Re: FMSO question



you did not clean the AD metadata of the DC that died as you should!
just deleting the computer account is not enough
see: http://blogs.dirteam.com/blogs/jorge/archive/2005/12/03/213.aspx

in your case I would:
* disconnect the promoted DC
* clean the AD metadata as needed
* seize FSMO roles as needed to another live DC
* install and promote a new DC (make a GC as needed)
* relocate the FSMO roles as needed

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"PRMolina" <prmolina@xxxxxxxxx> wrote in message
news:5477FF3F-D4F4-4996-B5E4-C98626002F46@xxxxxxxxxxxxxxxx
I have two DCs in a Win 2003 AD network, DC1 and DC2. DC1 crashed. I
removed it from Active Directory by right clicking on it in dsa.msc and
choosing delete. Then I rebuilt it, naming it DC1 again joined it to the
domain and ran dcpromo. Everything works, although its only been a couple
of
days so give it time.
I started thinking about it, and am wondering who my FMSOs are. Checked
system log on DC1 and sure enough got an error 16651 "The directory
service
is missing mandatory configuration information, and is unable to determine
the ownership of floating single-master operation roles". Also getting
some
warnings in the Directory Services logs in both servers, NTDS 1232
replication errors all relating to an inability to find the server with
these
roles.
It looks like there are risks if you introduce into a domain two servers
with these roles, so I would like to keep them on DC1 "just in case" even
though it has been wiped and reinstalled. This server is still randomly
locking up on me, more than likely a hardware problem, so I have to
consider
the possibility that it will be out of commission at some point.

Should I just go in and seize the roles onto the new unimproved DC1?

Any advice/comments/sympathetic laughter would be greatly appreciated!

-Paul


.



Relevant Pages

  • Re: Need Help with Odd LDAP Error, NCSecDesc Failure running DCDIA
    ... then promote the server. ... Based on the way you removed it, it's likely that replication is hung up on ... Allen sent some docs describing how to clean it. ... to clean the metadata of the rest of the servers after demoting the new ...
    (microsoft.public.windows.server.active_directory)
  • Re: Setup guides & a recommendation?
    ... You will have to do a metadata cleanup and forcibly remove ... you should have a clean and neat second DC. ... controller and server setup in tatters. ... The secondary domain controller has passed its tombstone and is now no ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need Help with Odd LDAP Error, NCSecDesc Failure running DCDIA
    ... Douglas, if your AD is setup properly, replication issues will be hard to ... server that is 1000 miles away. ... To cleanup the metadata use the link I ... Allen sent some docs describing how to clean it. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... # Allow out access to my ISP's Domain name server. ... Firewall Rule Set not allowing access to DNS servers? ... but I never said dc1 was my inside nic. ...
    (freebsd-questions)
  • Re: 2k3 keep hanging?
    ... Verifying that the local machine DC1, ... Connecting to directory service on server DC1. ... Latency information for 1 entries in the vector were ignored. ... The File Replication Service SYSVOL ready test ...
    (microsoft.public.windows.server.general)

Loading