Доброго времени суток!
Перехожу на Win2k8. При поднятии на нем AD просит провести процедуру: adprep /rodcprep
Запускаю данную процедуру на PDC и получаю ответ:
F:sourcesadprep>adprep /rodcprep
Программа Adprep подключена к FSMO домена: pdc.SUNRISE.local.
==============================================================================
Программа Adprep нашла раздел DC=DomainDnsZones,DC=SUNRISE,DC=local и готова к о
бновлению разрешений.
Adprep не может связаться с репликой для раздела DC=DomainDnsZones,DC=SUNRISE,DC
=local.
При выполнении Adprep обнаружена ошибка LDAP.
Код ошибки: 0x0. Расширенный код ошибки сервера: 0x0. Сообщение об ошибке сервер
а: (null).
Adprep не удалось выполнить операцию с разделом DC=DomainDnsZones,DC=SUNRISE,DC=
local. Выполняется переход к следующему разделу.
==============================================================================
==============================================================================
Программа Adprep нашла раздел DC=ForestDnsZones,DC=SUNRISE,DC=local и готова к о
бновлению разрешений.
Adprep не может связаться с репликой для раздела DC=ForestDnsZones,DC=SUNRISE,DC
=local.
При выполнении Adprep обнаружена ошибка LDAP.
Код ошибки: 0x0. Расширенный код ошибки сервера: 0x0. Сообщение об ошибке сервер
а: (null).
Adprep не удалось выполнить операцию с разделом DC=ForestDnsZones,DC=SUNRISE,DC=
local. Выполняется переход к следующему разделу.
==============================================================================
Программа Adprep обнаружила, что операция с разделом DC=SUNRISE,DC=local была вы
полнена. Выполняется переход к следующему разделу.
==============================================================================
Adprep завершила работу с ошибками. Не все разделы были обновлены. Дополнительны
е сведения см. в файле ADPrep.log в каталоге C:Windowsdebugadpreplogs200806
23165906.
Чтобы успешно обновить все разделы, вошедший в систему в данный момент пользоват
ель должен быть членом группы администраторов предприятия. Если это не так, испр
авьте ситуацию и повторно запустите Adprep.
-
Перемещено
21 апреля 2012 г. 17:57
merge forums (От:Windows Server 2008)
Есть сервер win 2003 standart sp1 единственный контроллер домена. Известно что раньше до меня был второй контроллер но потом его убрали. Сейчас я в сети поднял win 2008 r2 ent server и запустил на нем dcpromo, он сказал сделать на кд adprep /domainprep.
Собственно при выполнении возникает ошибка связанная с синхронизацией с отсутствующим вторым контроллером
Running domainprep …
Adprep was unable to modify the security descriptor on object CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=lks-tv,DC=local.
[Status/Consequence]
ADPREP was unable to merge the existing security descriptor with the new access control entry (ACE).
[User Action]
Check the log file ADPrep.log in the C:WINDOWSdebugadpreplogs20120530165523 directory for more information.
Adprep encountered an LDAP error.
Error code: 0x20. Server extended error code: 0x208d, Server error message: 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
‘CN=File Replication Service,CN=System,DC=lks-tv,DC=local’
.
Adprep was unable to update domain information.
[Status/Consequence]
Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation.
[User Action]
Check the log file, ADPrep.log, in the C:WINDOWSdebugadpreplogs20120530165523 directory for more information.
Собственно чтото мне подсказывает что надо удалить из системы остатки второго контроллера, но вот как правильно это сделать?
Есть сервер win 2003 standart sp1 единственный контроллер домена. Известно что раньше до меня был второй контроллер но потом его убрали. Сейчас я в сети поднял win 2008 r2 ent server и запустил на нем dcpromo, он сказал сделать на кд adprep /domainprep.
Собственно при выполнении возникает ошибка связанная с синхронизацией с отсутствующим вторым контроллером
Running domainprep …
Adprep was unable to modify the security descriptor on object CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=lks-tv,DC=local.
[Status/Consequence]
ADPREP was unable to merge the existing security descriptor with the new access control entry (ACE).
[User Action]
Check the log file ADPrep.log in the C:WINDOWSdebugadpreplogs20120530165523 directory for more information.
Adprep encountered an LDAP error.
Error code: 0x20. Server extended error code: 0x208d, Server error message: 0000208D: NameErr: DSID-031001CD, problem 2001 (NO_OBJECT), data 0, best match of:
‘CN=File Replication Service,CN=System,DC=lks-tv,DC=local’
.
Adprep was unable to update domain information.
[Status/Consequence]
Adprep requires access to existing domain-wide information from the infrastructure master in order to complete this operation.
[User Action]
Check the log file, ADPrep.log, in the C:WINDOWSdebugadpreplogs20120530165523 directory for more information.
Собственно чтото мне подсказывает что надо удалить из системы остатки второго контроллера, но вот как правильно это сделать?
- Remove From My Forums
-
Question
-
found these two partition’s probibly assigned to the old crashed 2003 AD DC that i already cleared the metadata of. tried looking for the FSMOroleowner in ADSI with no luck. when running the /rocdprep it fails with «could not contact replica»
so if i coudl force these two partitions to look at the only server now left that woudl probibly fix this holdup.I have confirmed dcdiag DNS checks all good with 5 FIMSO roles active on now single 2003 AD server. the roles i am looking to reassign are only the forestdnszones & domaindnszones which are the only hold up to prepping for svr 2008 integration.
Microsft KB says «do not delete & try recreate» so thats out…4 days of googling to only see that there are literally Dozens of tech’s with very same issue but nobody’s fixes (if they posted one) is working for me 🙁
Anobody have a link for the fixfsmo.vbs script that is suppose to address this issue?
-
Edited by
Monday, June 7, 2010 8:11 PM
missed adding what i found
-
Edited by