Re: Problems after domain upgrade

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



How did you rename your server name?

You should following following procedure while rename domain controller in a
domain that has single domain controller.


http://technet2.microsoft.com/WindowsServer/en/library/aad1169a-f0d2-47d5-b0ea-989081ce62be1033.mspx?mfr=true

Regards,
Mallika.

"Wolfgang Kais" wrote:

I forgot:
After raising the functional levels I renamed the new server and gave
him the name of the old one.


"Wolfgang Kais" wrote:

My question is about an error in the directory service event log after
an upgrade to a Windows Server 2003 domain.

There was a single Windows 2000 domain with one domain controller (SP4).

I executed "adprep" 3 times (after correcting the schema conflict with
Exchange 2000) with /forestprep, /domainprep and /domainprep /gpprep.
Then I added a Windows Server 2003 SP1 domain controller to the domain.

I transferred all 5 fsmo roles to the new domain controller (ntdsutil),
replicated the global catalog to the new domain controller and made the
new server a dns (AD integrated in "windows 2000 mode"), dhcp and wins
server.

After checking that replication between the two was successful using
replmon, I demoted the old domain controller to be a member server and
then completely removed it from the domain.

As the old server name still appeared in "AD Sites and Services", I
tried a "metadata cleanup" using ntdsutil, but the old server was not
listed in the site, so I deleted the server object using the snap-in.

Also, I made sure that the new server is ISTG and site licensing server.

Then I raised domain and forest functional levels to Windows Server 2003.

We fixed the msdtc issue using component services.

Checking the event log, the only problem left now is error 1411 from
source "NTDS Replication". It states that a SPN for a certain
"guid"._msdcs.domain.local could not be determined and that mutual
authentication could not take place.

I did browse the dns zones for that guid, but did not find it.

The guid is not the one from the new DC.

Any ideas on how to fix this error?

Another problem (not really a problem for the moment, but I'd like it
to be fixed): The dhcp service on the new server was never authorized
but now (after renaming the server) it is. That's OK so far, but:
I can't remove the authorization, neither using the dhcp snap-in nor
using netsh. The error message states that there was no such object.
Trying to authorize the server (using netsh) results in the message,
that the object already exists...
Maybe someone can tell me where to edit the authorization list manually
(adsiedit)?

--
Thanks in advance,
Wolfgang




.



Relevant Pages

  • correction for Gary
    ... Renaming a Domain Controller issues. ... If you wish to rename a DC, ... To rename a domain controller, use the Netdom tool command-line utility, the ... domain functional level must be set to Windows Server 2003 as well. ...
    (microsoft.public.windows.server.active_directory)
  • Re: can NT4 servers and 2003 server play nicely together?
    ... NT servers and win2k3 servers can both be on the wire at the same time. ... rename the domain name. ... 4.Upgrade the new PDC to Windows Server 2003. ... 325857 How To Expand the Boot Partition During a Windows Server 2003 Upgrade ...
    (microsoft.public.windows.server.migration)
  • Re: How to replace single domain controller in domain with a singl
    ... Although you can use System Properties to rename a domain controller, Active Directory and DNS replication latency might temporarily prevent clients from locating or authenticating to the renamed domain controller. ... export of DHCP database for 2008 choose ... demote the old DC to member server, reboot and rename it, reboot ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain controller name -rename issue
    ... Make sure you have at least a system state backup before starting the rename of the production one. ... The DNS host names of domain controllers in a renamed domain are not ... Windows NT 4.0 primary domain controller to Windows 2000 ... it with dcpromo /forceremoval to member server. ...
    (microsoft.public.windows.server.active_directory)
  • Cant connect to 2k3 server from mac osx smb client
    ... Panels -> Administrative Tools -> Domain Controller ... Server: ... >I have a fresh install of Windows Server 2003. ... I created a user account in Active ...
    (microsoft.public.windows.server.networking)