Re: Windows 2003 DC Demotion / Promotion
- From: "Jorge Silva" <jorgesilva_pt@xxxxxxxxxxx>
- Date: Wed, 23 Aug 2006 18:00:46 +0100
Windows Server 2003 SP1 introduces rights that give an administrator
independent
control over local and remote permissions for starting COM servers,
activating COM server settings, and accessing COM servers.
Some people reset to the default settings and the errors stop, you can try
that if you wan to:
Open the Component Services and change the COM Security by editing the
default permissions.
In some cases the service account don't have the remote access checkbox
checked and is needed. If that is the case give the service account remote
access permissions to the COM Applications and rebooted the DC.
Description of the changes to DCOM security settings after you install
Windows Server 2003 Service Pack 1
http://support.microsoft.com/default.aspx?scid=kb;EN-US;903220
Some firewalls may reject network traffic that originates from Windows
Server 2003 Service Pack 1-based computers
http://support.microsoft.com/default.aspx?scid=kb;EN-US;899148
Availability of Windows Server 2003 Post-Service Pack 1 COM+ 1.5 Hotfix
Rollup Package 6
http://support.microsoft.com/kb/897667/en-us
--
I hope that the information above helps you
Good Luck
Jorge Silva
MCSA
Systems Administrator
<joshelson@xxxxxxxxx> wrote in message
news:1156350231.468748.166430@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Jorge,
Thanks for the quick response and the information. I am having COM+
issues on the DC, and none of the conventional resolutions I'm aware of
has resolved the issue.
The primary symptom is a massive number (thousands a day) of COM+ event
viewer messages that look like:
Event Type: Error
Event Source: COM
Event Category: None
Event ID: 10022
Date: 8/23/2006
Time: 11:16:33 AM
User: N/A
Computer: DC01
Description:
The machine-default access security descriptor for the COM Server
application C:\WINNT\Explorer.EXE is invalid. It contains Access
Control Entries with permissions that are invalid. The requested action
was therefore not performed. This security permission can be corrected
using the Component Services administrative tool.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
I should mention that this machine went down hard after a UPS failure
during a power outage, so I'm a bit uncomfortable with the state of the
machine (though it's still limping by without COM+ being functional).
There are a number of online resources that attempt to address this
issue, but none seem to work (not even the COM+ rebuild procedure).
I don't really want to use the forceremoval options unless I have to,
but wanted to prepare for the contingency.
Josh
Jorge Silva wrote:
Inline
Can I do this simply with Domain Administrator rights in the child- Domain Admin rights.
domain, or does this require me to have Enterprise Administrator
rights?
Do rights required for the demotion portion change if I use-You need to logon the server to use the force removal switch, but
the /forceremoval option?
careful,
you'll manually have to remove the entries from AD.
Can you explain us why are you asking this questions, or what type of
issues
are you having?
--
I hope that the information above helps you
Good Luck
Jorge Silva
MCSA
Systems Administrator
<joshelson@xxxxxxxxx> wrote in message
news:1156348049.422721.284400@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Quick question (and one I probably should remember from the MCSE...).
I have a Windows 2000 mode forest / root, with a child domain running
Windows 2003 native mode.
I have an ailing DC in this child domain, and I'd like to demote him,
rebuild and then promote him.
Can I do this simply with Domain Administrator rights in the child
domain, or does this require me to have Enterprise Administrator
rights? Do rights required for the demotion portion change if I use
the /forceremoval option?
Thanks!
Josh
.
- References:
- Windows 2003 DC Demotion / Promotion
- From: joshelson
- Re: Windows 2003 DC Demotion / Promotion
- From: Jorge Silva
- Re: Windows 2003 DC Demotion / Promotion
- From: joshelson
- Windows 2003 DC Demotion / Promotion
- Prev by Date: Re: Adding Windows 2003 R2 DCs to a Windows 2000 Native Forest/Domain
- Next by Date: RE: Please Help...Dying...aah
- Previous by thread: Re: Windows 2003 DC Demotion / Promotion
- Next by thread: Re: Windows 2003 DC Demotion / Promotion
- Index(es):
Relevant Pages
|