hi all,
I had to forcely remove a domain controller named DC2 (because it was considered as a tombstone)by stopping kdc service and then made a
clean up metadata(keep in mind that I isolated dc02 in temp site with site have a subnet with the same IP of dc02 but with mask 32 bit this isolation was in 28-9-2018)
then I create a new machine with the same name and ip address and make it an additional domain controller
then running dcdiag I got the following error
Starting test: KccEvent
A warning event occurred. EventID: 0x80000B46
Time Generated: 09/29/2018 22:09:31
Event String:
The security of this directory server can be significantly enhanced by configuring the server to reject SAS
L (Negotiate, Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that
are performed on a clear text (non-SSL/TLS-encrypted) connection. Even if no clients are using such binds, configuring the server to
reject them will improve the security of this server.
An error event occurred. EventID: 0xC000043C
Time Generated: 09/29/2018 22:10:03
Event String:
Internal event: Active Directory Domain Services could not update the following object with changes received from the following source directory service. This is because an error occurred during the application of the
changes to Active Directory Domain Services on the directory service.
An error event occurred. EventID: 0xC000083C
Time Generated: 09/29/2018 22:10:03
Event String:
This event contains REPAIR PROCEDURES for the 1084 event which has previously been logged. This message indicates a specific issue with the consistency of the Active Directory Domain Services database on this replication
destination. A database error occurred while applying replicated changes to the following object. The database had unexpected contents, preventing the change from being made.
......................... DC02 failed test KccEvent
the whole dcdiag
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = DC02
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\DC02
Starting test: Connectivity
......................... DC02 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC02
Starting test: Advertising
......................... DC02 passed test Advertising
Starting test: FrsEvent
......................... DC02 passed test FrsEvent
Starting test: DFSREvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... DC02 passed test DFSREvent
Starting test: SysVolCheck
......................... DC02 passed test SysVolCheck
Starting test: KccEvent
A warning event occurred. EventID: 0x80000B46
Time Generated: 09/29/2018 22:09:31
Event String:
The security of this directory server can be significantly enhanced by configuring the server to reject SAS
L (Negotiate, Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that
are performed on a clear text (non-SSL/TLS-encrypted) connection. Even if no clients are using such binds, configuring the server to
reject them will improve the security of this server.
An error event occurred. EventID: 0xC000043C
Time Generated: 09/29/2018 22:10:03
Event String:
Internal event: Active Directory Domain Services could not update the following object with changes received from the following source directory service. This is because an error occurred during the application of the
changes to Active Directory Domain Services on the directory service.
An error event occurred. EventID: 0xC000083C
Time Generated: 09/29/2018 22:10:03
Event String:
This event contains REPAIR PROCEDURES for the 1084 event which has previously been logged. This message indicates a specific issue with the consistency of the Active Directory Domain Services database on this replication
destination. A database error occurred while applying replicated changes to the following object. The database had unexpected contents, preventing the change from being made.
......................... DC02 failed test KccEvent
Starting test: KnowsOfRoleHolders
......................... DC02 passed test KnowsOfRoleHolders
Starting test: MachineAccount
......................... DC02 passed test MachineAccount
Starting test: NCSecDesc
......................... DC02 passed test NCSecDesc
Starting test: NetLogons
......................... DC02 passed test NetLogons
Starting test: ObjectsReplicated
......................... DC02 passed test ObjectsReplicated
Starting test: Replications
......................... DC02 passed test Replications
Starting test: RidManager
......................... DC02 passed test RidManager
Starting test: Services
......................... DC02 passed test Services
Starting test: SystemLog
A warning event occurred. EventID: 0xA004001B
Time Generated: 09/29/2018 21:23:53
EvtFormatMessage failed, error 15027 the message resource is present but the message is not found in the string/message table.
(Event String (event log = System) could not be retrieved, error
0x3ab3)
A warning event occurred. EventID: 0x00000083
Time Generated: 09/29/2018 21:23:54
Event String:
NtpClient was unable to set a domain peer to use as a time source because of DNS resolution error on 'DC01.mydomain.local'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error
was: No such host is known. (0x80072AF9).
A warning event occurred. EventID: 0xA004001B
Time Generated: 09/29/2018 21:33:55
EvtFormatMessage failed, error 15027 the message resource is present but the message is not found in the string/message table.
(Event String (event log = System) could not be retrieved, error
0x3ab3)
A warning event occurred. EventID: 0xA004001B
Time Generated: 09/29/2018 21:43:52
EvtFormatMessage failed, error 15027 the message resource is present but the message is not found in the string/message table.
(Event String (event log = System) could not be retrieved, error
0x3ab3)
A warning event occurred. EventID: 0xA004001B
Time Generated: 09/29/2018 21:53:55
EvtFormatMessage failed, error 15027 the message resource is present but the message is not found in the string/message table.
(Event String (event log = System) could not be retrieved, error
0x3ab3)
A warning event occurred. EventID: 0x000727A5
Time Generated: 09/29/2018 22:08:54
Event String:
The WinRM service is not listening for WS-Management requests.
A warning event occurred. EventID: 0x00001796
Time Generated: 09/29/2018 22:10:17
Event String:
Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.
......................... DC02 passed test SystemLog
Starting test: VerifyReferences
......................... DC02 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : mydomain
Starting test: CheckSDRefDom
......................... mydomain passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... mydomain passed test CrossRefValidation
Running enterprise tests on : mydomain.local
Starting test: LocatorCheck
......................... mydomain.local passed test LocatorCheck
Starting test: Intersite
......................... mydomain.local passed test Intersite