Меню

Ошибка ldap 0x3a 58

We are in the process of upgrading Exchange 2007 to 2010.  In the process we are running dcdiag with the /a switch and the result below.

We have checked our dns server and found this to be «we think» correctly configured.

is there any way we can be pointed in the correct direction to resolve this issue before proceeding with the upgrade.

Directory Server Diagnosis

Performing initial setup:

   Trying to find home server…

   Home Server = RAD01PPWDC01

   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   
   Testing server: RAD01RAD01PPWDC01

      Starting test: Connectivity

         The host 3edd0255-ac86-4d77-9218-458a1984dbce._msdcs.radford.internal

         could not be resolved to an IP address. Check the DNS server, DHCP,

         server name, etc.

         Got error while checking LDAP and RPC connectivity. Please check your

         firewall settings.

         ……………………. RAD01PPWDC01 failed test Connectivity

   
   Testing server: RAD01RAD01PVWDC02

      Starting test: Connectivity

         ……………………. RAD01PVWDC02 passed test Connectivity

   
   Testing server: RAD01RAD02PPWDC01

      Starting test: Connectivity

         ……………………. RAD02PPWDC01 passed test Connectivity

Doing primary tests

   
   Testing server: RAD01RAD01PPWDC01

      Skipping all tests, because server RAD01PPWDC01 is not responding to

      directory service requests.

   
   Testing server: RAD01RAD01PVWDC02

      Starting test: Advertising

         ……………………. RAD01PVWDC02 passed test Advertising

      Starting test: FrsEvent

         ……………………. RAD01PVWDC02 passed test FrsEvent

      Starting test: DFSREvent

         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems.
         ……………………. RAD01PVWDC02 failed test DFSREvent

      Starting test: SysVolCheck

         ……………………. RAD01PVWDC02 passed test SysVolCheck

      Starting test: KccEvent

         ……………………. RAD01PVWDC02 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ……………………. RAD01PVWDC02 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ……………………. RAD01PVWDC02 passed test MachineAccount

      Starting test: NCSecDesc

         ……………………. RAD01PVWDC02 passed test NCSecDesc

      Starting test: NetLogons

         ……………………. RAD01PVWDC02 passed test NetLogons

      Starting test: ObjectsReplicated

         ……………………. RAD01PVWDC02 passed test ObjectsReplicated

      Starting test: Replications

         ……………………. RAD01PVWDC02 passed test Replications

      Starting test: RidManager

         ……………………. RAD01PVWDC02 passed test RidManager

      Starting test: Services

         ……………………. RAD01PVWDC02 passed test Services

      Starting test: SystemLog

         A warning event occurred.  EventID: 0x0000002F

            Time Generated: 04/15/2013   15:11:07

            Event String:

            Time Provider NtpClient: No valid response has been received from manually configured peer 2.au.pool.ntp.org after 8 attempts to contact it. This peer will be discarded as a time source and
NtpClient will attempt to discover a new peer with this DNS name. The error was: The peer is unreachable.

         A warning event occurred.  EventID: 0x0000002F

            Time Generated: 04/15/2013   15:12:11

            Event String:

            Time Provider NtpClient: No valid response has been received from manually configured peer 0.au.pool.ntp.org after 8 attempts to contact it. This peer will be discarded as a time source and
NtpClient will attempt to discover a new peer with this DNS name. The error was: The peer is unreachable.

         A warning event occurred.  EventID: 0x0000002F

            Time Generated: 04/15/2013   15:17:03

            Event String:

            Time Provider NtpClient: No valid response has been received from manually configured peer 3.au.pool.ntp.org after 8 attempts to contact it. This peer will be discarded as a time source and
NtpClient will attempt to discover a new peer with this DNS name. The error was: The peer is unreachable.

         A warning event occurred.  EventID: 0x0000002F

            Time Generated: 04/15/2013   15:18:07

            Event String:

            Time Provider NtpClient: No valid response has been received from manually configured peer 1.au.pool.ntp.org after 8 attempts to contact it. This peer will be discarded as a time source and
NtpClient will attempt to discover a new peer with this DNS name. The error was: The peer is unreachable.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:27:27

            Event String:

            Driver HP Color LaserJet 3600 required for printer !!RAD01PVWPS02!ITS-HPCLJ3600 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:27:27

            Event String:

            Driver Send to Microsoft OneNote 15 Driver required for printer Send To OneNote 2013 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:27:30

            Event String:

            Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.

         A warning event occurred.  EventID: 0x00000010

            Time Generated: 04/15/2013   15:51:02

            Event String:

            Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try
to establish a connection.

         ……………………. RAD01PVWDC02 failed test SystemLog

      Starting test: VerifyReferences

         ……………………. RAD01PVWDC02 passed test VerifyReferences

   
   Testing server: RAD01RAD02PPWDC01

      Starting test: Advertising

         ……………………. RAD02PPWDC01 passed test Advertising

      Starting test: FrsEvent

         ……………………. RAD02PPWDC01 passed test FrsEvent

      Starting test: DFSREvent

         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems.
         ……………………. RAD02PPWDC01 failed test DFSREvent

      Starting test: SysVolCheck

         ……………………. RAD02PPWDC01 passed test SysVolCheck

      Starting test: KccEvent

         ……………………. RAD02PPWDC01 passed test KccEvent

      Starting test: KnowsOfRoleHolders

         ……………………. RAD02PPWDC01 passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         ……………………. RAD02PPWDC01 passed test MachineAccount

      Starting test: NCSecDesc

         ……………………. RAD02PPWDC01 passed test NCSecDesc

      Starting test: NetLogons

         ……………………. RAD02PPWDC01 passed test NetLogons

      Starting test: ObjectsReplicated

         ……………………. RAD02PPWDC01 passed test ObjectsReplicated

      Starting test: Replications

         [Replications Check,RAD02PPWDC01] A recent replication attempt failed:

            From RAD01PPWDC01 to RAD02PPWDC01

            Naming Context: CN=Schema,CN=Configuration,DC=radford,DC=internal

            The replication generated an error (8524):

            The DSA operation is unable to proceed because of a DNS lookup failure.

            

            The failure occurred at 2013-04-15 15:41:05.

            The last success occurred at 2013-04-15 14:52:14.

            2 failures have occurred since the last success.

            The guid-based DNS name

            3edd0255-ac86-4d77-9218-458a1984dbce._msdcs.radford.internal

            is not registered on one or more DNS servers.

         [Replications Check,RAD02PPWDC01] A recent replication attempt failed:

            From RAD01PVWDC02 to RAD02PPWDC01

            Naming Context: CN=Schema,CN=Configuration,DC=radford,DC=internal

            The replication generated an error (1908):

            Could not find the domain controller for this domain.

            The failure occurred at 2013-04-15 15:42:05.

            The last success occurred at 2013-04-15 14:52:14.

            2 failures have occurred since the last success.

            Kerberos Error.

            A KDC was not found to authenticate the call.

            Check that sufficient domain controllers are available.

         [Replications Check,RAD02PPWDC01] A recent replication attempt failed:

            From RAD01PPWDC01 to RAD02PPWDC01

            Naming Context: CN=Configuration,DC=radford,DC=internal

            The replication generated an error (8524):

            The DSA operation is unable to proceed because of a DNS lookup failure.

            

            The failure occurred at 2013-04-15 15:36:04.

            The last success occurred at 2013-04-15 14:52:14.

            1 failures have occurred since the last success.

            The guid-based DNS name

            3edd0255-ac86-4d77-9218-458a1984dbce._msdcs.radford.internal

            is not registered on one or more DNS servers.

         [Replications Check,RAD02PPWDC01] A recent replication attempt failed:

            From RAD01PVWDC02 to RAD02PPWDC01

            Naming Context: CN=Configuration,DC=radford,DC=internal

            The replication generated an error (1908):

            Could not find the domain controller for this domain.

            The failure occurred at 2013-04-15 15:38:34.

            The last success occurred at 2013-04-15 14:52:14.

            1 failures have occurred since the last success.

            Kerberos Error.

            A KDC was not found to authenticate the call.

            Check that sufficient domain controllers are available.

         ……………………. RAD02PPWDC01 failed test Replications

      Starting test: RidManager

         ……………………. RAD02PPWDC01 passed test RidManager

      Starting test: Services

         ……………………. RAD02PPWDC01 passed test Services

      Starting test: SystemLog

         A warning event occurred.  EventID: 0x000003F6

            Time Generated: 04/15/2013   15:33:18

            Event String:

            Name resolution for the name _ldap._tcp.dc._msdcs.radford.internal timed out after none of the configured DNS servers responded.

         A warning event occurred.  EventID: 0x00000C18

            Time Generated: 04/15/2013   15:33:31

            Event String:

            The primary Domain Controller for this domain could not be located.

         A warning event occurred.  EventID: 0x8000001D

            Time Generated: 04/15/2013   15:33:39

            Event String:

            The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if
this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:33:49

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         A warning event occurred.  EventID: 0x000003F6

            Time Generated: 04/15/2013   15:33:57

            Event String:

            Name resolution for the name _ldap._tcp.radford.internal timed out after none of the configured DNS servers responded.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:34:16

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         A warning event occurred.  EventID: 0x00002724

            Time Generated: 04/15/2013   15:34:18

            Event String:

            This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.

         A warning event occurred.  EventID: 0x00000081

            Time Generated: 04/15/2013   15:34:36

            Event String:

            NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error
was: The entry is not found. (0x800706E1)

         An error event occurred.  EventID: 0xC2000001

            Time Generated: 04/15/2013   15:34:38

            Event String: Unexpected failure. Error code: 490@01010004

         A warning event occurred.  EventID: 0x00000081

            Time Generated: 04/15/2013   15:34:38

            Event String:

            NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error
was: The entry is not found. (0x800706E1)

         An error event occurred.  EventID: 0x00000423

            Time Generated: 04/15/2013   15:34:42

            Event String:

            The DHCP service failed to see a directory server for authorization.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:34:43

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0x00000423

            Time Generated: 04/15/2013   15:34:54

            Event String:

            The DHCP service failed to see a directory server for authorization.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:35:10

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0x00000469

            Time Generated: 04/15/2013   15:35:22

            Event String:

            The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine
gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:35:37

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:36:04

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:36:31

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         A warning event occurred.  EventID: 0x000727AA

            Time Generated: 04/15/2013   15:36:49

            Event String:

            The WinRM service failed to create the following SPNs: WSMAN/RAD02PPWDC01.radford.internal; WSMAN/RAD02PPWDC01.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:36:58

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0xC00A0038

            Time Generated: 04/15/2013   15:37:11

            Event String:

            The Terminal Server security layer detected an error in the protocol stream and has disconnected the client. Client IP: 172.26.100.32.

         An error event occurred.  EventID: 0x00000469

            Time Generated: 04/15/2013   15:37:15

            Event String:

            The processing of Group Policy failed because of lack of network connectivity to a domain controller. This may be a transient condition. A success message would be generated once the machine
gets connected to the domain controller and Group Policy has succesfully processed. If you do not see a success message for several hours, then contact your administrator.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:37:19

            Event String:

            Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:37:20

            Event String:

            Driver HP Color LaserJet 3600 required for printer !!RAD01PVWPS02!ITS-HPCLJ3600 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:37:22

            Event String:

            Driver Send to Microsoft OneNote 15 Driver required for printer Send To OneNote 2013 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:37:25

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:37:52

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         An error event occurred.  EventID: 0xC00038D6

            Time Generated: 04/15/2013   15:38:19

            Event String:

            The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

         A warning event occurred.  EventID: 0x00001695

            Time Generated: 04/15/2013   15:39:11

            Event String:

            Dynamic registration or deletion of one or more DNS records associated with DNS domain ‘radford.internal.’ failed.  These records are used by other computers to locate this server as a
domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).  

         A warning event occurred.  EventID: 0x00001695

            Time Generated: 04/15/2013   15:49:26

            Event String:

            Dynamic registration or deletion of one or more DNS records associated with DNS domain ‘radford.internal.’ failed.  These records are used by other computers to locate this server as a
domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).  

         A warning event occurred.  EventID: 0x00001695

            Time Generated: 04/15/2013   15:49:34

            Event String:

            Dynamic registration or deletion of one or more DNS records associated with DNS domain ‘ForestDnsZones.radford.internal.’ failed.  These records are used by other computers to locate this
server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).  

         A warning event occurred.  EventID: 0x00001695

            Time Generated: 04/15/2013   15:49:34

            Event String:

            Dynamic registration or deletion of one or more DNS records associated with DNS domain ‘DomainDnsZones.radford.internal.’ failed.  These records are used by other computers to locate this
server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).  

         A warning event occurred.  EventID: 0x00000081

            Time Generated: 04/15/2013   15:49:43

            Event String:

            NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error
was: The entry is not found. (0x800706E1)

         A warning event occurred.  EventID: 0x00000081

            Time Generated: 04/15/2013   15:49:44

            Event String:

            NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error
was: The entry is not found. (0x800706E1)

         A warning event occurred.  EventID: 0x00000081

            Time Generated: 04/15/2013   15:49:47

            Event String:

            NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error
was: The entry is not found. (0x800706E1)

         A warning event occurred.  EventID: 0x00000081

            Time Generated: 04/15/2013   15:49:48

            Event String:

            NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error
was: The entry is not found. (0x800706E1)

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:52:24

            Event String:

            Driver HP Color LaserJet 3600 required for printer !!RAD01PVWPS02!ITS-HPCLJ3600 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000422

            Time Generated: 04/15/2013   15:52:24

            Event String:

            The processing of Group Policy failed. Windows attempted to read the file \radford.internalSysVolradford.internalPolicies{5E6E8D57-6C8C-4868-A402-715F3DFE1048}gpt.ini from a domain controller
and was not successful. Group Policy settings may not be applied until this event is resolved. This issue may be transient and could be caused by one or more of the following:

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:52:25

            Event String:

            Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 04/15/2013   15:52:26

            Event String:

            Driver Send to Microsoft OneNote 15 Driver required for printer Send To OneNote 2013 is unknown. Contact the administrator to install the driver before you log in again.

         ……………………. RAD02PPWDC01 failed test SystemLog

      Starting test: VerifyReferences

         ……………………. RAD02PPWDC01 passed test VerifyReferences

   
   
   
   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

            For the partition (DC=ForestDnsZones,DC=radford,DC=internal) we

            encountered the following error retrieving the cross-ref’s

            (CN=15934885-fc90-49d6-9b06-9cce03bb6eb3,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. ForestDnsZones failed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=ForestDnsZones,DC=radford,DC=internal) we

            encountered the following error retrieving the cross-ref’s

            (CN=15934885-fc90-49d6-9b06-9cce03bb6eb3,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. ForestDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

            For the partition (DC=DomainDnsZones,DC=radford,DC=internal) we

            encountered the following error retrieving the cross-ref’s

            (CN=4df4ae6e-9956-4537-8aa4-f2ddca964490,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. DomainDnsZones failed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=DomainDnsZones,DC=radford,DC=internal) we

            encountered the following error retrieving the cross-ref’s

            (CN=4df4ae6e-9956-4537-8aa4-f2ddca964490,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. DomainDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ……………………. Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition

            (CN=Schema,CN=Configuration,DC=radford,DC=internal) we encountered

            the following error retrieving the cross-ref’s

            (CN=Enterprise Schema,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. Schema failed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ……………………. Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (CN=Configuration,DC=radford,DC=internal) we

            encountered the following error retrieving the cross-ref’s

            (CN=Enterprise Configuration,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. Configuration failed test CrossRefValidation

   
   Running partition tests on : radford

      Starting test: CheckSDRefDom

         ……………………. radford passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=radford,DC=internal) we encountered the

            following error retrieving the cross-ref’s

            (CN=ADRADFORD01,CN=Partitions,CN=Configuration,DC=radford,DC=internal)

             information:

               LDAP Error 0x3a (58).

         ……………………. radford failed test CrossRefValidation

   
   Running enterprise tests on : radford.internal

      Starting test: LocatorCheck

         ……………………. radford.internal passed test LocatorCheck

      Starting test: Intersite

         ……………………. radford.internal passed test Intersite

Two Windows Server 2008 R2 domain controllers. One was cloned, and the clone was introduced into the network. This created AD problems — group policy did not run, users could not access network drives, DNS lookup failures. I followed the steps
in article 875495 to fix. All steps were completed: cloned DC forced demoted, metadata cleaned, FSMO roles seized.

DC1 = cloned and demoted server — now a member server
DC2 = domain controller that seized FSMO roles from DC1

Any assistance would be appreciated. Thanks.

****Cannot access DNS Manager on DC2: when DNS Manager is expanded in Server Manager, an error pops up:»The server DC2 could not be contacted. The error was: access is denied. Would you like to add anyway?» If I add the server, the there
is a red circle with a white dash through it. There are no zones shown. I tried to add DNS Manager through an empty MMC too, not luck with name, FQDN, IP address or localhost.

All commands and errors are from DC2.

***FSMO
netdom query fsmo
Schema master               DC2..local
Domain naming master        DC2..local
PDC                         DC2..local
RID pool manager            DC2..local
Infrastructure master       DC2..local
The command completed successfully.

****Errors in Event Viewer ->
—DFS Replication:
The DFS Replication service failed to contact domain controller  to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. 

This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues. 

 
Additional Information: 
Error: 160 (One or more arguments are not correct.)

—Directory Service:
Active Directory Domain Services was unable to establish a connection with the global catalog. 

 
Additional Data 
Error value:
8430 The directory service encountered an internal failure. 
Internal ID:
3200db0 

 
User Action: 
Make sure a global catalog is available in the forest, and is reachable from this domain controller. You may use the nltest utility to diagnose this problem.

Active Directory Domain Services attempted to communicate with the following global catalog and the attempts were unsuccessful. 

 
Global catalog:
\DC2..local 

 
The operation in progress might be unable to continue. Active Directory Domain Services will use the domain controller locator to try to find an available global catalog server. 

 
Additional Data 
Error value:
5 Access is denied.

—DNS Server:
The DNS server was unable to open Active Directory.  This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it.  Check that the Active Directory is functioning
properly and reload the zone. The event data is the error code.

—FRS:
Following is the summary of warnings and errors encountered by File Replication Service while polling the Domain Controller DC2..local for FRS replica set configuration information. 

 
 Could not bind to a Domain Controller. Will try again at next polling cycle.

 
—System:
The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

The processing of Group Policy failed. Windows attempted to read the file \.localsysvol.localPolicies{31B2F340-016D-11D2-945F-00C04FB984F9}gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this
event is resolved. This issue may be transient and could be caused by one or more of the following: 
a) Name Resolution/Network Connectivity to the current domain controller. 
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). 
c) The Distributed File System (DFS) client has been disabled.

***IPCONFIG 
ipconfig /all
Windows IP Configuration

   Host Name . . . . . . . . . . . . : DC2
   Primary Dns Suffix  . . . . . . . : .local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : .local

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
   Physical Address. . . . . . . . . : 00-0C-29-20-58-9E
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::9582:81bf:c619:4af8%11(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.154.1.22(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.224
   Default Gateway . . . . . . . . . : 10.154.1.254
   DHCPv6 IAID . . . . . . . . . . . : 234884137
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-D5-1E-58-00-0C-29-20-58-9E

   DNS Servers . . . . . . . . . . . : 10.154.1.22
   Primary WINS Server . . . . . . . : 10.154.1.20
   Secondary WINS Server . . . . . . : 10.154.1.22
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{169A634F-5876-49F7-AFE5-319BD7B78A89}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

dcdiag /test:dns ->

 Directory Server Diagnosis
Performing initial setup:

   Trying to find home server…

   Home Server = DC2

   * Identified AD Forest. 
   Done gathering initial info.

Doing initial required tests

   
   Testing server: Default-First-Site-NameDC2

      Starting test: Connectivity

         The host cd24f743-c955-4530-9a42-358a4869b53f._msdcs..local

         could not be resolved to an IP address. Check the DNS server, DHCP,

         server name, etc.

         Got error while checking LDAP and RPC connectivity. Please check your

         firewall settings.

         ……………………. DC2 failed test Connectivity

Doing primary tests

   
   Testing server: Default-First-Site-NameDC2

   
      Starting test: DNS

         

         DNS Tests are running and not hung. Please wait a few minutes…

         ……………………. DC2 failed test DNS

   
   Running partition tests on : ForestDnsZones

   
   Running partition tests on : DomainDnsZones

   
   Running partition tests on : Schema

   
   Running partition tests on : Configuration

   
   Running partition tests on : 

   
   Running enterprise tests on : .local

      Starting test: DNS

         Test results for domain controllers:

            
            DC: DC2..local

            Domain: .local

            

                  
               TEST: Basic (Basc)
                  Error: No LDAP connectivity
                  Warning: adapter

                  [00000007] Intel(R) PRO/1000 MT Network Connection has

                  invalid DNS server: 10.154.1.22 (DC2)

                  Error: all DNS servers are invalid

                  No host records (A or AAAA) were found for this DC

                  Warning: no DNS RPC connectivity (error or non Microsoft DNS server is running)

         
         Summary of test results for DNS servers used by the above domain

         controllers:

         

            DNS server: 10.154.1.22 (DC2)

               1 test failure on this DNS server

               Name resolution is not functional. _ldap._tcp..local. failed on the DNS server 10.154.1.22

               
         Summary of DNS test results:

         
                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: .local

               DC2                PASS FAIL n/a  n/a  n/a  n/a  n/a  

         
         ……………………. .local failed test DNS

Two Windows Server 2008 R2 domain controllers. One was cloned, and the clone was introduced into the network. This created AD problems — group policy did not run, users could not access network drives, DNS lookup failures. I followed the steps
in article 875495 to fix. All steps were completed: cloned DC forced demoted, metadata cleaned, FSMO roles seized.

DC1 = cloned and demoted server — now a member server
DC2 = domain controller that seized FSMO roles from DC1

Any assistance would be appreciated. Thanks.

****Cannot access DNS Manager on DC2: when DNS Manager is expanded in Server Manager, an error pops up:»The server DC2 could not be contacted. The error was: access is denied. Would you like to add anyway?» If I add the server, the there
is a red circle with a white dash through it. There are no zones shown. I tried to add DNS Manager through an empty MMC too, not luck with name, FQDN, IP address or localhost.

All commands and errors are from DC2.

***FSMO
netdom query fsmo
Schema master               DC2..local
Domain naming master        DC2..local
PDC                         DC2..local
RID pool manager            DC2..local
Infrastructure master       DC2..local
The command completed successfully.

****Errors in Event Viewer ->
—DFS Replication:
The DFS Replication service failed to contact domain controller  to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. 

This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues. 

 
Additional Information: 
Error: 160 (One or more arguments are not correct.)

—Directory Service:
Active Directory Domain Services was unable to establish a connection with the global catalog. 

 
Additional Data 
Error value:
8430 The directory service encountered an internal failure. 
Internal ID:
3200db0 

 
User Action: 
Make sure a global catalog is available in the forest, and is reachable from this domain controller. You may use the nltest utility to diagnose this problem.

Active Directory Domain Services attempted to communicate with the following global catalog and the attempts were unsuccessful. 

 
Global catalog:
\DC2..local 

 
The operation in progress might be unable to continue. Active Directory Domain Services will use the domain controller locator to try to find an available global catalog server. 

 
Additional Data 
Error value:
5 Access is denied.

—DNS Server:
The DNS server was unable to open Active Directory.  This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it.  Check that the Active Directory is functioning
properly and reload the zone. The event data is the error code.

—FRS:
Following is the summary of warnings and errors encountered by File Replication Service while polling the Domain Controller DC2..local for FRS replica set configuration information. 

 
 Could not bind to a Domain Controller. Will try again at next polling cycle.

 
—System:
The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

The processing of Group Policy failed. Windows attempted to read the file \.localsysvol.localPolicies{31B2F340-016D-11D2-945F-00C04FB984F9}gpt.ini from a domain controller and was not successful. Group Policy settings may not be applied until this
event is resolved. This issue may be transient and could be caused by one or more of the following: 
a) Name Resolution/Network Connectivity to the current domain controller. 
b) File Replication Service Latency (a file created on another domain controller has not replicated to the current domain controller). 
c) The Distributed File System (DFS) client has been disabled.

***IPCONFIG 
ipconfig /all
Windows IP Configuration

   Host Name . . . . . . . . . . . . : DC2
   Primary Dns Suffix  . . . . . . . : .local
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : .local

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Intel(R) PRO/1000 MT Network Connection
   Physical Address. . . . . . . . . : 00-0C-29-20-58-9E
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::9582:81bf:c619:4af8%11(Preferred)
   IPv4 Address. . . . . . . . . . . : 10.154.1.22(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.224
   Default Gateway . . . . . . . . . : 10.154.1.254
   DHCPv6 IAID . . . . . . . . . . . : 234884137
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-D5-1E-58-00-0C-29-20-58-9E

   DNS Servers . . . . . . . . . . . : 10.154.1.22
   Primary WINS Server . . . . . . . : 10.154.1.20
   Secondary WINS Server . . . . . . : 10.154.1.22
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{169A634F-5876-49F7-AFE5-319BD7B78A89}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

dcdiag /test:dns ->

 Directory Server Diagnosis
Performing initial setup:

   Trying to find home server…

   Home Server = DC2

   * Identified AD Forest. 
   Done gathering initial info.

Doing initial required tests

   
   Testing server: Default-First-Site-NameDC2

      Starting test: Connectivity

         The host cd24f743-c955-4530-9a42-358a4869b53f._msdcs..local

         could not be resolved to an IP address. Check the DNS server, DHCP,

         server name, etc.

         Got error while checking LDAP and RPC connectivity. Please check your

         firewall settings.

         ……………………. DC2 failed test Connectivity

Doing primary tests

   
   Testing server: Default-First-Site-NameDC2

   
      Starting test: DNS

         

         DNS Tests are running and not hung. Please wait a few minutes…

         ……………………. DC2 failed test DNS

   
   Running partition tests on : ForestDnsZones

   
   Running partition tests on : DomainDnsZones

   
   Running partition tests on : Schema

   
   Running partition tests on : Configuration

   
   Running partition tests on : 

   
   Running enterprise tests on : .local

      Starting test: DNS

         Test results for domain controllers:

            
            DC: DC2..local

            Domain: .local

            

                  
               TEST: Basic (Basc)
                  Error: No LDAP connectivity
                  Warning: adapter

                  [00000007] Intel(R) PRO/1000 MT Network Connection has

                  invalid DNS server: 10.154.1.22 (DC2)

                  Error: all DNS servers are invalid

                  No host records (A or AAAA) were found for this DC

                  Warning: no DNS RPC connectivity (error or non Microsoft DNS server is running)

         
         Summary of test results for DNS servers used by the above domain

         controllers:

         

            DNS server: 10.154.1.22 (DC2)

               1 test failure on this DNS server

               Name resolution is not functional. _ldap._tcp..local. failed on the DNS server 10.154.1.22

               
         Summary of DNS test results:

         
                                            Auth Basc Forw Del  Dyn  RReg Ext
            _________________________________________________________________
            Domain: .local

               DC2                PASS FAIL n/a  n/a  n/a  n/a  n/a  

         
         ……………………. .local failed test DNS

I have Event ID 4512 error — The DNS server was unable to create the built-in directory partition ForestDnsZones.mydomain.local. The error was 9906.

Upon checking with dcdiag, I realised that it was something leftover from when one of the DC failed and I had followed the removal using NTDSUtil Metacleanup. But it seems to be not enough?

Anyone can walk me through how to remove the remnants?

Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation

   
   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation

   
   Running partition tests on : mydomainmc

      Starting test: CheckSDRefDom

         ......................... mydomainmc passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... mydomainmc passed test CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=DomainDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=a53d60e8-8981-46ff-9d4d-ce52599114ce,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... DomainDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=ForestDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=d43915b1-cb75-4172-aa91-feaee4b9eb54,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... ForestDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=DomainDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=a53d60e8-8981-46ff-9d4d-ce52599114ce,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... DomainDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=ForestDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=d43915b1-cb75-4172-aa91-feaee4b9eb54,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... ForestDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=DomainDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=a53d60e8-8981-46ff-9d4d-ce52599114ce,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... DomainDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=ForestDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=d43915b1-cb75-4172-aa91-feaee4b9eb54,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... ForestDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=DomainDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=a53d60e8-8981-46ff-9d4d-ce52599114ce,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... DomainDnsZones failed test

         CrossRefValidation

   
   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

            For the partition (DC=ForestDnsZones,DC=mydomainmc,DC=local) we

            encountered the following error retrieving the cross-ref's

            (CN=d43915b1-cb75-4172-aa91-feaee4b9eb54,CN=Partitions,CN=Configuration,DC=mydomainmc,DC=local)

             information: 
               LDAP Error 0x3a (58). 
         ......................... ForestDnsZones failed test

         CrossRefValidation

   
   Running enterprise tests on : mydomainmc.local

      Starting test: LocatorCheck

         ......................... mydomainmc.local passed test LocatorCheck

      Starting test: Intersite

         ......................... mydomainmc.local passed test Intersite

Open in new window

Название ошибки Номер Пояснения/причины LDAP_SUCCESS 0 (x’00) Успешное завершение запроса. LDAP_OPERATIONS_ERROR 1 (x’01) Произошла ошибка операции. LDAP_PROTOCOL_ERROR 2 (x’02) Обнаружено нарушение протокола. LDAP_TIMELIMIT_EXCEEDED 3 (x’03) Превышено ограничение по времени LDAP. LDAP_SIZELIMIT_EXCEEDED 4 (x’04) Превышено ограничение по размеру LDAP. LDAP_COMPARE_FALSE 5 (x’05) Операция сравнения вернула «ложь». LDAP_COMPARE_TRUE 6 (x’06) Операция сравнения вернула «истину». LDAP_STRONG_AUTH_NOT_SUPPORTED 7 (x’07) Сервер LDAP не поддерживает строгую аутентификацию. LDAP_STRONG_AUTH_REQUIRED 8 (x’08) Для данной операции требуется прохождение строгой аутентификации. LDAP_PARTIAL_RESULTS 9 (x’09) Возвращены только частичные результаты. LDAP_REFERRAL 10 (x’0A) Указывает, что в ответе присутствует отсылка LDAP. Данное сообщение будет содержать один или несколько LDAP URL, по которым клиент должен перенаправить последующие операции для получения данного DN. LDAP_ADMINLIMIT_EXCEEDED 11 (x’0B) Указывает на то, что какие-либо ограничения, установленные на стороне сервера на количество записей, возвращаемое при поиске, были превышены. LDAP_UNAVAILABLE_CRITICAL_EXTENSION 12 (x’0C) Указывает на то, что элемент управления или правило соответствия, запрашиваемые в операции, не поддерживаются данным сервером. LDAP_CONFIDENTIALITY_REQUIRED 13 (x’0D) Конфигурация данного сервера требует обеспечения какой-либо формы конфиденциальности (TLS/SSL или SASL) при выполнении подсоединения с предоставляемым DN, например, определённая на глобальном уровне или в разделе database директива security может требовать соблюдения некоторой формы SSF при выполнении simple_bind или операции обновления. LDAP_SASL_BIND_IN_PROGRESS 14 (x’0E) Данный сервер в настоящий момент выполняет SASL-подсоединение и в этом контексте запрашиваемая операция является неверной. 15 (x’0F) Не используется. LDAP_NO_SUCH_ATTRIBUTE 16 (x’10) Указанный в запросе атрибут не присутствует в записи. LDAP_UNDEFINED_TYPE 17 (x’11) Указанный в запросе тип атрибута был неверным. LDAP_INAPPROPRIATE_MATCHING 18 (x’12) Указывает на то, что правило соответствия с расширяемым фильтром соответствия не поддерживается для указываемого типа атрибута. LDAP_CONSTRAINT_VIOLATION 19 (x’13) Указываемое в операции значение атрибута нарушает некоторые ограничения.
Возможные причины:
1. Строка слишком большой длины.
2. Неверный тип — строка записывается в числовой атрибут.
3. Неправильное значение, например, атрибут может принимать только определённое значение, либо одно из набора значений. LDAP_TYPE_OR_VALUE_EXISTS 20 (x’14) Указываемый тип атрибута или значение атрибута уже присутствует в записи.
Возможные причины:
1. При добавлении записи — один или несколько атрибутов в LDIF (или операции добавления/замены) для записи в точности совпадают (дублируются). LDAP_INVALID_SYNTAX 21 (x’15) Было указано неверное значение атрибута. 22 — 31 (x’16 — x’1F). Не используются. LDAP_NO_SUCH_OBJECT 32 (x’20) Указанная запись не существует в каталоге (DIT). LDAP_ALIAS_PROBLEM 33 (x’21) Псевдоним в DIT указывает на несуществующую запись. LDAP_INVALID_DN_SYNTAX 34 (x’22) Был указан синтаксически неверный DN. Может также возникнуть, если Вы используете файл в формате LDIF (dn: cn=xxx и т.д.) с утилитой ldapdelete, которой требуется только указание простого DN. 35 (x’23) Зарезервировано и не используется в LDAPv3 (LDAPv2: LDAP_IS_LEAF — указанный объект является листовым, то есть у него нет дочерних объектов). LDAP_ALIAS_DEREF_PROBLEM 36 (x’24) Возникла проблема при разыменовании псевдонима. Смотрите также описание ошибки 33. 37 — 47 (x’25 — x’2F). Не используются. LDAP_INAPPROPRIATE_AUTH 48 (x’30) Была указана проверка подлинности, которую невозможно осуществить, например, была указана LDAP_AUTH_SIMPLE, а у записи нет атрибута userPassword. LDAP_INVALID_CREDENTIALS 49 (x’31) Были предоставлены неверные учётные данные, например, неправильный пароль.
Дополнительный текст: unable to get TLS Client DN (невозможно получить DN клиента TLS).
Возможные причины:
1. Не предоставлен сертификат клиента в случае, если директива TLSVerifyClient установлена в ‘demand’.
2. Не предоставлен сертификат клиента в случае, если директива TLSVerifyClient установлена в ‘never’. В этом случае данное сообщение об ошибке не является фатальным и обслуживание клиента продолжается. LDAP_INSUFFICIENT_ACCESS 50 (x’32) У данного пользователя недостаточно прав доступа на осуществление запрашиваемой операции. LDAP_BUSY 51 (x’33) Данный сервер (DSA) слишком занят, чтобы выполнить запрашиваемую операцию. LDAP_UNAVAILABLE 52 (x’34) DSA недоступен. Он может быть, например, остановлен, поставлен на паузу или находится в процессе инициализации. LDAP_UNWILLING_TO_PERFORM 53 (x’35) Данный сервер (DSA) не желает выполнять запрашиваемую операцию.
Дополнительный текст: no global superior knowledge (нет сведений о глобальном вышестоящем каталоге) — имя записи, которую собираются добавить или модифицировать, не находится ни в одном из контекстов именования и у сервера нет правильной отсылки на вышестоящий каталог.
Возможная причина: не задан атрибут olcSuffix (директива suffix в slapd.conf) для DIT, на которое идёт ссылка.
Дополнительный текст: Shadow context; no update referral (теневой контекст (реплика); отсылки для выполнения обновлений не указано) — DIT, в которое собираются вносить изменения, является репликой в режиме «только для чтения», и, из-за отсутствия директивы updateref, невозможно возвратить отсылку.
Возможные причины:
1. Была попытка произвести запись в реплику «только для чтения» (в конфигурации syncrepl потребитель всегда в режиме «только для чтения»).
2. В конфигурации syncrepl multi-master в файле slapd.conf возможно пропущена директива mirrormode true.
3. Если slapd при запуске использовал файл slapd.conf, а директория slapd.d (cn=config) также существует, то при последующих модификациях DIT могут возникать ошибки с выдачей этого сообщения. В частности, в FreeBSD требуется наличие явного указания в rc.conf (slapd_cn_config=»YES») для принудительного использования slapd.d. LDAP_LOOP_DETECT 54 (x’36) Выявлено зацикливание. 54 — 59 (x’37 — x’3B). Не используются. LDAP_SORT_CONTROL_MISSING 60 (x’3C) В стандартах не используется. Только для Sun LDAP Directory Server. Сервер не получил требуемый элемент управления сортировки на стороне сервера. LDAP_RANGE_INDEX_ERROR 61 (x’3D) В стандартах не используется. Только для Sun LDAP Directory Server. Результаты запроса превысили диапазон, указанный в запросе. 62 — 63 (x’3E — x’3F). Не используются. LDAP_NAMING_VIOLATION 64 (x’40) Указывает на то, что данный запрос содержит нарушение именования в отношении текущего DIT. LDAP_OBJECT_CLASS_VIOLATION 65 (x’41) Произошло нарушение объектного класса при использовании текущего набора схемы данных, например, при добавлении записи был пропущен обязательный (must) атрибут. LDAP_NOT_ALLOWED_ON_NONLEAF 66 (x’42) Операция на нелистовой записи (то есть той, у которой есть дочерние записи) не разрешается. LDAP_NOT_ALLOWED_ON_RDN 67 (x’43) Операция над RDN, например, удаление атрибута, использующегося в качестве RDN в DN, не разрешается. LDAP_ALREADY_EXISTS 68 (x’44) Данная запись уже существует в этом DIT. LDAP_NO_OBJECT_CLASS_MODS 69 (x’45) Не разрешена модификация объектного класса. LDAP_RESULTS_TOO_LARGE 70 (x’46) Только C API (черновой RFC). Результаты слишком велики и не могут содержаться в данном сообщении. LDAP_AFFECTS_MULTIPLE_DSAS 71 (x’47) Указывает на то, что операцию необходимо выполнить на нескольких серверах (DSA), а это не разрешено. 72 — 79 (x’48 — x’4F). Не используются. LDAP_OTHER 80 (x’50) Произошла неизвестная ошибка.
Возможная причина:
Попытка удаления атрибута (особенно в cn=config), удаление которого запрещено.
Дополнительный текст: olcDbDirectory: value #0: invalid path: No such file or directory
Возможная причина: перед инициализацией новой базы данных директория для её размещения должна существовать. LDAP_SERVER_DOWN 81 (x’51) Только C API (черновой RFC). Библиотека LDAP не может связаться с LDAP-сервером. LDAP_LOCAL_ERROR 82 (x’52) Только C API (черновой RFC). Произошла некоторая локальная ошибка. Обычно это неудачная попытка выделения динамической памяти. LDAP_ENCODING_ERROR 83 (x’53) Только C API (черновой RFC). Произошла ошибка при кодировании параметров, отправляемых на LDAP-сервер. LDAP_DECODING_ERROR 84 (x’54) Только C API (черновой RFC). Произошла ошибка при декодировании результатов, полученных от LDAP-сервера. LDAP_TIMEOUT 85 (x’55) Только C API (черновой RFC). При ожидании результатов было превышено ограничение по времени. LDAP_AUTH_UNKNOWN 86 (x’56) Только C API (черновой RFC). В ldap_bind() был указан неизвестный метод аутентификации. LDAP_FILTER_ERROR 87 (x’57) Только C API (черновой RFC). Операции ldap_search() был предоставлен неправильный фильтр (например, количество открывающихся и закрывающихся скобок в фильтре не совпадает). LDAP_USER_CANCELLED 88 (x’58) Только C API (черновой RFC). Указывает на то, что пользователь прервал запрошенную операцию. LDAP_PARAM_ERROR 89 (x’59) Только C API (черновой RFC). Процедура ldap была вызвана с неверными параметрами. LDAP_NO_MEMORY 90 (x’5A) Только C API (черновой RFC). Выделение памяти (например, с помощью malloc(3) или другого механизма динамического выделения памяти) вызвало сбой в процедуре из библиотеки ldap. LDAP_CONNECT_ERROR 91 (x’5B) Только C API (черновой RFC). Библиотека/клиент не может соединиться с LDAP-сервером, указанным в URL. LDAP_NOT_SUPPORTED 92 (x’5C) Только C API (черновой RFC). Указывает на то, что в запросе используется функция, не поддерживаемая данным сервером. LDAP_CONTROL_NOT_FOUND 93 (x’5D) Только C API (черновой RFC). Запрашиваемый элемент управления не найден на данном сервере. LDAP_NO_RESULTS_RETURNED 94 (x’5E) Только C API (черновой RFC). Запрашиваемая операция завершилась успешно, но никаких результатов возвращено (получено) не было. LDAP_MORE_RESULTS_TO_RETURN 95 (x’5F) Только C API (черновой RFC). Запрашиваемая операция завершилась успешно, но должны быть возвращены дополнительные результаты, которые можно уместить в текущее сообщение. LDAP_CLIENT_LOOP 96 (x’60) Только C API (черновой RFC). Клиент выявил зацикливание, например, при следовании по отсылкам. LDAP_REFERRAL_LIMIT_EXCEEDED 97 (x’61) Только C API (черновой RFC). Сервер или клиент превысил какое-либо установленное ограничение при следовании по отсылкам.

0 0 голоса
Рейтинг статьи
Подписаться
Уведомить о
guest

0 комментариев
Старые
Новые Популярные
Межтекстовые Отзывы
Посмотреть все комментарии

А вот еще интересные материалы:

  • Яшка сломя голову остановился исправьте ошибки
  • Ясность цели позволяет целеустремленно добиваться намеченного исправьте ошибки
  • Ясность цели позволяет целеустремленно добиваться намеченного где ошибка
  • Ошибка lda на лексусе
  • Ошибка l01 на котле электролюкс квантум