Domain has bad or corrupt sysvol, missing IPv6 DNS in gc, no GUID in registry for NTFRS
Posted on 2016-08-28
Two DCs in the domain, both have sysvol corruption that I can't seem to fix.
For starters, sysvol in both had only the domain pointer, no polices or scripts subfolders. I wanted to repair them by changing the registry settings to do a non-authoritative restore in HKLM\system\current control set\serives\ntfrs\parameters\backup/restore\process at startup and change BurFlags to D2.
Imagine my surprise to see that the only thing in Ntfrs was Parameters and it was essentially empty. So I used a reference DC from another domain to rebuild it. But then I got stumped. I don't know where to find the GUID value fr the replica sets subfolders.
Undaunted, I figured restarting File Replication Service (Ntfrs). Much to my amazement, it was set to disabled on both DCs. So I changed to automatic, thinking I had solved the problem. Even more to my amazement, ntfrs will not start on either DC. I get an error 1053 service did not respond in a timely fashion. I bumped up the timeout value from 60000 to 100000 and still the same result.
Of course dcdiag craps out all over the place. In particular, there are lots of SChannel errors, and the event logs are full of them, too. I wasn't paying that much attention to them but could they be a conspirator in this? Dcdiag just failed with systemlog test with a bunch of SChannel errors trying to reach the remote endpoint, and then failed again waiting for file replication service. All other tests passed.
I mentioned in the title that any IPv6 AAAA records were absent in _msdcs zone for gc and pdc. I also checked to see that all FSMO roles were on one server (the original one in the domain), and they were. Just doesn't feel like a DNS issue though.
Now my questions I hope you can help me answer:
1. why won't ntfrs start on either DC? If it were to, that would hopefully rebuild the registry. Nothing in the event
2. why the Schannel errors, or more precisely, how do I fix them? Related to the other issues?
3. what in particular is keeping replication from working? FIrst server seems to have a correct sysvol, but not the second. If I create private and scripts folders, NETLOGON wipes them out.
One last detail. When I open DFS Manager and run a health report, the second DC (bad sysvol) shows as an error that the local path does not match the newly configured local path and a warning that the DC is awaiting initial replication of sysvol. Let's just say its been a long, long time before this came to my attention.