[W2003] Kan Group Policy niet aanpassen

Pagina: 1
Acties:

Acties:
  • 0 Henk 'm!

  • nico_van_wijk
  • Registratie: Januari 2008
  • Laatst online: 02-07 13:40
Heb een PDC en een BDC windows 2003 server draaien. De PDC was tevens file-server.

Helaas is de PDC gecrasht waardoor de BDC het netjes heeft overgenomen. Nu wil ik bepaalde Grouppolicy's aanpassen omdat bijvoorbeeld de Mijn Documenten redirect hiermee wordt geregeld en deze verwijst nu naar de PDC. Dit probeer ik dus op de BDC.

Echter krijg ik de foutmelding: The domain controller for Group Policy operartions is not available.....
Zou dit kunnen komen opdat ik de BDC nog niet heb opgewaardeerd tot PDC?

Acties:
  • 0 Henk 'm!

  • Turdie
  • Registratie: Maart 2006
  • Laatst online: 20-08-2024
1:
Je zou als eerst is een dcdiag /v kunnen draaien om te kijken wat er precies mis gaat, eventueel kun je de output daarvan hier posten. DCDiag is te vinden in de Windows Server 2003 Support Tools.

2:
Heb je de FSMO rollen overgezet van je oude PDC naar je BDC?
Using Ntdsutil.exe to transfer or seize FSMO roles to a domain controller

Maar, eigenlijk is PDC en BDC een NT4 term en die bestaat niet meer.

[ Voor 71% gewijzigd door Turdie op 04-02-2013 06:29 ]


Acties:
  • 0 Henk 'm!

  • CMD-Snake
  • Registratie: Oktober 2011
  • Laatst online: 13-11-2022
Vergeet niet dat je ook de metadata moet verwijderen uit AD van je oude domain controller na het overzetten van de missende FSMO rol(len). Zie hier voor het verwijderen van de metadata. Beschrijvingen van Windows Server 2000 t/m 2008R2 in het artikel. (Alhoewel 2008R2 dit veel eenvoudiger maakt.)

Acties:
  • 0 Henk 'm!

  • Semt-x
  • Registratie: September 2002
  • Laatst online: 09:18
BDC is ee Windows NT term, en sinds windows 2000 niet meer van belang.
PDC bestaat als server rol ook niet meer, en bestaat alleen nog als FSMO rol, die enkele rollen vervult voor AD. (zoals tijd sync, en legacy aanmeldingen van machines voor nt4 en eerder)

De NT BDC was een read only domain controller. de PDC was de writable DC. Sinds Windows 2000 zijn alle DC's writable. Er hoeft niet te worden opgewaardeerd. als alles werkt zoals het hoort gaat dat vazelf.

De vorm van de vraag doet me vermoeden dat het vanaf het begin al niet goed werkte. Met repadmin /showrepl kun je zien wanneer de DC's voor het laatst met elkaar hebben gesynchroniseerd.

h2h,
Sem

Acties:
  • 0 Henk 'm!

  • nico_van_wijk
  • Registratie: Januari 2008
  • Laatst online: 02-07 13:40
Semt-x schreef op maandag 04 februari 2013 @ 09:39:
De vorm van de vraag doet me vermoeden dat het vanaf het begin al niet goed werkte. Met repadmin /showrepl kun je zien wanneer de DC's voor het laatst met elkaar hebben gesynchroniseerd.

h2h,
Sem
Hieronder de dcdiag /v die ik heb uitgevoerd. Hierin is o.a. te zien dat er gisterenmiddag nog is gerepliceerd met de primary DC (src-fs01). De secondary DC zorg er wel voor dat de gebruikers kunnen aanloggen op het domein, echter kan ik dus geen group policy's aanpassen en het valt me ook op dat de netwerk mapping scripts niet meer worden gestart.

Overigens krijg ik de volgende melding wanneer ik probeer een grouppolicy te wijzigen:

Domain controller nog found for src.local
The domain controller for group policy operations is not available. You may cancel this operation for this session or retry using one of the following domain controller choises:
  • The one with the operartions Master token for the PDC emulator
  • The onde used by the Active Directory Snap-ins
  • Use any available domain controller
Ik kan overigens niets meer doen met het overzetten van FSMO rollen, gezien de primary DC fysiek kapot is.

--------------------------------------------------------------------------------------
Domain Controller Diagnosis


Performing initial setup:

* Verifying that the local machine src-fs02, is a DC.

* Connecting to directory service on server src-fs02.

* Collecting site info.

* Identifying all servers.

* Identifying all NC cross-refs.

* Found 2 DC(s). Testing 1 of them.

Done gathering initial info.


Doing initial required tests


Testing server: Default-First-Site-Name\SRC-FS02

Starting test: Connectivity

* Active Directory LDAP Services Check

* Active Directory RPC Services Check

......................... SRC-FS02 passed test Connectivity


Doing primary tests


Testing server: Default-First-Site-Name\SRC-FS02

Starting test: Replications

* Replications Check

[Replications Check,SRC-FS02] A recent replication attempt failed:

From SRC-FS01 to SRC-FS02

Naming Context: DC=ForestDnsZones,DC=src,DC=local

The replication generated an error (1256):

The remote system is not available. For information about network troubleshooting, see Windows Help.

The failure occurred at 2013-02-04 09:54:10.

The last success occurred at 2013-02-03 13:53:50.

20 failures have occurred since the last success.

[SRC-FS01] DsBindWithSpnEx() failed with error 1722,

The RPC server is unavailable..

Printing RPC Extended Error Info:

Error Record 1, ProcessID is 2904 (DcDiag)

System Time is: 2/4/2013 9:11:16:51

Generating component is 8 (winsock)

Status is 1722: The RPC server is unavailable.


Detection location is 323

Error Record 2, ProcessID is 2904 (DcDiag)

System Time is: 2/4/2013 9:11:16:51

Generating component is 8 (winsock)

Status is 1237: The operation could not be completed. A retry should be performed.


Detection location is 313

Error Record 3, ProcessID is 2904 (DcDiag)

System Time is: 2/4/2013 9:11:16:51

Generating component is 8 (winsock)

Status is 10060: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.


Detection location is 311

NumberOfParameters is 3

Long val: 135

Pointer val: 0

Pointer val: 0

Error Record 4, ProcessID is 2904 (DcDiag)

System Time is: 2/4/2013 9:11:16:51

Generating component is 8 (winsock)

Status is 10060: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.


Detection location is 318

[Replications Check,SRC-FS02] A recent replication attempt failed:

From SRC-FS01 to SRC-FS02

Naming Context: DC=DomainDnsZones,DC=src,DC=local

The replication generated an error (1256):

The remote system is not available. For information about network troubleshooting, see Windows Help.

The failure occurred at 2013-02-04 09:54:10.

The last success occurred at 2013-02-03 13:53:50.

20 failures have occurred since the last success.

[Replications Check,SRC-FS02] A recent replication attempt failed:

From SRC-FS01 to SRC-FS02

Naming Context: CN=Schema,CN=Configuration,DC=src,DC=local

The replication generated an error (1722):

The RPC server is unavailable.

The failure occurred at 2013-02-04 09:54:52.

The last success occurred at 2013-02-03 13:53:50.

20 failures have occurred since the last success.

The source remains down. Please check the machine.

[Replications Check,SRC-FS02] A recent replication attempt failed:

From SRC-FS01 to SRC-FS02

Naming Context: CN=Configuration,DC=src,DC=local

The replication generated an error (1722):

The RPC server is unavailable.

The failure occurred at 2013-02-04 09:54:31.

The last success occurred at 2013-02-03 13:53:50.

20 failures have occurred since the last success.

The source remains down. Please check the machine.

[Replications Check,SRC-FS02] A recent replication attempt failed:

From SRC-FS01 to SRC-FS02

Naming Context: DC=src,DC=local

The replication generated an error (1722):

The RPC server is unavailable.

The failure occurred at 2013-02-04 09:54:10.

The last success occurred at 2013-02-03 14:16:09.

20 failures have occurred since the last success.

The source remains down. Please check the machine.

* Replication Latency Check

REPLICATION-RECEIVED LATENCY WARNING

SRC-FS02: Current time is 2013-02-04 10:10:54.

DC=ForestDnsZones,DC=src,DC=local

Last replication recieved from SRC-FS01 at 2013-02-03 13:53:50.

DC=DomainDnsZones,DC=src,DC=local

Last replication recieved from SRC-FS01 at 2013-02-03 13:53:50.

CN=Schema,CN=Configuration,DC=src,DC=local

Last replication recieved from SRC-FS01 at 2013-02-03 13:53:50.

CN=Configuration,DC=src,DC=local

Last replication recieved from SRC-FS01 at 2013-02-03 13:53:50.

DC=src,DC=local

Last replication recieved from SRC-FS01 at 2013-02-03 14:16:09.

* Replication Site Latency Check

......................... SRC-FS02 passed test Replications

Test omitted by user request: Topology

Test omitted by user request: CutoffServers

Starting test: NCSecDesc

* Security Permissions check for all NC's on DC SRC-FS02.

* Security Permissions Check for

DC=ForestDnsZones,DC=src,DC=local

(NDNC,Version 2)

* Security Permissions Check for

DC=DomainDnsZones,DC=src,DC=local

(NDNC,Version 2)

* Security Permissions Check for

CN=Schema,CN=Configuration,DC=src,DC=local

(Schema,Version 2)

* Security Permissions Check for

CN=Configuration,DC=src,DC=local

(Configuration,Version 2)

* Security Permissions Check for

DC=src,DC=local

(Domain,Version 2)

......................... SRC-FS02 passed test NCSecDesc

Starting test: NetLogons

* Network Logons Privileges Check

Verified share \\SRC-FS02\netlogon

Verified share \\SRC-FS02\sysvol

......................... SRC-FS02 passed test NetLogons

Starting test: Advertising

The DC SRC-FS02 is advertising itself as a DC and having a DS.

The DC SRC-FS02 is advertising as an LDAP server

The DC SRC-FS02 is advertising as having a writeable directory

The DC SRC-FS02 is advertising as a Key Distribution Center

The DC SRC-FS02 is advertising as a time server

......................... SRC-FS02 passed test Advertising

Starting test: KnowsOfRoleHolders

Role Schema Owner = CN=NTDS Settings,CN=SRC-FS01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local

Warning: SRC-FS01 is the Schema Owner, but is not responding to DS RPC Bind.

RPC Extended Error Info not available. Use group policy on the local machine at "Computer Configuration/Administrative Templates/System/Remote Procedure Call" to enable it.

[SRC-FS01] LDAP search failed with error 58,

The specified server cannot perform the requested operation..

Warning: SRC-FS01 is the Schema Owner, but is not responding to LDAP Bind.

Role Domain Owner = CN=NTDS Settings,CN=SRC-FS01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local

Warning: SRC-FS01 is the Domain Owner, but is not responding to DS RPC Bind.

RPC Extended Error Info not available. Use group policy on the local machine at "Computer Configuration/Administrative Templates/System/Remote Procedure Call" to enable it.

Warning: SRC-FS01 is the Domain Owner, but is not responding to LDAP Bind.

Role PDC Owner = CN=NTDS Settings,CN=SRC-FS01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local

Warning: SRC-FS01 is the PDC Owner, but is not responding to DS RPC Bind.

RPC Extended Error Info not available. Use group policy on the local machine at "Computer Configuration/Administrative Templates/System/Remote Procedure Call" to enable it.

Warning: SRC-FS01 is the PDC Owner, but is not responding to LDAP Bind.

Role Rid Owner = CN=NTDS Settings,CN=SRC-FS01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local

Warning: SRC-FS01 is the Rid Owner, but is not responding to DS RPC Bind.

RPC Extended Error Info not available. Use group policy on the local machine at "Computer Configuration/Administrative Templates/System/Remote Procedure Call" to enable it.

Warning: SRC-FS01 is the Rid Owner, but is not responding to LDAP Bind.

Role Infrastructure Update Owner = CN=NTDS Settings,CN=SRC-FS01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local

Warning: SRC-FS01 is the Infrastructure Update Owner, but is not responding to DS RPC Bind.

RPC Extended Error Info not available. Use group policy on the local machine at "Computer Configuration/Administrative Templates/System/Remote Procedure Call" to enable it.

Warning: SRC-FS01 is the Infrastructure Update Owner, but is not responding to LDAP Bind.

......................... SRC-FS02 failed test KnowsOfRoleHolders

Starting test: RidManager

* Available RID Pool for the Domain is 2103 to 1073741823

* src-fs01.src.local is the RID Master

......................... SRC-FS02 failed test RidManager

Starting test: MachineAccount

Checking machine account for DC SRC-FS02 on DC SRC-FS02.

* SPN found :LDAP/src-fs02.src.local/src.local

* SPN found :LDAP/src-fs02.src.local

* SPN found :LDAP/SRC-FS02

* SPN found :LDAP/src-fs02.src.local/SRC

* SPN found :LDAP/0b02a15f-a505-4703-aa4b-845afbde2247._msdcs.src.local

* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/0b02a15f-a505-4703-aa4b-845afbde2247/src.local

* SPN found :HOST/src-fs02.src.local/src.local

* SPN found :HOST/src-fs02.src.local

* SPN found :HOST/SRC-FS02

* SPN found :HOST/src-fs02.src.local/SRC

* SPN found :GC/src-fs02.src.local/src.local

......................... SRC-FS02 passed test MachineAccount

Starting test: Services

* Checking Service: Dnscache

* Checking Service: NtFrs

* Checking Service: IsmServ

* Checking Service: kdc

* Checking Service: SamSs

* Checking Service: LanmanServer

* Checking Service: LanmanWorkstation

* Checking Service: RpcSs

* Checking Service: w32time

* Checking Service: NETLOGON

......................... SRC-FS02 passed test Services

Test omitted by user request: OutboundSecureChannels

Starting test: ObjectsReplicated

SRC-FS02 is in domain DC=src,DC=local

Checking for CN=SRC-FS02,OU=Domain Controllers,DC=src,DC=local in domain DC=src,DC=local on 1 servers

Object is up-to-date on all servers.

Checking for CN=NTDS Settings,CN=SRC-FS02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local in domain CN=Configuration,DC=src,DC=local on 1 servers

Object is up-to-date on all servers.

......................... SRC-FS02 passed test ObjectsReplicated

Starting test: frssysvol

* The File Replication Service SYSVOL ready test

File Replication Service's SYSVOL is ready

......................... SRC-FS02 passed test frssysvol

Starting test: frsevent

* The File Replication Service Event log test

......................... SRC-FS02 passed test frsevent

Starting test: kccevent

* The KCC Event log test

Found no KCC errors in Directory Service Event log in the last 15 minutes.

......................... SRC-FS02 passed test kccevent

Starting test: systemlog

* The System Event log test

An Error Event occured. EventID: 0xC25A001D

Time Generated: 02/04/2013 10:00:49

(Event String could not be retrieved)

......................... SRC-FS02 failed test systemlog

Test omitted by user request: VerifyReplicas

Starting test: VerifyReferences

The system object reference (serverReference)


CN=SRC-FS02,OU=Domain Controllers,DC=src,DC=local and backlink on


CN=SRC-FS02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local


are correct.

The system object reference (frsComputerReferenceBL)


CN=SRC-FS02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=src,DC=local


and backlink on CN=SRC-FS02,OU=Domain Controllers,DC=src,DC=local are


correct.

The system object reference (serverReferenceBL)


CN=SRC-FS02,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=src,DC=local


and backlink on


CN=NTDS Settings,CN=SRC-FS02,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=src,DC=local


are correct.

......................... SRC-FS02 passed test VerifyReferences

Test omitted by user request: VerifyEnterpriseReferences

Test omitted by user request: CheckSecurityError


Running partition tests on : ForestDnsZones

Starting test: CrossRefValidation

......................... ForestDnsZones passed test CrossRefValidation

Starting test: CheckSDRefDom

......................... ForestDnsZones passed test CheckSDRefDom


Running partition tests on : DomainDnsZones

Starting test: CrossRefValidation

......................... DomainDnsZones passed test CrossRefValidation

Starting test: CheckSDRefDom

......................... DomainDnsZones passed test CheckSDRefDom


Running partition tests on : Schema

Starting test: CrossRefValidation

......................... Schema passed test CrossRefValidation

Starting test: CheckSDRefDom

......................... Schema passed test CheckSDRefDom


Running partition tests on : Configuration

Starting test: CrossRefValidation

......................... Configuration passed test CrossRefValidation

Starting test: CheckSDRefDom

......................... Configuration passed test CheckSDRefDom


Running partition tests on : src

Starting test: CrossRefValidation

......................... src passed test CrossRefValidation

Starting test: CheckSDRefDom

......................... src passed test CheckSDRefDom


Running enterprise tests on : src.local

Starting test: Intersite

Skipping site Default-First-Site-Name, this site is outside the scope


provided by the command line arguments provided.

......................... src.local passed test Intersite

Starting test: FsmoCheck

Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355

A Global Catalog Server could not be located - All GC's are down.

Warning: DcGetDcName(PDC_REQUIRED) call failed, error 1355

A Primary Domain Controller could not be located.

The server holding the PDC role is down.

Time Server Name: \\src-fs02.src.local

Locator Flags: 0xe00001f8

Preferred Time Server Name: \\src-fs02.src.local

Locator Flags: 0xe00001f8

KDC Name: \\src-fs02.src.local

Locator Flags: 0xe00001f8

......................... src.local failed test FsmoCheck

Test omitted by user request: DNS

Test omitted by user request: DNS

Acties:
  • 0 Henk 'm!

  • CMD-Snake
  • Registratie: Oktober 2011
  • Laatst online: 13-11-2022
Semt-x schreef op maandag 04 februari 2013 @ 09:39:
De NT BDC was een read only domain controller. de PDC was de writable DC. Sinds Windows 2000 zijn alle DC's writable.
Alleen met 2003 waren alle DC writable. Sinds 2008 is er de Read-Only DC weer als feature.

De TS moet de missende FSMO rollen overhevelen naar zijn bestaande DC. Let wel dat je de oude DC nooit meer kan gebruiken daarna. Tenzij je die buiten het netwerk opnieuw installeert als een nieuwe machine.

Ik zie in de output ook verwijzingen naar een missende PDC emulator.

Acties:
  • 0 Henk 'm!

  • nico_van_wijk
  • Registratie: Januari 2008
  • Laatst online: 02-07 13:40
CMD-Snake schreef op maandag 04 februari 2013 @ 11:47:
[...]
De TS moet de missende FSMO rollen overhevelen naar zijn bestaande DC.
Maar dit kan toch niet meer? Mijn primary dc is deffect.

Acties:
  • 0 Henk 'm!

  • CMD-Snake
  • Registratie: Oktober 2011
  • Laatst online: 13-11-2022
nico_van_wijk schreef op maandag 04 februari 2013 @ 12:04:
[...]

Maar dit kan toch niet meer? Mijn primary dc is deffect.
In een van de eerste reacties in het topic is een link naar de handleiding hoe je dit moet doen. Maar nogmaals hier:

How to view and transfer FSMO roles in Windows Server 2003

Ik had ook een link gegeven hoe je de metadata op kan ruimen als je FSMO rollen hebt overgezet. De troep opruimen is ook een belangrijke stap. Je foutmeldingen moeten dan ook verdwijnen.

De oude DC kan je na het overzetten van de FSMO rollen nooit meer gebruiken.

Acties:
  • 0 Henk 'm!

  • Question Mark
  • Registratie: Mei 2003
  • Laatst online: 12-07 15:28

Question Mark

Moderator SSC/WOS

F7 - Nee - Ja

^^ dat dus

FSMO rollen seizen en een metadata cleanup gaan uitvoeren.

Verder hoop ik wel voor topicstarter dat beide DC's Global Catalog waren.

MCSE NT4/2K/2K3, MCTS, MCITP, CCA, CCEA, CCEE, CCIA, CCNA, CCDA, CCNP, CCDP, VCP, CEH + zwemdiploma A & B


Acties:
  • 0 Henk 'm!

  • nico_van_wijk
  • Registratie: Januari 2008
  • Laatst online: 02-07 13:40
Question Mark schreef op maandag 04 februari 2013 @ 14:03:

Verder hoop ik wel voor topicstarter dat beide DC's Global Catalog waren.
Iedereen hartelijk dank voor zijn reacties. Heb de domein controller weer gerepareerd door er een nieuw moederbord erin te zetten.

Ik heb wel geleerd dat ik een aantal zaken niet goed heb ingericht. Bij het inloggen van de clients ging er toch het één en ander niet goed. Nu werd ik ook getriggerd door Mark, de Global Catolog stond niet aan op de 2e dc.

Betekend dit dat alle objecten niet goed bijgehouden worden, waardoor er inlog problemen ontstaan? Wat is het verschil nu tussen in en uitschakelen?

Mijn bedoeling was dat alles gewoon lekker door zou blijven draaien als de 1e dc uitvalt, dit was beperkt zo.

Acties:
  • 0 Henk 'm!

  • Killah_Priest
  • Registratie: Augustus 2001
  • Laatst online: 12-07 19:52
A global catalog is a domain controller that stores a copy of all Active Directory objects in a forest. The global catalog stores a full copy of all objects in the directory for its host domain and a partial copy of all objects for all other domains in the forest, as shown in the following figure.

Zie http://technet.microsoft....ry/cc736934(v=ws.10).aspx voor meer info over de GC
Pagina: 1