Quantcast
Channel: Directory Services forum
Viewing all 31638 articles
Browse latest View live

IPv6 on DCs

$
0
0

Hi,

I have Windows 2008 R2 RODCs on remote sites and IPv6 is disabled on the Server's TCP/IP properties.

from a client machine in one of the remote site when i ping the RODC by name it returns the IPv6 address and when i do nslookup for the same DC it shows IPv6 and IPv4 addresses registered for the RODC and IPv6 showing as primary address.

I am not able to access the RODC from the client machine.

Why would this happen?

Note: Recently we have deployed Direct Access in our environment and the servers are installed in the Hub site as part of the deployment there were some changes made on DNS server for ISATAP.

Please suggest.

Regards,

Maqsood


Maqsood Mohammed Senior Systems Engineer MCITP-Enterprise Admin & ITILv3 Foundation Certified


SSO tasks with FreeBSD

$
0
0

Good day! Allow question:

To set up SSO Freebsd be used as a gateway. Are there any recommendations for a gateway on FreeBSD primary their interaction with AD FS 2.0?

What requirements must be Fribsd for use as a gateway to the ADFS 2.0?

P.S. Sorry for my English

Active directory 2003 to Windows server 2012 migration with DHCP

$
0
0
We are Migrating Current Active directory 2003 to windows server 2012 with DHCP role.

We have successfully migrated AD and DNS role and transferred all FSMO roles to new Windows server 2012 server.

But we have issue with DHCP.

We have Export DHCP  settings from windows server 2003 and than import in windows server 2012 server. we have followed below steps for this.

on 2003 Domain controller
open cmd as a Administrator and run netsh dhcp server export c:\dhcp.txt all
copy dhcp.txt file to new domain controller windows server 2012
on 2012 Domain controller
open cmd as a Administrator and run netsh dhcp server import c:\dhcp.txt all

Authorized dhcp server on windows server 2012 and disable DHCP role in 2003 domain controller and trying to get lease from 2012 domain controller.

Lease can not be getting form new 2012 domain controller we have restarted service twice and checked event log and got below details

"The DHCP\BINL service on the local machine belonging to the windows administrative domain contoso.com has determine that authorized to start. it is servicing clients now."

Here I have attached screenshot for the DHCP

Kindly suggest....

Quick response highly appreciable.... DHCP

Branches Connectivity analyzing

$
0
0

Hi,

Anyone can tell me that is there any tool with that i can check connectivity from head office to all other branches. Mean they are connecting with head office or not. Please help me. I have to do all it manually by ping. 

Certificate Service "Disabled"

$
0
0

I'm trying to install AD Certificate Services on my Server 2012 machine which is also a domain controller.

The service installation completes successfully but I am not able to get the certsrv service to stop. In Services.msc, the service shows as "Disabled". When I set it to automatic and start it, I get an error message like so:

Windows could not start the Active Directory Certificate Services service on Local Computer.

Error 2: The system cannot find the file specified.

The event viewer has a log under "System" for this event as well, and it says this:

The Active Directory Certificate Services service terminated with the following error: The system cannot find the file specified.


Any ideas on how I can get to the bottom of this?


RADIUS stopped working

$
0
0

Hello,

My Server 2012 with NPS to authenticate clients for WiFi using RADIUS has started denying requests.

The logs show the last successful auth was on 26th of August.

The event log is full of events that say that the user was denied access because

"The client could not be authenticated  because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server."

From what I can see, the successful auth entries in thel og in the past were using the PEAP protocol. But the newer requests are using EAP.

To the best of my knowledge, nothing has changed on my access points configuration or on my server. Devices that worked fine now (smartphones, laptops etc) are now apaprently using the incorrect authentication protocol!

What could make the authentication protocol change in this way? Something in the access point perhaps that's advertising the incorrect protocol?

Infraestructure rol transfer error

$
0
0

I need help with a problem similar to the post "ForestDNSZones or DomainDNSZones FSMO says “The role owner attribute could not be read”" by Chris Davis in this forum.

I have a Windows 2003 domain with a single domain controller and I need to add a second domain controller with Windows 2008. The process does not work because the tool adprep32.exe / domainprep shows an error: "Win32 Error Encountered Adprep. Error code: 0x57 Error message: The parameter is incorrect .. "

Checking in domain I see some problems. When I check "Operation Master" in the application "Active Directory Users and Computers", in the Infrastructure tab where it should show the name of the server that has that role instead of saying the name says ERROR. When I try to transfer it to the current domain controller says that the account does not have sufficient privileges although it is the default domain administrator account.

DCDiag command displays an error in the test KnowsOfRoleHolders "Warning: Could not resolve the PDC name for role. Infrastructure Update Owner. The name was Not Found Error. "

Using the command "seize infrastructure owner" at the ntdsutil tool gives the error: "Attempting safe transfer of infrastructure FSMO before seizure. ldap_modify_sW Error 0x32 (50 (Insufficient Rights). Ldap extended error message is 00002098: SecErr: DSID-03151D7D, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0 Win32 Error returned is 0x2098 (Insufficient access rights to perform the operation.)) "

In the same window says that the domain controller has all the roles but says "Infrastructure role owner can not be found"

I would appreciate your help with this problem. 

Clients are contacting DCs in different sites?

$
0
0

Hello all,

Single domain and single forest with 8 sites across locations.

I have a problem in two of the locations that, clients are not contacting the location DCs and also not the dns entries specified in TCP- IP properties.

DNS Entries in Clients configured as.

Primary DNS - Site DC

Secondary DNS - Nearest site DC

Third pref DNS - HQ DC

And i have promoted a new DC in HQ very recently.

The problem is, according to the network team input, in that two of the locations, clients are contacting the newly promoted in DC in HQ. Which not specified in client DNS  entries either. 

Why this behavior? please help with your inputs.

In which scenario it will happen like this?


can't move the schema owner from the damaged server to the new one

$
0
0

Hello everyone,

I hope i can find way to fix this problem, i have environment windows server,and a critical damage happened to primary server "windows server 2008 r2" so i removed it from the network and now i have already DC02 working but i got some error in event viewer when i followed this error i found this so i found the schema owner still in the previous server, when i tried to transfer schema owner to the new server i got this

 so based on this problem i can't install exchange server.

is there any way to fix that?

many thanks for all

Windows serwer 2003

$
0
0

Will win 7/8 workstations work with windows serwer 2003 as a domain file serwer?

Please advise.

Windows 2012 Active Directory Migration Issue

$
0
0

Dear All,

I am managing a Windows 2008 R2 active directory domain having one corporate office Site and 5 branch Sites. We are in the process of upgrading our active directory to Windows 2012. I have 2 DCs in corp office and one DC each in branch offices, so making 7 DCs in total. I have successfully demoted one DC in corp office and 2 DCs in branch offices and deployed Windows 2012 DCs. I have 3 Windows 2012 DCs and reaming 4 Windows 2008 R2 DCs. I am facing a problem in one of the branch offices while migrating to Windows 2012. I have deployed Windows 2012 server there but I cannot access the Windows 2012 DC in the corp office using\\servername. Username and password screen is being displayed while accessing this DC. I have recreated the Windows 2012 server in the branch 3 times but still facing the same issue. I noticed this while promoting this 2012 server to DC and I got access denied error. Interestingly this server can access 6 other DCs except the first windows 2012 DC in corp office. I doubt 2 things. First something related to IPv6 as I cannot see IPv6 record for the corp Windows 2012 DC in DNS. Secondly there is no windows DHCP server in the branch offices but we have cisco DHCP server. So initially this windows 2012 server is being IP address assigned by cisco DHCP server. Please guide me how to fix this issue or we have some tool to troubleshoot this. One thing to add I tried to access with IP address of the corp windows 2012 DC but still getting the access denied error.

Thanks
Rajesh

trust relationship between workstation and the primary domain fail

$
0
0

I've got this problem from my member server : trust relationship between workstation and the primary domain fail

solved the problem by rejoining the problematic server, but I want to know why this is happening? And what are the preventive solution?


rgds, Krisna

Forest trust issue

$
0
0

I have created two different forest i.e. abc.com and xyz.com and established an external trust between both forest. now my question is what i need to configure so a user of abc.com can log-in on the computer which is attached to xyz.com.

note- external is working ok because i am able to validate it.

CHANGE DC TO ADC Using Windows power shell Remotely

$
0
0

Hi,

I am new to windows server, learning server 2012.  I installed server 2012 trail version on lenovo H330 Model desktop for practicing purpose . Lenovo H330 configuration is Core i5 processor, 8 GB ram and 1 Tb HDD, after some days it is updated i shutdown the system to shift the server place after starting it again screen goes black. I am not able to see anything on the screen, then i thought VGA adapter  is gone r monitor may gone. But i checked the system with other hdd which installed windows 7, it is working fine. I have adc also with server 2008 standard 32 - bit edition, now i want to make 2008 as DC, for that i want to transfer roles from DC but it Doesn't work because display of dc doesn't work. I can connect to DC via power shell remotely. So please help me how to transfer roles from 2012 to 2008 via power shell remotely connected from my laptop. Please help me

THANKING YOU.


Frequently i'm getting.. "the security database on the server does not have a computer account for this workstation trust relationship in windows 7" Pls.. suggest me on this

$
0
0

<cufon alt="Relationship" cufon-canvas" style="width:168px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;font-size:1px !important;line-height:1px !important;"><cufon alt="Solved: " cufon-canvas" style="width:112px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="The " cufon-canvas" style="width:61px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:99px;height:39px;top:-1px;left:-4px;" width="99"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Security " cufon-canvas" style="width:122px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:160px;height:39px;top:-1px;left:-4px;" width="160"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Database " cufon-canvas" style="width:140px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:177px;height:39px;top:-1px;left:-4px;" width="177"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="on " cufon-canvas" style="width:44px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:81px;height:39px;top:-1px;left:-4px;" width="81"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="the " cufon-canvas" style="width:52px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:90px;height:39px;top:-1px;left:-4px;" width="90"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Server " cufon-canvas" style="width:102px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:140px;height:39px;top:-1px;left:-4px;" width="140"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Does " cufon-canvas" style="width:80px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:118px;height:39px;top:-1px;left:-4px;" width="118"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Not " cufon-canvas" style="width:60px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:97px;height:39px;top:-1px;left:-4px;" width="97"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Have " cufon-canvas" style="width:82px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:120px;height:39px;top:-1px;left:-4px;" width="120"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="a " cufon-canvas" style="width:26px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:63px;height:39px;top:-1px;left:-4px;" width="63"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Computer " cufon-canvas" style="width:146px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:183px;height:39px;top:-1px;left:-4px;" width="183"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Account " cufon-canvas" style="width:122px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:160px;height:39px;top:-1px;left:-4px;" width="160"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="for " cufon-canvas" style="width:47px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:84px;height:39px;top:-1px;left:-4px;" width="84"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="This " cufon-canvas" style="width:66px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:103px;height:39px;top:-1px;left:-4px;" width="103"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Workstation " cufon-canvas" style="width:175px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:213px;height:39px;top:-1px;left:-4px;" width="213"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Trust " cufon-canvas" style="width:77px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:115px;height:39px;top:-1px;left:-4px;" width="115"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon><cufon alt="Relationship" cufon-canvas" style="width:168px;height:36px;display:inline-block !important; !important;vertical-align:middle !important;"><canvas height="39" style=" !important;width:197px;height:39px;top:-1px;left:-4px;" width="197"></canvas><cufontext style="display:inline-block !important;width:0px !important;height:0px !important;overflow:hidden !important;text-indent:-10000in !important;"></cufontext></cufon></cufon>



The Active Directory definition of this resource record is corrupt or contains an invalid DNS name. The event data contains the error.

$
0
0

Hi,

I keep getting the below event logged when a DC's Dns services are restarted.

The DNS server was unable to create a resource record for 899494f1-fac0-4405-8bf4-d3d2326d0449._msdcs.domain.local. in zone domain.local. The Active Directory definition of this resource record is corrupt or contains an invalid DNS name. The event data contains the error.

The server was demoted and promoted and the server received a new GUID but the server is still trying to register the 899494f1-fac0-4405-8bf4-d3d2326d0449._msdcs.domain.local entry. The entry does not exist in the domain.

I used the below article before we demoted the server and it however did not resolve the problem:

http://technet.microsoft.com/en-us/library/cc735667(v=ws.10).aspx

Does anyone have any ideas?

Thanks

Don


Kind Regards Don

Old DC is still primary FILE REPLICATION SERVICE member

$
0
0

Hi,

An old DC which was recently demoted running Server 2003 is still listed as the primary member of FRS when I run ntfrsutl ds.

The server that replaced it is running 2008 R2 which seems to be working fine. 

I'm trying to add an RODC to the domain which is going to live in our branch office but after running dcpromo a sysvol and netlogon is never created, in my search to try and fix this issue I ran into this FRS issue. Could this be what is causing my RODC issues?

I found the old server in ASDI edit under CN=FileReplicationService, I didn't want to delete it because its listed as the primary member.

I ran through the steps in KB article 216498 but the old-dc doesnt show up when you run list servers in site

Any help on fixing the below issue would be appreciated. 

SETTINGS: FILE REPLICATION SERVICE

   DN   : cn=file replication service,cn=system,dc=sub,dc=MyDomain,dc=com

   Guid : a02a87d5-c64c-4515-aedf5fd47fc211b5

   WhenCreated  : 9/19/2007 13:34:32 GMT Standard Time GMT Daylight Time [0]

   WhenChanged  : 8/13/2013 15:23:50 GMT Standard Time GMT Daylight Time [0]

   SET: DOMAIN SYSTEM VOLUME (SYSVOL SHARE)

      DN   : cn=domain system volume (sysvol share),cn=file replication service,cn=system,dc=sub,dc=MyDomain,dc=com

      Guid : 7ee172a2-5881-4047-b02dd3d58e241c3d

      Type          : 2

      Primary Member: CN= OLD-DC-2003,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=sub,DC=MyDomain,DC=com

      File Filter   : *.tmp, *.bak, ~*

      Dir  Filter   : (null)

      FRS Flags     : (null)

      WhenCreated  : 9/19/2007 13:41:33 GMT Standard Time GMT Daylight Time [0]

      WhenChanged  : 8/13/2013 15:25:0 GMT Standard Time GMT Daylight Time [0]

      MEMBER: RODC-BRANCH-DC

         DN   : cn=RODC-BRANCH-DC,cn=domain system volume (sysvol share),cn=file replication service,cn=system,dc=sub,dc=MyDomain,dc=com

         Guid : 54d7b52d-e302-473e-b1d198ed7aec507e

         Server Ref     : CN=NTDS Settings,CN=RODC-BRANCH-DC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=sub,DC=MyDomain,DC=com

         Computer Ref   : cn=RODC-BRANCH-DC,ou=domain controllers,dc=sub,dc=MyDomain,dc=com

         Cracked Domain : sub.MyDomain.com

         Cracked Name   : 00000002 SUB\RODC-BRANCH-DC$

         Cracked Domain : sub.MyDomain.com

         Cracked Name   : fffffff4 S-1-5-21-1292428093-1715567821-725345543-2119

         Computer's DNS : RODC-BRANCH-DC.sub.MyDomain.com

         WhenCreated  : 8/28/2013 16:46:2 GMT Standard Time GMT Daylight Time [0]

         WhenChanged  : 8/28/2013 16:46:2 GMT Standard Time GMT Daylight Time [0]

         CXTION: RODC CONNECTION (FRS)

            DN   : cn=rodc connection (frs),cn=ntds settings,cn=RODC-BRANCH-DC,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration,dc=sub,dc=MyDomain,dc=com

            Guid : c7425dd2-24c9-414f-944b90e021adc8fc

            Partner Dn   : cn=ntds settings,cn=NEW-DC-2008,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration,dc=sub,dc=MyDomain,dc=com

            Partner Rdn  : NTDS SETTINGS

            Enabled      : TRUE

            WhenCreated  : 8/28/2013 16:46:2 GMT Standard Time GMT Daylight Time [0]

            WhenChanged  : 8/28/2013 16:54:55 GMT Standard Time GMT Daylight Time [0]

            Options      : 0x00000041 [AutoGenCxtion 0x00000040 ]

            Schedule

            Day 1: 111111111111111111111111

            Day 2: 111111111111111111111111

            Day 3: 111111111111111111111111

            Day 4: 111111111111111111111111

            Day 5: 111111111111111111111111

            Day 6: 111111111111111111111111

            Day 7: 111111111111111111111111

      MEMBER: NEW-DC-2008

         DN   : cn=New-DC-2008,cn=domain system volume (sysvol share),cn=file replication service,cn=system,dc=sub,dc=MyDomain,dc=com

         Guid : 842f495a-da47-4d68-97c32022b7b75c4c

         Server Ref     : CN=NTDS Settings,CN=NEW-DC-2008,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=sub,DC=MyDomain,DC=com

         Computer Ref   : cn=New-DC-2008,ou=domain controllers,dc=sub,dc=MyDomain,dc=com

         Cracked Domain : sub.MyDomain.com

         Cracked Name   : 00000002 SUB\NEW-DC-2008$

         Cracked Domain : sub.MyDomain.com

         Cracked Name   : fffffff4 S-1-5-21-1292428093-1715567821-725345543-1639

         Computer's DNS : NEW-DC-2008.sub.MyDomain.com

         WhenCreated  : 8/13/2013 15:37:23 GMT Standard Time GMT Daylight Time [0]

         WhenChanged  : 8/13/2013 15:37:23 GMT Standard Time GMT Daylight Time [0]

         CXTION: 733652D3-0393-4030-933F-6503AA104CA1

            DN   : cn=733652d3-0393-4030-933f-6503aa104ca1,cn=ntds settings,cn=New-DC-2008,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration,dc=sub,dc=MyDomain,dc=com

            Guid : e30d8701-4ec5-4197-ac4e9b8dcbcd4408

            Partner Dn   : cn=ntds settings,cn=SECONDARY-DC-2003,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration,dc=sub,dc=MyDomain,dc=com

            Partner Rdn  : NTDS SETTINGS

            Enabled      : TRUE

            WhenCreated  : 8/13/2013 15:42:10 GMT Standard Time GMT Daylight Time [0]

            WhenChanged  : 8/27/2013 10:53:8 GMT Standard Time GMT Daylight Time [0]

            Options      : 0x00000001 [AutoGenCxtion ]

            Schedule

            Day 1: 111111111111111111111111

            Day 2: 111111111111111111111111

            Day 3: 111111111111111111111111

            Day 4: 111111111111111111111111

            Day 5: 111111111111111111111111

            Day 6: 111111111111111111111111

            Day 7: 111111111111111111111111

      MEMBER: OLD-DC-2003

         DN   : cn=OLD-DC-2003,cn=domain system volume (sysvol share),cn=file replication service,cn=system,dc=sub,dc=MyDomain,dc=com

         Guid : f7fa620a-b514-4f56-afa3ec9a06d69fe7

         Server Ref     : (null)

         Computer Ref   : (null)

         WhenCreated  : 9/19/2007 13:41:33 GMT Standard Time GMT Daylight Time [0]

         WhenChanged  : 8/13/2013 15:25:0 GMT Standard Time GMT Daylight Time [0]

         WARN - OLD-DC-2003 lacks a settings reference

      MEMBER: SECONDARY-DC-2003

         DN   : cn=Secondary-DC-2003,cn=domain system volume (sysvol share),cn=file replication service,cn=system,dc=sub,dc=MyDomain,dc=com

         Guid : b8b5ef68-7c8b-47ff-b880a30fe6167703

         Server Ref     : CN=NTDS Settings,CN=SECONDARY-DC-2003,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=sub,DC=MyDomain,DC=com

         Computer Ref   : cn=Secondary-DC-2003,ou=domain controllers,dc=sub,dc=MyDomain,dc=com

         Cracked Domain : sub.MyDomain.com

         Cracked Name   : 00000002 SUB\SECONDARY-DC-2003$

         Cracked Domain : sub.MyDomain.com

         Cracked Name   : fffffff4 S-1-5-21-1292428093-1715567821-725345543-1621

         Computer's DNS : SECONDARY-DC-2003.sub.MyDomain.com

         WhenCreated  : 3/21/2011 14:36:49 GMT Standard Time GMT Daylight Time [0]

         WhenChanged  : 8/13/2013 15:25:1 GMT Standard Time GMT Daylight Time [0]

         CXTION: F4197068-1754-49E3-8DBE-FF6E85A520E2

            DN   : cn=f4197068-1754-49e3-8dbe-ff6e85a520e2,cn=ntds settings,cn=Secondary-DC-2003,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration,dc=sub,dc=MyDomain,dc=com

            Guid : c0ea21fa-1f01-41b7-80bf8ead91cfed38

            Partner Dn   : cn=ntds settings,cn=New-DC-2008,cn=servers,cn=default-first-site-name,cn=sites,cn=configuration,dc=sub,dc=MyDomain,dc=com

            Partner Rdn  : NTDS SETTINGS

            Enabled      : TRUE

            WhenCreated  : 8/13/2013 15:27:16 GMT Standard Time GMT Daylight Time [0]

            WhenChanged  : 8/27/2013 10:4:14 GMT Standard Time GMT Daylight Time [0]

            Options      : 0x00000001 [AutoGenCxtion ]

            Schedule

            Day 1: 111111111111111111111111

            Day 2: 111111111111111111111111

            Day 3: 111111111111111111111111

            Day 4: 111111111111111111111111

            Day 5: 111111111111111111111111

            Day 6: 111111111111111111111111

            Day 7: 111111111111111111111111



SYSVOL & Atribute User Replication when DC is Off on Site Link Bridge

$
0
0

We have this AD hierchary:

Site Link1: Site0 - Site1    Site Link2: Site1 - Site2    (These 2 site links have cost 100 and Replication Interval 15)

Site Link Bridge: Site Link1 + Site Link2

Site 0 have 4 DCs. Site 1 and Site 2 have a DC. FSMO roles are on Site 0. KCC and Bridge are enabled

When DC on Site1 is off, SYSVOL changes on Site 0 are replicated to Site2, but Atribute User changes are not replicated to Site2

How long KCC takes to generate an object beetween Site0 and Site2?? I can't see it...


How to find / change machine id

$
0
0
hi friends i wanna know how to find and machine id. i am asking about machine id, not mac id or ip n isp. my machine id shows like "d41d8cd98t".

Error setting up Active Directory Domain Services (AD DS)

$
0
0

I've installed the role to the local server without much trouble, but when I open the Administrative Center, I am greeted with:

"Cannot connect to any domain. Refresh or try again when connection is available."

I click okay and try to view the local machine, and it says:

"Cannot find an available server in the <MYDOMAIN> domain that is running the Active Directory Web Service (ADWS)"

But I can see that my local server is in fact running the ADWS service.

I think it's a DNS issue (from looking at other threads), so I ran "dcdiag /test:DNS" and got the following result:

C:\Users\Administrator.SCARLETT-SERVER>dcdiag /test:DNS

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = SCARLETT-SERVER
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: Default-First-Site-Name\SCARLETT-SERVER
      Starting test: Connectivity
         The host
         ffed53cd-bd64-40ae-bc3d-2f13cb51de4f._msdcs.scarlettsystems.net could
         not be resolved to an IP address. Check the DNS server, DHCP, server
         name, etc.
         Got error while checking LDAP and RPC connectivity. Please check your
         firewall settings.
         ......................... SCARLETT-SERVER failed test Connectivity

Doing primary tests

   Testing server: Default-First-Site-Name\SCARLETT-SERVER

      Starting test: DNS

         DNS Tests are running and not hung. Please wait a few minutes...
         ......................... SCARLETT-SERVER passed test DNS

   Running partition tests on : Schema

   Running partition tests on : Configuration

   Running partition tests on : scarlettsystems

   Running enterprise tests on : scarlettsystems.net
      Starting test: DNS
         Test results for domain controllers:

            DC: SCARLETT-SERVER.scarlettsystems.net
            Domain: scarlettsystems.net


               TEST: Basic (Basc)
                  Error: No LDAP connectivity
                  Error: can't read network adapter information through WMI
                  Warning: The A record for this DC was not found
                  Warning: The AAAA record for this DC was not found
                  No host records (A or AAAA) were found for this DC

               TEST: Dynamic update (Dyn)
                  Warning: Failed to add the test record dcdiag-test-record in z
one scarlettsystems.net

            TEST: Records registration (RReg)
               Error: Record registrations cannot be found for all the network
               adapters

         Summary of DNS test results:

                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: scarlettsystems.net
               SCARLETT-SERVER              PASS FAIL PASS PASS WARN FAIL n/a

         ......................... scarlettsystems.net failed test DNS

What can be the issue?

P.S., Pinging the domain works correctly, so the DNS I presume is working.
Viewing all 31638 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>