Re: Unknown Objects prevent replication

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Yeah that still doesn't sound right, I have yet to have seen a case where an object didn't have an objectGuid and it is impossible to have a DN without an RDN since the DN isn't a stored value, it is built from the RDN; AD is a flat structure internally, not hierarchical. I am wondering if you have some weird ACLs on those objects. What does the ntsecuritydescriptor attribute have it in for those objects?

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



Bart Vermeire wrote:
As requested I performed the adfind and it gives the same output as seen in LDP: DN only. All other objects in that container show the expected attributes except those two. Since the complete output is very long, I can send it offline if you like. This is just a small excerpt:

uSNCreated: 1378535
volTableIdxGUID: {31736676-3032-0000-0000-000000000000}
whenChanged: 20060317102331.0Z
whenCreated: 20060317102331.0Z

dn:CN=6bcd5684-8314-11d6-977b-00c04f613221\0ADEL:923fc15f-28fa-463d-ae72-18c92f50ba5e,CN=Deleted Objects,DC=DOMAIN,DC=COM

dn:CN=6bcd5687-8314-11d6-977b-00c04f613221\0ADEL:53779baa-266a-4821-acc6-76f63a8ee96d,CN=Deleted Objects,DC=DOMAIN,DC=COM

dn:CN=CC4100AC23294F309E05B7C7DCD0B001,CN=VolumeTable,CN=FileLinks,CN=System,DC=DOMAIN,DC=COM
cn: CC4100AC23294F309E05B7C7DCD0B001
instanceType: 4
linkTrackSecret: A7E9 D6A3 D909 2604 0000 0000 0000 0000

.



Relevant Pages

  • Re: Change Naming Attribute (RDN) from CN to UID
    ... You cannot change the RDN attribute. ... You can however set yourself up a policy you follow that says you set the cn to something unique such as the sAMAccountName. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to Use CSVDE.exe without exporting the "DN"
    ... Yeah, DN isn't an attribute. ... The attribute is distinguishedName, but aside from that, the DN is passed back separately anyway and probably hardcoded to be stamped, why would anyone NOT want the DN???? ... Joe Richards Microsoft MVP Windows Server Directory Services ... Cary Shultz wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: Orphaned SIDs
    ... Yeah I am curious too since I still don't understand the question. ... I could see this being a perception issue, a lingering object issue, or a IM problem. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)