Doing initial required tests
 Â
  Testing server: Default-First-Site-Name\SA S-DC01
   Starting test: Connectivity
     * Active Directory LDAP Services Check
     Determining IP4 connectivity
     * Active Directory RPC Services Check
     ......................... SAS-DC01 passed test Connectivity
 Â
  Testing server: Default-First-Site-Name\SA S-DC02
   Starting test: Connectivity
     * Active Directory LDAP Services Check
     Determining IP4 connectivity
     * Active Directory RPC Services Check
     ......................... SAS-DC02 passed test Connectivity
Doing primary tests
 Â
  Testing server: Default-First-Site-Name\SA S-DC01
   Starting test: Advertising
     The DC SAS-DC01 is advertising itself as a DC and having a DS.
     The DC SAS-DC01 is advertising as an LDAP server
     The DC SAS-DC01 is advertising as having a writeable directory
     The DC SAS-DC01 is advertising as a Key Distribution Center
     The DC SAS-DC01 is advertising as a time server
     The DS SAS-DC01 is advertising as a GC.
     ......................... SAS-DC01 passed test Advertising
   Starting test: CheckSecurityError
     * Dr Auth:  Beginning security errors check!
     Found KDC SAS-DC02 for domain LCSAS.local in site Default-First-Site-Name
     Checking machine account for DC SAS-DC01 on DC SAS-DC02.
     * SPN found :LDAP/SAS-DC01.LCSAS.local /LCSAS.loc al
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/SAS-DC01
     * SPN found :LDAP/SAS-DC01.LCSAS.local /LCSAS
     * SPN found :LDAP/ff139bb6-abf2-488f-9 a52-8bb1df eceb46._ms dcs.LCSAS. local
     * SPN found :E3514235-4B06-11D1-AB04-0 0C04FC2DCD 2/ff139bb6 -abf2-488f -9a52-8bb1 dfeceb46/L CSAS.local
     * SPN found :HOST/SAS-DC01.LCSAS.local /LCSAS.loc al
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :HOST/SAS-DC01
     * SPN found :HOST/SAS-DC01.LCSAS.local /LCSAS
     * SPN found :GC/SAS-DC01.LCSAS.local/L CSAS.local
     Checking for CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo cal in domain DC=LCSAS,DC=local on 2 servers
      Object is up-to-date on all servers.
     [SAS-DC01] No security related replication errors were found on this
     DC!  To target the connection to a specific source DC use
     /ReplSource:<DC>.
     ......................... SAS-DC01 passed test CheckSecurityError
   Starting test: CutoffServers
     * Configuration Topology Aliveness Check
     * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Schema,CN=Configuration ,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Configuration,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC01 passed test CutoffServers
   Starting test: FrsEvent
     * The File Replication Service Event log test
     ......................... SAS-DC01 passed test FrsEvent
   Starting test: DFSREvent
     The DFS Replication Event Log.
     Skip the test because the server is running FRS.
     ......................... SAS-DC01 passed test DFSREvent
   Starting test: SysVolCheck
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC01 passed test SysVolCheck
   Starting test: FrsSysVol
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC01 passed test FrsSysVol
   Starting test: KccEvent
     * The KCC Event log test
     Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
     ......................... SAS-DC01 passed test KccEvent
   Starting test: KnowsOfRoleHolders
     Role Schema Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role Domain Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role PDC Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role Rid Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role Infrastructure Update Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     ......................... SAS-DC01 passed test KnowsOfRoleHolders
   Starting test: MachineAccount
     Checking machine account for DC SAS-DC01 on DC SAS-DC01.
     * SPN found :LDAP/SAS-DC01.LCSAS.local /LCSAS.loc al
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/SAS-DC01
     * SPN found :LDAP/SAS-DC01.LCSAS.local /LCSAS
     * SPN found :LDAP/ff139bb6-abf2-488f-9 a52-8bb1df eceb46._ms dcs.LCSAS. local
     * SPN found :E3514235-4B06-11D1-AB04-0 0C04FC2DCD 2/ff139bb6 -abf2-488f -9a52-8bb1 dfeceb46/L CSAS.local
     * SPN found :HOST/SAS-DC01.LCSAS.local /LCSAS.loc al
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :HOST/SAS-DC01
     * SPN found :HOST/SAS-DC01.LCSAS.local /LCSAS
     * SPN found :GC/SAS-DC01.LCSAS.local/L CSAS.local
     ......................... SAS-DC01 passed test MachineAccount
   Starting test: NCSecDesc
     * Security Permissions check for all NC's on DC SAS-DC01.
     The forest is not ready for RODC. Will skip checking ERODC ACEs.
     * Security Permissions Check for
      DC=ForestDnsZones,DC=LCSAS ,DC=local
      (NDNC,Version 3)
     * Security Permissions Check for
      DC=DomainDnsZones,DC=LCSAS ,DC=local
      (NDNC,Version 3)
     * Security Permissions Check for
      CN=Schema,CN=Configuration ,DC=LCSAS, DC=local
      (Schema,Version 3)
     * Security Permissions Check for
      CN=Configuration,DC=LCSAS, DC=local
      (Configuration,Version 3)
     * Security Permissions Check for
      DC=LCSAS,DC=local
      (Domain,Version 3)
     ......................... SAS-DC01 passed test NCSecDesc
   Starting test: NetLogons
     * Network Logons Privileges Check
     Verified share \\SAS-DC01\netlogon
     Verified share \\SAS-DC01\sysvol
     ......................... SAS-DC01 passed test NetLogons
   Starting test: ObjectsReplicated
     SAS-DC01 is in domain DC=LCSAS,DC=local
     Checking for CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo cal in domain DC=LCSAS,DC=local on 2 servers
      Object is up-to-date on all servers.
     Checking for CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local in domain CN=Configuration,DC=LCSAS, DC=local on 2 servers
      Object is up-to-date on all servers.
     ......................... SAS-DC01 passed test ObjectsReplicated
   Starting test: OutboundSecureChannels
     * The Outbound Secure Channels test
     ** Did not run Outbound Secure Channels test because /testdomain: was
     not entered
     ......................... SAS-DC01 passed test OutboundSecureChannels
   Starting test: Replications
     * Replications Check
     * Replication Latency Check
      DC=ForestDnsZones,DC=LCSAS ,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=DomainDnsZones,DC=LCSAS ,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Schema,CN=Configuration ,DC=LCSAS, DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Configuration,DC=LCSAS, DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=LCSAS,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
     ......................... SAS-DC01 passed test Replications
   Starting test: RidManager
     * Available RID Pool for the Domain is 4604 to 1073741823
     * SAS-DC01.LCSAS.local is the RID Master
     * DsBind with RID Master was successful
     * rIDAllocationPool is 3604 to 4103
     * rIDPreviousAllocationPool is 3604 to 4103
     * rIDNextRID: 3702
     ......................... SAS-DC01 passed test RidManager
   Starting test: Services
     * Checking Service: EventSystem
     * Checking Service: RpcSs
     * Checking Service: NTDS
     * Checking Service: DnsCache
     * Checking Service: NtFrs
     * Checking Service: IsmServ
     * Checking Service: kdc
     * Checking Service: SamSs
     * Checking Service: LanmanServer
     * Checking Service: LanmanWorkstation
     * Checking Service: w32time
     * Checking Service: NETLOGON
     ......................... SAS-DC01 passed test Services
   Starting test: SystemLog
     * The System Event log test
     Found no errors in "System" Event log in the last 60 minutes.
     ......................... SAS-DC01 passed test SystemLog
   Starting test: Topology
     * Configuration Topology Integrity Check
     * Analyzing the connection topology for DC=ForestDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=DomainDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Schema,CN=Configuration ,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Configuration,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC01 passed test Topology
   Starting test: VerifyEnterpriseReferences
     LDAP Error 0x5e (94) - No result present in message.
     ......................... SAS-DC01 failed test
     VerifyEnterpriseReferences
   Starting test: VerifyReferences
     The system object reference (serverReference)
     CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo cal and backlink on
     CN=SAS-DC01,CN=Servers,CN= Default-Fi rst-Site-N ame,CN=Sit es,CN=Conf iguration, DC=LCSAS,D C=local
     are correct.
     The system object reference (serverReferenceBL)
     CN=SAS-DC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS ,DC=local
     and backlink on
     CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     are correct.
     The system object reference (frsComputerReferenceBL)
     CN=SAS-DC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS ,DC=local
     and backlink on CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo cal
     are correct.
     ......................... SAS-DC01 passed test VerifyReferences
   Starting test: VerifyReplicas
     ......................... SAS-DC01 passed test VerifyReplicas
 Â
  Testing server: Default-First-Site-Name\SA S-DC02
   Starting test: Advertising
     The DC SAS-DC02 is advertising itself as a DC and having a DS.
     The DC SAS-DC02 is advertising as an LDAP server
     The DC SAS-DC02 is advertising as having a writeable directory
     The DC SAS-DC02 is advertising as a Key Distribution Center
     The DC SAS-DC02 is advertising as a time server
     The DS SAS-DC02 is advertising as a GC.
     ......................... SAS-DC02 passed test Advertising
   Starting test: CheckSecurityError
     * Dr Auth:  Beginning security errors check!
     Found KDC SAS-DC02 for domain LCSAS.local in site Default-First-Site-Name
     Checking machine account for DC SAS-DC02 on DC SAS-DC02.
     * SPN found :LDAP/SAS-DC02.LCSAS.local /LCSAS.loc al
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/SAS-DC02
     * SPN found :LDAP/SAS-DC02.LCSAS.local /LCSAS
     * SPN found :LDAP/cfc883d6-0b96-421c-8 5b1-e3ef6d ca1098._ms dcs.LCSAS. local
     * SPN found :E3514235-4B06-11D1-AB04-0 0C04FC2DCD 2/cfc883d6 -0b96-421c -85b1-e3ef 6dca1098/L CSAS.local
     * SPN found :HOST/SAS-DC02.LCSAS.local /LCSAS.loc al
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :HOST/SAS-DC02
     * SPN found :HOST/SAS-DC02.LCSAS.local /LCSAS
     * SPN found :GC/SAS-DC02.LCSAS.local/L CSAS.local
     [SAS-DC02] No security related replication errors were found on this
     DC!  To target the connection to a specific source DC use
     /ReplSource:<DC>.
     ......................... SAS-DC02 passed test CheckSecurityError
   Starting test: CutoffServers
     * Configuration Topology Aliveness Check
     * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Schema,CN=Configuration ,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Configuration,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC02 passed test CutoffServers
   Starting test: FrsEvent
     * The File Replication Service Event log test
     ......................... SAS-DC02 passed test FrsEvent
   Starting test: DFSREvent
     The DFS Replication Event Log.
     Skip the test because the server is running FRS.
     ......................... SAS-DC02 passed test DFSREvent
   Starting test: SysVolCheck
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC02 passed test SysVolCheck
   Starting test: FrsSysVol
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC02 passed test FrsSysVol
   Starting test: KccEvent
     * The KCC Event log test
     Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
     ......................... SAS-DC02 passed test KccEvent
   Starting test: KnowsOfRoleHolders
     Role Schema Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role Domain Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role PDC Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role Rid Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     Role Infrastructure Update Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     ......................... SAS-DC02 passed test KnowsOfRoleHolders
   Starting test: MachineAccount
     Checking machine account for DC SAS-DC02 on DC SAS-DC02.
     * SPN found :LDAP/SAS-DC02.LCSAS.local /LCSAS.loc al
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/SAS-DC02
     * SPN found :LDAP/SAS-DC02.LCSAS.local /LCSAS
     * SPN found :LDAP/cfc883d6-0b96-421c-8 5b1-e3ef6d ca1098._ms dcs.LCSAS. local
     * SPN found :E3514235-4B06-11D1-AB04-0 0C04FC2DCD 2/cfc883d6 -0b96-421c -85b1-e3ef 6dca1098/L CSAS.local
     * SPN found :HOST/SAS-DC02.LCSAS.local /LCSAS.loc al
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :HOST/SAS-DC02
     * SPN found :HOST/SAS-DC02.LCSAS.local /LCSAS
     * SPN found :GC/SAS-DC02.LCSAS.local/L CSAS.local
     ......................... SAS-DC02 passed test MachineAccount
   Starting test: NCSecDesc
     * Security Permissions check for all NC's on DC SAS-DC02.
     The forest is not ready for RODC. Will skip checking ERODC ACEs.
     * Security Permissions Check for
      DC=ForestDnsZones,DC=LCSAS ,DC=local
      (NDNC,Version 3)
     * Security Permissions Check for
      DC=DomainDnsZones,DC=LCSAS ,DC=local
      (NDNC,Version 3)
     * Security Permissions Check for
      CN=Schema,CN=Configuration ,DC=LCSAS, DC=local
      (Schema,Version 3)
     * Security Permissions Check for
      CN=Configuration,DC=LCSAS, DC=local
      (Configuration,Version 3)
     * Security Permissions Check for
      DC=LCSAS,DC=local
      (Domain,Version 3)
     ......................... SAS-DC02 passed test NCSecDesc
   Starting test: NetLogons
     * Network Logons Privileges Check
     Verified share \\SAS-DC02\netlogon
     Verified share \\SAS-DC02\sysvol
     ......................... SAS-DC02 passed test NetLogons
   Starting test: ObjectsReplicated
     SAS-DC02 is in domain DC=LCSAS,DC=local
     Checking for CN=SAS-DC02,OU=Domain Controllers,DC=LCSAS,DC=lo cal in domain DC=LCSAS,DC=local on 2 servers
      Object is up-to-date on all servers.
     Checking for CN=NTDS Settings,CN=SAS-DC02,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local in domain CN=Configuration,DC=LCSAS, DC=local on 2 servers
      Object is up-to-date on all servers.
     ......................... SAS-DC02 passed test ObjectsReplicated
   Starting test: OutboundSecureChannels
     * The Outbound Secure Channels test
     ** Did not run Outbound Secure Channels test because /testdomain: was
     not entered
     ......................... SAS-DC02 passed test OutboundSecureChannels
   Starting test: Replications
     * Replications Check
     * Replication Latency Check
      DC=ForestDnsZones,DC=LCSAS ,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=DomainDnsZones,DC=LCSAS ,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Schema,CN=Configuration ,DC=LCSAS, DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Configuration,DC=LCSAS, DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=LCSAS,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
     ......................... SAS-DC02 passed test Replications
   Starting test: RidManager
     * Available RID Pool for the Domain is 4604 to 1073741823
     * SAS-DC01.LCSAS.local is the RID Master
     * DsBind with RID Master was successful
     * rIDAllocationPool is 4104 to 4603
     * rIDPreviousAllocationPool is 4104 to 4603
     * rIDNextRID: 4104
     ......................... SAS-DC02 passed test RidManager
   Starting test: Services
     * Checking Service: EventSystem
     * Checking Service: RpcSs
     * Checking Service: NTDS
     * Checking Service: DnsCache
     * Checking Service: NtFrs
     * Checking Service: IsmServ
     * Checking Service: kdc
     * Checking Service: SamSs
     * Checking Service: LanmanServer
     * Checking Service: LanmanWorkstation
     * Checking Service: w32time
     * Checking Service: NETLOGON
     ......................... SAS-DC02 passed test Services
   Starting test: SystemLog
     * The System Event log test
     Found no errors in "System" Event log in the last 60 minutes.
     ......................... SAS-DC02 passed test SystemLog
   Starting test: Topology
     * Configuration Topology Integrity Check
     * Analyzing the connection topology for DC=ForestDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=DomainDnsZones,DC=LCSAS ,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Schema,CN=Configuration ,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Configuration,DC=LCSAS, DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC02 passed test Topology
   Starting test: VerifyEnterpriseReferences
     LDAP Error 0x5e (94) - No result present in message.
     ......................... SAS-DC02 failed test
     VerifyEnterpriseReferences
   Starting test: VerifyReferences
     The system object reference (serverReference)
     CN=SAS-DC02,OU=Domain Controllers,DC=LCSAS,DC=lo cal and backlink on
     CN=SAS-DC02,CN=Servers,CN= Default-Fi rst-Site-N ame,CN=Sit es,CN=Conf iguration, DC=LCSAS,D C=local
     are correct.
     The system object reference (serverReferenceBL)
     CN=SAS-DC02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS ,DC=local
     and backlink on
     CN=NTDS Settings,CN=SAS-DC02,CN=Se rvers,CN=D efault-Fir st-Site-Na me,CN=Site s,CN=Confi guration,D C=LCSAS,DC =local
     are correct.
     The system object reference (frsComputerReferenceBL)
     CN=SAS-DC02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS ,DC=local
     and backlink on CN=SAS-DC02,OU=Domain Controllers,DC=LCSAS,DC=lo cal
     are correct.
     ......................... SAS-DC02 passed test VerifyReferences
   Starting test: VerifyReplicas
     ......................... SAS-DC02 passed test VerifyReplicas
 Â
   Starting test: DNS
     Â
        Starting test: DNS
        Â
         DNS Tests are running and not hung. Please wait a few
         minutes...
         See DNS test in enterprise tests section for results
         ......................... SAS-DC02 passed test DNS
     See DNS test in enterprise tests section for results
     ......................... SAS-DC01 passed test DNS
 Â
  Running partition tests on : ForestDnsZones
   Starting test: CheckSDRefDom
     ......................... ForestDnsZones passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... ForestDnsZones passed test
     CrossRefValidation
 Â
  Running partition tests on : DomainDnsZones
   Starting test: CheckSDRefDom
     ......................... DomainDnsZones passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... DomainDnsZones passed test
     CrossRefValidation
 Â
  Running partition tests on : Schema
   Starting test: CheckSDRefDom
     ......................... Schema passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... Schema passed test CrossRefValidation
 Â
  Running partition tests on : Configuration
   Starting test: CheckSDRefDom
     ......................... Configuration passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... Configuration passed test CrossRefValidation
 Â
  Running partition tests on : LCSAS
   Starting test: CheckSDRefDom
     ......................... LCSAS passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... LCSAS passed test CrossRefValidation
 Â
  Running enterprise tests on : LCSAS.local
   Starting test: DNS
     Test results for domain controllers:
     Â
      DC: SAS-DC01.LCSAS.local
      Domain: LCSAS.local
     Â
        Â
        TEST: Authentication (Auth)
         Authentication test: Successfully completed
        Â
        TEST: Basic (Basc)
         The OS
         Microsoft Windows Server 2012 R2 Standard (Service Pack level: 0.0)
         is supported.
         NETLOGON service is running
         kdc service is running
         DNSCACHE service is running
         DNS service is running
         DC is a DNS server
         Network adapters information:
         Adapter [00000016] Hyper-V Virtual Ethernet Adapter:
           MAC address is F8:BC:12:4D:16:FA
           IP Address is static
           IP address: 10.57.0.5
           DNS servers:
            10.57.0.5 (sas-dc01.) [Valid]
            10.57.0.8 (sas-dc02.) [Valid]
            127.0.0.1 (sas-dc01.) [Valid]
         The A host record(s) for this DC was found
         The SOA record for the Active Directory zone was found
         The Active Directory zone on this DC/DNS server was found primary
         Root zone on this DC/DNS server was not found
        Â
        TEST: Forwarders/Root hints (Forw)
         Recursion is enabled
         Forwarders Information:
           10.250.169.60 (<name unavailable>) [Valid]
           10.250.169.61 (<name unavailable>) [Valid]
        Â
        TEST: Delegations (Del)
         Delegation information for the zone: LCSAS.local.
           Delegated domain name: _msdcs.LCSAS.local.
            DNS server: sas-dc01. IP:10.57.0.5 [Valid]
            DNS server: sas-dc02. IP:10.57.0.8 [Valid]
        Â
        TEST: Dynamic update (Dyn)
         Test record dcdiag-test-record added successfully in zone LCSAS.local
         Test record dcdiag-test-record deleted successfully in zone LCSAS.local
        Â
        TEST: Records registration (RReg)
         Network Adapter [00000016] Hyper-V Virtual Ethernet Adapter:
           Matching CNAME record found at DNS server 10.57.0.5:
           ff139bb6-abf2-488f-9a52-8b b1dfeceb46 ._msdcs.LC SAS.local
           Matching A record found at DNS server 10.57.0.5:
           SAS-DC01.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.434da1c0-e999-4 0e4-9db2-1 dbd7b5a60d 7.domains. _msdcs.LCS AS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.dc._msdcs.L CSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.dc._msdcs.LCSAS .local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. dc._msdcs. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.dc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.gc._msdcs.LCSAS .local
           Matching A record found at DNS server 10.57.0.5:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _gc._tcp.Default-First-Sit e-Name._si tes.LCSAS. local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.gc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.pdc._msdcs.LCSA S.local
           Matching CNAME record found at DNS server 10.57.0.8:
           ff139bb6-abf2-488f-9a52-8b b1dfeceb46 ._msdcs.LC SAS.local
           Matching A record found at DNS server 10.57.0.8:
           SAS-DC01.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.434da1c0-e999-4 0e4-9db2-1 dbd7b5a60d 7.domains. _msdcs.LCS AS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.dc._msdcs.L CSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.dc._msdcs.LCSAS .local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. dc._msdcs. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.dc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.gc._msdcs.LCSAS .local
           Matching A record found at DNS server 10.57.0.8:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _gc._tcp.Default-First-Sit e-Name._si tes.LCSAS. local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.gc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.pdc._msdcs.LCSA S.local
           Matching CNAME record found at DNS server 10.57.0.5:
           ff139bb6-abf2-488f-9a52-8b b1dfeceb46 ._msdcs.LC SAS.local
           Matching A record found at DNS server 10.57.0.5:
           SAS-DC01.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.434da1c0-e999-4 0e4-9db2-1 dbd7b5a60d 7.domains. _msdcs.LCS AS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.dc._msdcs.L CSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.dc._msdcs.LCSAS .local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. dc._msdcs. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.dc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.gc._msdcs.LCSAS .local
           Matching A record found at DNS server 10.57.0.5:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _gc._tcp.Default-First-Sit e-Name._si tes.LCSAS. local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.gc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.pdc._msdcs.LCSA S.local
    Â
     Â
      DC: SAS-DC02.LCSAS.local
      Domain: LCSAS.local
     Â
        Â
        TEST: Authentication (Auth)
         Authentication test: Successfully completed
        Â
        TEST: Basic (Basc)
         The OS
         Microsoft Windows Server 2012 R2 Standard (Service Pack level: 0.0)
         is supported.
         NETLOGON service is running
         kdc service is running
         DNSCACHE service is running
         DNS service is running
         DC is a DNS server
         Network adapters information:
         Adapter
         [00000010] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client):
        Â
           MAC address is A4:BA:DB:1A:20:96
           IP Address is static
           IP address: 10.57.0.8
           DNS servers:
            10.57.0.5 (sas-dc01.) [Valid]
            10.57.0.8 (sas-dc02.) [Valid]
            127.0.0.1 (sas-dc02.) [Valid]
         The A host record(s) for this DC was found
         The SOA record for the Active Directory zone was found
         The Active Directory zone on this DC/DNS server was found primary
         Root zone on this DC/DNS server was not found
        Â
        TEST: Forwarders/Root hints (Forw)
         Recursion is enabled
         Forwarders Information:
           10.250.169.60 (<name unavailable>) [Valid]
           10.250.169.61 (<name unavailable>) [Valid]
        Â
        TEST: Delegations (Del)
         Delegation information for the zone: LCSAS.local.
           Delegated domain name: _msdcs.LCSAS.local.
            DNS server: sas-dc01. IP:10.57.0.5 [Valid]
            DNS server: sas-dc02. IP:10.57.0.8 [Valid]
        Â
        TEST: Dynamic update (Dyn)
         Test record dcdiag-test-record added successfully in zone LCSAS.local
         Test record dcdiag-test-record deleted successfully in zone LCSAS.local
        Â
        TEST: Records registration (RReg)
         Network Adapter
         [00000010] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client):
        Â
           Matching CNAME record found at DNS server 10.57.0.5:
           cfc883d6-0b96-421c-85b1-e3 ef6dca1098 ._msdcs.LC SAS.local
           Matching A record found at DNS server 10.57.0.5:
           SAS-DC02.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.434da1c0-e999-4 0e4-9db2-1 dbd7b5a60d 7.domains. _msdcs.LCS AS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.dc._msdcs.L CSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.dc._msdcs.LCSAS .local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. dc._msdcs. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.dc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.gc._msdcs.LCSAS .local
           Matching A record found at DNS server 10.57.0.5:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _gc._tcp.Default-First-Sit e-Name._si tes.LCSAS. local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S ite-Name._ sites.gc._ msdcs.LCSA S.local
           Matching CNAME record found at DNS server 10.57.0.8:
           cfc883d6-0b96-421c-85b1-e3 ef6dca1098 ._msdcs.LC SAS.local
           Matching A record found at DNS server 10.57.0.8:
           SAS-DC02.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.434da1c0-e999-4 0e4-9db2-1 dbd7b5a60d 7.domains. _msdcs.LCS AS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.dc._msdcs.L CSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.dc._msdcs.LCSAS .local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. dc._msdcs. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.dc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.gc._msdcs.LCSAS .local
           Matching A record found at DNS server 10.57.0.8:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _gc._tcp.Default-First-Sit e-Name._si tes.LCSAS. local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.gc._ msdcs.LCSA S.local
           Matching CNAME record found at DNS server 10.57.0.8:
           cfc883d6-0b96-421c-85b1-e3 ef6dca1098 ._msdcs.LC SAS.local
           Matching A record found at DNS server 10.57.0.8:
           SAS-DC02.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.434da1c0-e999-4 0e4-9db2-1 dbd7b5a60d 7.domains. _msdcs.LCS AS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.dc._msdcs.L CSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.dc._msdcs.LCSAS .local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. dc._msdcs. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.dc._ msdcs.LCSA S.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir st-Site-Na me._sites. LCSAS.loca l
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.gc._msdcs.LCSAS .local
           Matching A record found at DNS server 10.57.0.8:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _gc._tcp.Default-First-Sit e-Name._si tes.LCSAS. local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S ite-Name._ sites.gc._ msdcs.LCSA S.local
    Â
     Summary of test results for DNS servers used by the above domain
     controllers:
    Â
      DNS server: 10.250.169.60 (<name unavailable>)
        All tests passed on this DNS server
       Â
      DNS server: 10.250.169.61 (<name unavailable>)
        All tests passed on this DNS server
       Â
      DNS server: 10.57.0.5 (sas-dc01.)
        All tests passed on this DNS server
        Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered
        DNS delegation for the domain  _msdcs.LCSAS.local. is operational on IP 10.57.0.5
       Â
      DNS server: 10.57.0.8 (sas-dc02.)
        All tests passed on this DNS server
        Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered
        DNS delegation for the domain  _msdcs.LCSAS.local. is operational on IP 10.57.0.8
       Â
     Summary of DNS test results:
    Â
                      Auth Basc Forw Del  Dyn  RReg Ext
      __________________________ __________ __________ __________ _________
      Domain: LCSAS.local
        SAS-DC01           PASS PASS PASS PASS PASS PASS n/a Â
        SAS-DC02           PASS PASS PASS PASS PASS PASS n/a Â
    Â
     ......................... LCSAS.local passed test DNS
   Starting test: LocatorCheck
     GC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     PDC Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     Time Server Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     Preferred Time Server Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     KDC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     ......................... LCSAS.local passed test LocatorCheck
   Starting test: FsmoCheck
     GC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     PDC Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     Time Server Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     Preferred Time Server Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     KDC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     ......................... LCSAS.local passed test FsmoCheck
   Starting test: Intersite
     Skipping site Default-First-Site-Name, this site is outside the scope
     provided by the command line arguments provided.
     ......................... LCSAS.local passed test Intersite
Directory Server Diagnosis
Performing initial setup:
  Trying to find home server...
  * Verifying that the local machine SAS-DC02, is a Directory Server.
  Home Server = SAS-DC02
  * Connecting to directory service on server SAS-DC02.
  * Identified AD Forest.
  Collecting AD specific global data
  * Collecting site info.
  Calling ldap_search_init_page(hld,
  The previous call succeeded
  Iterating through the sites
  Looking at base site object: CN=NTDS Site Settings,CN=Default-First-
  Getting ISTG and options for the site
  * Identifying all servers.
  Calling ldap_search_init_page(hld,
  The previous call succeeded....
  The previous call succeeded
  Iterating through the list of servers
  Getting information for the server CN=NTDS Settings,CN=SAS-DC01,CN=Se
  objectGuid obtained
  InvocationID obtained
  dnsHostname obtained
  site info obtained
  All the info for the server collected
  Getting information for the server CN=NTDS Settings,CN=SAS-DC02,CN=Se
  objectGuid obtained
  InvocationID obtained
  dnsHostname obtained
  site info obtained
  All the info for the server collected
  * Identifying all NC cross-refs.
  * Found 2 DC(s). Testing 2 of them.
  Done gathering initial info.
Doing initial required tests
 Â
  Testing server: Default-First-Site-Name\SA
   Starting test: Connectivity
     * Active Directory LDAP Services Check
     Determining IP4 connectivity
     * Active Directory RPC Services Check
     ......................... SAS-DC01 passed test Connectivity
 Â
  Testing server: Default-First-Site-Name\SA
   Starting test: Connectivity
     * Active Directory LDAP Services Check
     Determining IP4 connectivity
     * Active Directory RPC Services Check
     ......................... SAS-DC02 passed test Connectivity
Doing primary tests
 Â
  Testing server: Default-First-Site-Name\SA
   Starting test: Advertising
     The DC SAS-DC01 is advertising itself as a DC and having a DS.
     The DC SAS-DC01 is advertising as an LDAP server
     The DC SAS-DC01 is advertising as having a writeable directory
     The DC SAS-DC01 is advertising as a Key Distribution Center
     The DC SAS-DC01 is advertising as a time server
     The DS SAS-DC01 is advertising as a GC.
     ......................... SAS-DC01 passed test Advertising
   Starting test: CheckSecurityError
     * Dr Auth:  Beginning security errors check!
     Found KDC SAS-DC02 for domain LCSAS.local in site Default-First-Site-Name
     Checking machine account for DC SAS-DC01 on DC SAS-DC02.
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/SAS-DC01
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/ff139bb6-abf2-488f-9
     * SPN found :E3514235-4B06-11D1-AB04-0
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :HOST/SAS-DC01
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :GC/SAS-DC01.LCSAS.local/L
     Checking for CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo
      Object is up-to-date on all servers.
     [SAS-DC01] No security related replication errors were found on this
     DC!  To target the connection to a specific source DC use
     /ReplSource:<DC>.
     ......................... SAS-DC01 passed test CheckSecurityError
   Starting test: CutoffServers
     * Configuration Topology Aliveness Check
     * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Schema,CN=Configuration
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Configuration,DC=LCSAS,
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC01 passed test CutoffServers
   Starting test: FrsEvent
     * The File Replication Service Event log test
     ......................... SAS-DC01 passed test FrsEvent
   Starting test: DFSREvent
     The DFS Replication Event Log.
     Skip the test because the server is running FRS.
     ......................... SAS-DC01 passed test DFSREvent
   Starting test: SysVolCheck
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC01 passed test SysVolCheck
   Starting test: FrsSysVol
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC01 passed test FrsSysVol
   Starting test: KccEvent
     * The KCC Event log test
     Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
     ......................... SAS-DC01 passed test KccEvent
   Starting test: KnowsOfRoleHolders
     Role Schema Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role Domain Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role PDC Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role Rid Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role Infrastructure Update Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     ......................... SAS-DC01 passed test KnowsOfRoleHolders
   Starting test: MachineAccount
     Checking machine account for DC SAS-DC01 on DC SAS-DC01.
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/SAS-DC01
     * SPN found :LDAP/SAS-DC01.LCSAS.local
     * SPN found :LDAP/ff139bb6-abf2-488f-9
     * SPN found :E3514235-4B06-11D1-AB04-0
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :HOST/SAS-DC01
     * SPN found :HOST/SAS-DC01.LCSAS.local
     * SPN found :GC/SAS-DC01.LCSAS.local/L
     ......................... SAS-DC01 passed test MachineAccount
   Starting test: NCSecDesc
     * Security Permissions check for all NC's on DC SAS-DC01.
     The forest is not ready for RODC. Will skip checking ERODC ACEs.
     * Security Permissions Check for
      DC=ForestDnsZones,DC=LCSAS
      (NDNC,Version 3)
     * Security Permissions Check for
      DC=DomainDnsZones,DC=LCSAS
      (NDNC,Version 3)
     * Security Permissions Check for
      CN=Schema,CN=Configuration
      (Schema,Version 3)
     * Security Permissions Check for
      CN=Configuration,DC=LCSAS,
      (Configuration,Version 3)
     * Security Permissions Check for
      DC=LCSAS,DC=local
      (Domain,Version 3)
     ......................... SAS-DC01 passed test NCSecDesc
   Starting test: NetLogons
     * Network Logons Privileges Check
     Verified share \\SAS-DC01\netlogon
     Verified share \\SAS-DC01\sysvol
     ......................... SAS-DC01 passed test NetLogons
   Starting test: ObjectsReplicated
     SAS-DC01 is in domain DC=LCSAS,DC=local
     Checking for CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo
      Object is up-to-date on all servers.
     Checking for CN=NTDS Settings,CN=SAS-DC01,CN=Se
      Object is up-to-date on all servers.
     ......................... SAS-DC01 passed test ObjectsReplicated
   Starting test: OutboundSecureChannels
     * The Outbound Secure Channels test
     ** Did not run Outbound Secure Channels test because /testdomain: was
     not entered
     ......................... SAS-DC01 passed test OutboundSecureChannels
   Starting test: Replications
     * Replications Check
     * Replication Latency Check
      DC=ForestDnsZones,DC=LCSAS
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=DomainDnsZones,DC=LCSAS
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Schema,CN=Configuration
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Configuration,DC=LCSAS,
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=LCSAS,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
     ......................... SAS-DC01 passed test Replications
   Starting test: RidManager
     * Available RID Pool for the Domain is 4604 to 1073741823
     * SAS-DC01.LCSAS.local is the RID Master
     * DsBind with RID Master was successful
     * rIDAllocationPool is 3604 to 4103
     * rIDPreviousAllocationPool is 3604 to 4103
     * rIDNextRID: 3702
     ......................... SAS-DC01 passed test RidManager
   Starting test: Services
     * Checking Service: EventSystem
     * Checking Service: RpcSs
     * Checking Service: NTDS
     * Checking Service: DnsCache
     * Checking Service: NtFrs
     * Checking Service: IsmServ
     * Checking Service: kdc
     * Checking Service: SamSs
     * Checking Service: LanmanServer
     * Checking Service: LanmanWorkstation
     * Checking Service: w32time
     * Checking Service: NETLOGON
     ......................... SAS-DC01 passed test Services
   Starting test: SystemLog
     * The System Event log test
     Found no errors in "System" Event log in the last 60 minutes.
     ......................... SAS-DC01 passed test SystemLog
   Starting test: Topology
     * Configuration Topology Integrity Check
     * Analyzing the connection topology for DC=ForestDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=DomainDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Schema,CN=Configuration
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Configuration,DC=LCSAS,
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC01 passed test Topology
   Starting test: VerifyEnterpriseReferences
     LDAP Error 0x5e (94) - No result present in message.
     ......................... SAS-DC01 failed test
     VerifyEnterpriseReferences
   Starting test: VerifyReferences
     The system object reference (serverReference)
     CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo
     CN=SAS-DC01,CN=Servers,CN=
     are correct.
     The system object reference (serverReferenceBL)
     CN=SAS-DC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS
     and backlink on
     CN=NTDS Settings,CN=SAS-DC01,CN=Se
     are correct.
     The system object reference (frsComputerReferenceBL)
     CN=SAS-DC01,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS
     and backlink on CN=SAS-DC01,OU=Domain Controllers,DC=LCSAS,DC=lo
     are correct.
     ......................... SAS-DC01 passed test VerifyReferences
   Starting test: VerifyReplicas
     ......................... SAS-DC01 passed test VerifyReplicas
 Â
  Testing server: Default-First-Site-Name\SA
   Starting test: Advertising
     The DC SAS-DC02 is advertising itself as a DC and having a DS.
     The DC SAS-DC02 is advertising as an LDAP server
     The DC SAS-DC02 is advertising as having a writeable directory
     The DC SAS-DC02 is advertising as a Key Distribution Center
     The DC SAS-DC02 is advertising as a time server
     The DS SAS-DC02 is advertising as a GC.
     ......................... SAS-DC02 passed test Advertising
   Starting test: CheckSecurityError
     * Dr Auth:  Beginning security errors check!
     Found KDC SAS-DC02 for domain LCSAS.local in site Default-First-Site-Name
     Checking machine account for DC SAS-DC02 on DC SAS-DC02.
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/SAS-DC02
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/cfc883d6-0b96-421c-8
     * SPN found :E3514235-4B06-11D1-AB04-0
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :HOST/SAS-DC02
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :GC/SAS-DC02.LCSAS.local/L
     [SAS-DC02] No security related replication errors were found on this
     DC!  To target the connection to a specific source DC use
     /ReplSource:<DC>.
     ......................... SAS-DC02 passed test CheckSecurityError
   Starting test: CutoffServers
     * Configuration Topology Aliveness Check
     * Analyzing the alive system replication topology for DC=ForestDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=DomainDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Schema,CN=Configuration
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for CN=Configuration,DC=LCSAS,
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the alive system replication topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC02 passed test CutoffServers
   Starting test: FrsEvent
     * The File Replication Service Event log test
     ......................... SAS-DC02 passed test FrsEvent
   Starting test: DFSREvent
     The DFS Replication Event Log.
     Skip the test because the server is running FRS.
     ......................... SAS-DC02 passed test DFSREvent
   Starting test: SysVolCheck
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC02 passed test SysVolCheck
   Starting test: FrsSysVol
     * The File Replication Service SYSVOL ready test
     File Replication Service's SYSVOL is ready
     ......................... SAS-DC02 passed test FrsSysVol
   Starting test: KccEvent
     * The KCC Event log test
     Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
     ......................... SAS-DC02 passed test KccEvent
   Starting test: KnowsOfRoleHolders
     Role Schema Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role Domain Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role PDC Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role Rid Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     Role Infrastructure Update Owner = CN=NTDS Settings,CN=SAS-DC01,CN=Se
     ......................... SAS-DC02 passed test KnowsOfRoleHolders
   Starting test: MachineAccount
     Checking machine account for DC SAS-DC02 on DC SAS-DC02.
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/SAS-DC02
     * SPN found :LDAP/SAS-DC02.LCSAS.local
     * SPN found :LDAP/cfc883d6-0b96-421c-8
     * SPN found :E3514235-4B06-11D1-AB04-0
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :HOST/SAS-DC02
     * SPN found :HOST/SAS-DC02.LCSAS.local
     * SPN found :GC/SAS-DC02.LCSAS.local/L
     ......................... SAS-DC02 passed test MachineAccount
   Starting test: NCSecDesc
     * Security Permissions check for all NC's on DC SAS-DC02.
     The forest is not ready for RODC. Will skip checking ERODC ACEs.
     * Security Permissions Check for
      DC=ForestDnsZones,DC=LCSAS
      (NDNC,Version 3)
     * Security Permissions Check for
      DC=DomainDnsZones,DC=LCSAS
      (NDNC,Version 3)
     * Security Permissions Check for
      CN=Schema,CN=Configuration
      (Schema,Version 3)
     * Security Permissions Check for
      CN=Configuration,DC=LCSAS,
      (Configuration,Version 3)
     * Security Permissions Check for
      DC=LCSAS,DC=local
      (Domain,Version 3)
     ......................... SAS-DC02 passed test NCSecDesc
   Starting test: NetLogons
     * Network Logons Privileges Check
     Verified share \\SAS-DC02\netlogon
     Verified share \\SAS-DC02\sysvol
     ......................... SAS-DC02 passed test NetLogons
   Starting test: ObjectsReplicated
     SAS-DC02 is in domain DC=LCSAS,DC=local
     Checking for CN=SAS-DC02,OU=Domain Controllers,DC=LCSAS,DC=lo
      Object is up-to-date on all servers.
     Checking for CN=NTDS Settings,CN=SAS-DC02,CN=Se
      Object is up-to-date on all servers.
     ......................... SAS-DC02 passed test ObjectsReplicated
   Starting test: OutboundSecureChannels
     * The Outbound Secure Channels test
     ** Did not run Outbound Secure Channels test because /testdomain: was
     not entered
     ......................... SAS-DC02 passed test OutboundSecureChannels
   Starting test: Replications
     * Replications Check
     * Replication Latency Check
      DC=ForestDnsZones,DC=LCSAS
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=DomainDnsZones,DC=LCSAS
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Schema,CN=Configuration
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      CN=Configuration,DC=LCSAS,
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
      DC=LCSAS,DC=local
        Latency information for 4 entries in the vector were ignored.
         4 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC). Â
     ......................... SAS-DC02 passed test Replications
   Starting test: RidManager
     * Available RID Pool for the Domain is 4604 to 1073741823
     * SAS-DC01.LCSAS.local is the RID Master
     * DsBind with RID Master was successful
     * rIDAllocationPool is 4104 to 4603
     * rIDPreviousAllocationPool is 4104 to 4603
     * rIDNextRID: 4104
     ......................... SAS-DC02 passed test RidManager
   Starting test: Services
     * Checking Service: EventSystem
     * Checking Service: RpcSs
     * Checking Service: NTDS
     * Checking Service: DnsCache
     * Checking Service: NtFrs
     * Checking Service: IsmServ
     * Checking Service: kdc
     * Checking Service: SamSs
     * Checking Service: LanmanServer
     * Checking Service: LanmanWorkstation
     * Checking Service: w32time
     * Checking Service: NETLOGON
     ......................... SAS-DC02 passed test Services
   Starting test: SystemLog
     * The System Event log test
     Found no errors in "System" Event log in the last 60 minutes.
     ......................... SAS-DC02 passed test SystemLog
   Starting test: Topology
     * Configuration Topology Integrity Check
     * Analyzing the connection topology for DC=ForestDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=DomainDnsZones,DC=LCSAS
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Schema,CN=Configuration
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for CN=Configuration,DC=LCSAS,
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     * Analyzing the connection topology for DC=LCSAS,DC=local.
     * Performing upstream (of target) analysis.
     * Performing downstream (of target) analysis.
     ......................... SAS-DC02 passed test Topology
   Starting test: VerifyEnterpriseReferences
     LDAP Error 0x5e (94) - No result present in message.
     ......................... SAS-DC02 failed test
     VerifyEnterpriseReferences
   Starting test: VerifyReferences
     The system object reference (serverReference)
     CN=SAS-DC02,OU=Domain Controllers,DC=LCSAS,DC=lo
     CN=SAS-DC02,CN=Servers,CN=
     are correct.
     The system object reference (serverReferenceBL)
     CN=SAS-DC02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS
     and backlink on
     CN=NTDS Settings,CN=SAS-DC02,CN=Se
     are correct.
     The system object reference (frsComputerReferenceBL)
     CN=SAS-DC02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=LCSAS
     and backlink on CN=SAS-DC02,OU=Domain Controllers,DC=LCSAS,DC=lo
     are correct.
     ......................... SAS-DC02 passed test VerifyReferences
   Starting test: VerifyReplicas
     ......................... SAS-DC02 passed test VerifyReplicas
 Â
   Starting test: DNS
     Â
        Starting test: DNS
        Â
         DNS Tests are running and not hung. Please wait a few
         minutes...
         See DNS test in enterprise tests section for results
         ......................... SAS-DC02 passed test DNS
     See DNS test in enterprise tests section for results
     ......................... SAS-DC01 passed test DNS
 Â
  Running partition tests on : ForestDnsZones
   Starting test: CheckSDRefDom
     ......................... ForestDnsZones passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... ForestDnsZones passed test
     CrossRefValidation
 Â
  Running partition tests on : DomainDnsZones
   Starting test: CheckSDRefDom
     ......................... DomainDnsZones passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... DomainDnsZones passed test
     CrossRefValidation
 Â
  Running partition tests on : Schema
   Starting test: CheckSDRefDom
     ......................... Schema passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... Schema passed test CrossRefValidation
 Â
  Running partition tests on : Configuration
   Starting test: CheckSDRefDom
     ......................... Configuration passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... Configuration passed test CrossRefValidation
 Â
  Running partition tests on : LCSAS
   Starting test: CheckSDRefDom
     ......................... LCSAS passed test CheckSDRefDom
   Starting test: CrossRefValidation
     ......................... LCSAS passed test CrossRefValidation
 Â
  Running enterprise tests on : LCSAS.local
   Starting test: DNS
     Test results for domain controllers:
     Â
      DC: SAS-DC01.LCSAS.local
      Domain: LCSAS.local
     Â
        Â
        TEST: Authentication (Auth)
         Authentication test: Successfully completed
        Â
        TEST: Basic (Basc)
         The OS
         Microsoft Windows Server 2012 R2 Standard (Service Pack level: 0.0)
         is supported.
         NETLOGON service is running
         kdc service is running
         DNSCACHE service is running
         DNS service is running
         DC is a DNS server
         Network adapters information:
         Adapter [00000016] Hyper-V Virtual Ethernet Adapter:
           MAC address is F8:BC:12:4D:16:FA
           IP Address is static
           IP address: 10.57.0.5
           DNS servers:
            10.57.0.5 (sas-dc01.) [Valid]
            10.57.0.8 (sas-dc02.) [Valid]
            127.0.0.1 (sas-dc01.) [Valid]
         The A host record(s) for this DC was found
         The SOA record for the Active Directory zone was found
         The Active Directory zone on this DC/DNS server was found primary
         Root zone on this DC/DNS server was not found
        Â
        TEST: Forwarders/Root hints (Forw)
         Recursion is enabled
         Forwarders Information:
           10.250.169.60 (<name unavailable>) [Valid]
           10.250.169.61 (<name unavailable>) [Valid]
        Â
        TEST: Delegations (Del)
         Delegation information for the zone: LCSAS.local.
           Delegated domain name: _msdcs.LCSAS.local.
            DNS server: sas-dc01. IP:10.57.0.5 [Valid]
            DNS server: sas-dc02. IP:10.57.0.8 [Valid]
        Â
        TEST: Dynamic update (Dyn)
         Test record dcdiag-test-record added successfully in zone LCSAS.local
         Test record dcdiag-test-record deleted successfully in zone LCSAS.local
        Â
        TEST: Records registration (RReg)
         Network Adapter [00000016] Hyper-V Virtual Ethernet Adapter:
           Matching CNAME record found at DNS server 10.57.0.5:
           ff139bb6-abf2-488f-9a52-8b
           Matching A record found at DNS server 10.57.0.5:
           SAS-DC01.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.434da1c0-e999-4
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.dc._msdcs.L
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.dc._msdcs.LCSAS
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.gc._msdcs.LCSAS
           Matching A record found at DNS server 10.57.0.5:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _gc._tcp.Default-First-Sit
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.pdc._msdcs.LCSA
           Matching CNAME record found at DNS server 10.57.0.8:
           ff139bb6-abf2-488f-9a52-8b
           Matching A record found at DNS server 10.57.0.8:
           SAS-DC01.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.434da1c0-e999-4
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.dc._msdcs.L
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.dc._msdcs.LCSAS
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.gc._msdcs.LCSAS
           Matching A record found at DNS server 10.57.0.8:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _gc._tcp.Default-First-Sit
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.pdc._msdcs.LCSA
           Matching CNAME record found at DNS server 10.57.0.5:
           ff139bb6-abf2-488f-9a52-8b
           Matching A record found at DNS server 10.57.0.5:
           SAS-DC01.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.434da1c0-e999-4
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.dc._msdcs.L
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.dc._msdcs.LCSAS
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.gc._msdcs.LCSAS
           Matching A record found at DNS server 10.57.0.5:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _gc._tcp.Default-First-Sit
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.pdc._msdcs.LCSA
    Â
     Â
      DC: SAS-DC02.LCSAS.local
      Domain: LCSAS.local
     Â
        Â
        TEST: Authentication (Auth)
         Authentication test: Successfully completed
        Â
        TEST: Basic (Basc)
         The OS
         Microsoft Windows Server 2012 R2 Standard (Service Pack level: 0.0)
         is supported.
         NETLOGON service is running
         kdc service is running
         DNSCACHE service is running
         DNS service is running
         DC is a DNS server
         Network adapters information:
         Adapter
         [00000010] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client):
        Â
           MAC address is A4:BA:DB:1A:20:96
           IP Address is static
           IP address: 10.57.0.8
           DNS servers:
            10.57.0.5 (sas-dc01.) [Valid]
            10.57.0.8 (sas-dc02.) [Valid]
            127.0.0.1 (sas-dc02.) [Valid]
         The A host record(s) for this DC was found
         The SOA record for the Active Directory zone was found
         The Active Directory zone on this DC/DNS server was found primary
         Root zone on this DC/DNS server was not found
        Â
        TEST: Forwarders/Root hints (Forw)
         Recursion is enabled
         Forwarders Information:
           10.250.169.60 (<name unavailable>) [Valid]
           10.250.169.61 (<name unavailable>) [Valid]
        Â
        TEST: Delegations (Del)
         Delegation information for the zone: LCSAS.local.
           Delegated domain name: _msdcs.LCSAS.local.
            DNS server: sas-dc01. IP:10.57.0.5 [Valid]
            DNS server: sas-dc02. IP:10.57.0.8 [Valid]
        Â
        TEST: Dynamic update (Dyn)
         Test record dcdiag-test-record added successfully in zone LCSAS.local
         Test record dcdiag-test-record deleted successfully in zone LCSAS.local
        Â
        TEST: Records registration (RReg)
         Network Adapter
         [00000010] Broadcom BCM5709C NetXtreme II GigE (NDIS VBD Client):
        Â
           Matching CNAME record found at DNS server 10.57.0.5:
           cfc883d6-0b96-421c-85b1-e3
           Matching A record found at DNS server 10.57.0.5:
           SAS-DC02.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.434da1c0-e999-4
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.dc._msdcs.L
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.dc._msdcs.LCSAS
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.5:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.gc._msdcs.LCSAS
           Matching A record found at DNS server 10.57.0.5:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.5:
           _gc._tcp.Default-First-Sit
           Matching  SRV record found at DNS server 10.57.0.5:
           _ldap._tcp.Default-First-S
           Matching CNAME record found at DNS server 10.57.0.8:
           cfc883d6-0b96-421c-85b1-e3
           Matching A record found at DNS server 10.57.0.8:
           SAS-DC02.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.434da1c0-e999-4
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.dc._msdcs.L
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.dc._msdcs.LCSAS
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.gc._msdcs.LCSAS
           Matching A record found at DNS server 10.57.0.8:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _gc._tcp.Default-First-Sit
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching CNAME record found at DNS server 10.57.0.8:
           cfc883d6-0b96-421c-85b1-e3
           Matching A record found at DNS server 10.57.0.8:
           SAS-DC02.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.434da1c0-e999-4
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.dc._msdcs.L
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.dc._msdcs.LCSAS
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._udp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _kpasswd._tcp.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
           Matching  SRV record found at DNS server 10.57.0.8:
           _kerberos._tcp.Default-Fir
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.gc._msdcs.LCSAS
           Matching A record found at DNS server 10.57.0.8:
           gc._msdcs.LCSAS.local
           Matching  SRV record found at DNS server 10.57.0.8:
           _gc._tcp.Default-First-Sit
           Matching  SRV record found at DNS server 10.57.0.8:
           _ldap._tcp.Default-First-S
    Â
     Summary of test results for DNS servers used by the above domain
     controllers:
    Â
      DNS server: 10.250.169.60 (<name unavailable>)
        All tests passed on this DNS server
       Â
      DNS server: 10.250.169.61 (<name unavailable>)
        All tests passed on this DNS server
       Â
      DNS server: 10.57.0.5 (sas-dc01.)
        All tests passed on this DNS server
        Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered
        DNS delegation for the domain  _msdcs.LCSAS.local. is operational on IP 10.57.0.5
       Â
      DNS server: 10.57.0.8 (sas-dc02.)
        All tests passed on this DNS server
        Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered
        DNS delegation for the domain  _msdcs.LCSAS.local. is operational on IP 10.57.0.8
       Â
     Summary of DNS test results:
    Â
                      Auth Basc Forw Del  Dyn  RReg Ext
      __________________________
      Domain: LCSAS.local
        SAS-DC01           PASS PASS PASS PASS PASS PASS n/a Â
        SAS-DC02           PASS PASS PASS PASS PASS PASS n/a Â
    Â
     ......................... LCSAS.local passed test DNS
   Starting test: LocatorCheck
     GC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     PDC Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     Time Server Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     Preferred Time Server Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     KDC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     ......................... LCSAS.local passed test LocatorCheck
   Starting test: FsmoCheck
     GC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     PDC Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     Time Server Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     Preferred Time Server Name: \\SAS-DC01.LCSAS.local
     Locator Flags: 0xe000f3fd
     KDC Name: \\SAS-DC02.LCSAS.local
     Locator Flags: 0xe000f1fc
     ......................... LCSAS.local passed test FsmoCheck
   Starting test: Intersite
     Skipping site Default-First-Site-Name, this site is outside the scope
     provided by the command line arguments provided.
     ......................... LCSAS.local passed test Intersite
ASKER
Is that because Server 2008 R2 and up use DFS Replication Service to replicate data instead of NT FRS replication?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
http://support.microsoft.com/kb/2512643
-saige-