Re: add a new 2003 server to domain as DC



Thanks Ulf,

nice to hear from you and tried hard to solve it again, but not much
progresses and get kind of desperate with this issue~~~~ have installed
a new 2k3 server but yes the problem stays, SYSVOL FRS gets no way to
work out...reported always event 13562 follows 13565(no popular 13508
error)(before and after forceremoval and cleanup), and the error string
%2 for 13562 is aleays empty:

------------------------------------
Event Type: Warning
Event Source: NtFrs
Event Category: None
Event ID: 13562
Date: 04.08.2005
Time: 20:29:37
User: N/A
Computer: BYRONBDC
Description:
Following is the summary of warnings and errors encountered by File
Replication Service while polling the Domain Controller
byronbdc.mydomain.net for FRS replica set configuration information.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
------------------------------------

besides, with "ntfrsutl ds" I got some vaules not sure for SYSVOL Set:

---------------------------------------
SET: DOMAIN SYSTEM VOLUME (SYSVOL SHARE)
DN : cn=domain system volume (sysvol share),cn=file replication
service,cn=system,dc=mydomain,dc=com
Guid : fbee5e0d-4b8f-4cf0-b90025f0b27ad29f
Type : (null)
Primary Member: (null)
File Filter : (null)
Dir Filter : (null)
FRS Flags : (null)
WhenCreated : 7/31/2005 21:15:49 W. Europe Standard Time W.
Europe Daylight Time [-60]
WhenChanged : 7/31/2005 21:21:7 W. Europe Standard Time W.
Europe Daylight Time [-60]
---------------------------------------

are all these "(null)"s kind of correct? otherwise, only error output I
can found with all kinds of diagnose tools, is still that line with
"dcdiag /v /c /a":

---------------------------------------
Starting test: VerifyEnterpriseReferences
LDAP Error 0x5e (94) - No result present in message.
......................... BYRONBDC failed test
VerifyEnterpriseReferences
---------------------------------------

no clue here, what correct keys should be somewhere for
enterprisereferences? and with frsdiag tool, after removal there are
only those 13562 fails from FRS event log; when added server as new DC,
frsdiag on PDC reports a unknown domain controller comes from nowhere:

------------------------------------------------------------
FRSDiag v1.7 on 04.08.2005 21:13:28
..\byronbdc on 2005-08-04 at 21.13.28
------------------------------------------------------------
Checking for errors/warnings in FRS Event Log ....
NtFrs 04.08.2005 13:39:44 Warning 13562 Following is the summary of
warnings and errors encountered by File Replication Service while
polling the Domain Controller byronbdc.mydomain.net for FRS replica set
configuration information.
......... failed 1
Checking for errors in Directory Service Event Log ....
NTDS Replication 04.08.2005 21:01:21 Error 1411 Active Directory failed
to construct a mutual authentication service principal name (SPN) for
the following domain controller. Domain controller:
27a425d2-0b84-4f2e-9538-2d3992dedcf2._msdcs.mydomain.net The call
was denied. Communication with this domain controller might be
affected. Additional Data Error value: 8589 The DS cannot
derive a service principal name (SPN) with which to mutually
authenticate the target server because the corresponding server object
in the local DS database has no serverReference attribute.
WARNING: Found Directory Service Errors in the past 15 days! FRS
Depends on AD so Check AD Replication!
......... failed 1
------------------------------------------------------------

strange is that
27a425d2-0b84-4f2e-9538-2d3992dedcf2._msdcs.mydomain.net, I dont have
any GUID like that as domain controller, and nowhere can I find them in
ADSI entries or Users/Computers/Metadata cleanup, is there another
place could it hidding? on testsvr looks rather ok, except event 13562,
13565, and reported registry SysvolReady = 0 still. with sonar.exe it
reports both failed, "cannot read instance E:\sysvol\domain", but
repadmin /showrepl and repadmin /showconns report all good....????

very much nearly my last try, seems it is good time to stop and screw
my head deep into AD/replication, finally do some serious studies.
however, still wish to get some good advices, as to me, "learning by
doing" disaster-masters, maybe with some guidence suddenly comes all
the light behind the corner...:)

thanks and my best Regards,

Paulo

.



Relevant Pages

  • Re: multiple errors in Active Directory
    ... The File Replication Service is having trouble enabling replication from ... FRS will keep retrying. ... This event log message will appear once per connection, ... Source domain controller address: ...
    (microsoft.public.windows.server.active_directory)
  • RE: Replication works off and on after upgrading to 2003 from 2000 server?
    ... I understand the issue is that after upgrading your domain controller to ... FRS can not correctly resolve the DNS name for server 2 from server 1. ... unable to complete the RPC connection to a specific replication partner. ... Since FRS servers gather their replication topology information from their ...
    (microsoft.public.windows.server.migration)
  • Problem with SYSVOL replication after DCPROMO
    ... FRS starts to replicate SYSVOL and filles stageing area and the sysvol ... I tried the BurFlags=D2, resulting in a complete new replication of SYSVOL, ... initializing the system volume with data from another domain controller. ... Service completes the initialization process, ...
    (microsoft.public.win2000.active_directory)
  • SYSVOL replication stops after DCPROMO
    ... FRS starts to replicate SYSVOL and filles stageing area and the sysvol ... I tried the BurFlags=D2, resulting in a complete new replication of SYSVOL, ... initializing the system volume with data from another domain controller. ... Service completes the initialization process, ...
    (microsoft.public.windows.server.active_directory)
  • Re: SYSVol Replication - Multiple Locations
    ... Sysvol and AD are replicated via two different mechanisms. ... replicated by FRS, so if you are having problems with Sysvol ... You can disable the ntfrs service, but as you know, replication will ... >> own server, and our hq has 3 servers, all of the servers are DCs. ...
    (microsoft.public.windows.server.active_directory)