Re: adprep /forestprep fails from W2K3 R2 CD 2



Thank you.

Will this command affect DFS replication? We have a root DFS with
replication between the servers. I do not want that stopped. When it
restarts it empties all the directories into pre-existing and all users are
blown out of the water.

Is there a way to control just AD replication? What is the opposite command
to reenable it?

Thanks,

Ravi

"Jorge de Almeida Pinto [MVP - DS]" wrote:

do not disconnect the schema master fsmo from the network as mentioned
(=WRONG), but disable outbound AD replication on the schema master fsmo

repadmin /options <schema DC> +DISABLE_OUTBOUND_REPL

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"Ravi" <Ravi@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:67D17A75-58B0-470F-9064-F286492AD947@xxxxxxxxxxxxxxxx
Hello,

We have a Small Business Server 2000 (DC and holds all FSMO roles) and a
W2K3 peer DC. (Adprep already run when that DC was installed.) I want to
promote a new W2K3 R2 server to DC. First I made the common mistake of
using
CD1. When I learned about CD 2, I re-ran the command adprep /forestprep
on
the SBS box that has all roles. Following a windows help document I ran
the
command while the SBS was disconnected from the network. It failed.
After a
few success messages, the end of the adprep.log says:

Adprep was unable to upgrade the schema on the schema master.

[Status/Consequence]

The schema will not be restored to its original state.

[User Action]

Check the Ldif.err log file in the
C:\WINNT\system32\debug\adprep\logs\20061018095401 directory for detailed
information.

Adprep set the value of registry key
System\CurrentControlSet\Services\NTDS\Parameters\Schema Update Allowed to
1

Adprep was unable to update forest-wide information.

[Status/Consequence]
Adprep requires access to existing forest-wide information from the schema
master in order to complete this operation.

[User Action]
Check the log file, Adprep.log, in the
C:\WINNT\system32\debug\adprep\logs\20061018095401 directory for more
information.

ldif.err says:

Entry DN: (null)
change: modify
Attribute 0) schemaUpdateNow:1

Add error on line 1276: Operations Error
The server side error is "The schema is not loaded."
An error has occurred in the program

ldif.log has numerous (81) success messages. The end of it says:

81:
CN=ms-DS-Source-Object-DN,CN=Schema,CN=Configuration,DC=hungermountain,DC=com
Entry DN:
CN=ms-DS-Source-Object-DN,CN=Schema,CN=Configuration,DC=hungermountain,DC=com
Entry modified successfully.


82: (null)
Entry DN: (null)
change: modify
Attribute 0) schemaUpdateNow:1

Add error on line 1276: Operations Error
The server side error is "The schema is not loaded."
81 entries modified successfully.
An error has occurred in the program

Although the help doc says to restore the schema master from backup if
there
are significant problems, I did not do that. (We do have a full backup
from
last night.) I reconnected the server to the network and ran dcdiag on
both
the SBS and the W2K3 DCs. Scary messages about the schema being out of
sync
and replication of the schema not occurring. However after an hour or so
these cleaned themselves up and DCDiag on both machines now passes all
dcdiag
tests. But the registry key still reports version 30.

Any suggestions? I saw the question about whether or not the adprep can
be
run with users connected (that implies that the server is still on the
network), and I saw other Microsoft instructions that do not mention
disconnecting from the network (917385 for example). Is it possible that
the
DC NEEDS to be connected to run forestprep??? Should it be disconnected
or
not?

I am confused by the message: "Adprep requires access to existing
forest-wide information from the schema master in order to complete this
operation." The SBS where adprep was run IS the schema master.

I have not yet run adprep /domainprep from the R2 CD because of the failed
/forestprep. I saw another message that even though the key still said
30,
the dcpromo of an R2 machine succeeded. Should I try adprep /domainprep
and
promoting the new machine again? Rerun /forestprep connected to the
network?

Are there SBS 2000 and W2K3 R2 issues I'm not aware of (seems unlikely)?

Any advice greatly appreciated.

Thank you.

Ravi



.



Relevant Pages

  • Re: adprep /forestprep failure
    ... If I understand correctly, I don't expect to see anything for replication, ... because there is currently only one DC in the domain and forest, spserver01. ... The win 2003 server is not yet a DC, ... Schema FSMO holder shows spserver01.season.com. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD replication
    ... the child domain, I remove DNS from the child domain DC during weekend, and ... Before I upgrade the schema version to windows 2003 R2, ... Windows 2003 R2 server to DC, which it need upgrade the forest, then ... then the AD replication betwenn COS DC2 to main domain stoped. ...
    (microsoft.public.windows.server.active_directory)
  • Re: upgrade a Windows 2003 DC to R2
    ... MS-KBQ293783_Cannot Upgrade Windows 2000 Server to Windows Server 2003 with ... > when doing adprep forestprep. ... > "attributeId" attribute value for objects defined in Windows 2000 schema ...
    (microsoft.public.windows.server.active_directory)
  • Re: adprep /forestprep failure
    ... I ran ntdsutil to seize the schema master role, ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... The win 2003 server is not yet a DC, since I can't run adprep. ... Schema FSMO holder shows spserver01.season.com. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD replication
    ... Before I upgrade the schema version to windows 2003 R2, ... Windows 2003 R2 server to DC, which it need upgrade the forest, then I ... then the AD replication betwenn COS DC2 to main domain stoped. ... COS\DC2 via RPC ...
    (microsoft.public.windows.server.active_directory)