How to restore or recreate Active Directory System Object
- From: larsen <larsen@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Tue, 13 Feb 2007 08:44:03 -0800
OS: W2000k Server - two Domain Controlers
One Domain
One Forrest
I need to recreate AD object "cn=server,cn=system,dc=domainname"
class of object = samserver
One day this object disappeared from AD. and happen all described below.
Is anybody know how to recreate this object or import/export this object
from backups. I cannot replicate DC from Backups because password of machines
has changed and I cannot reset passwords because this object not exist - that
is my hypothesis, Or maybe somebody has different explanation and solution.
Everythink I tried - failed.
Problem is described below:
I have big problem with may DC enviroment, one day I had installed MS APARS
and then restarted one of two W2000 DC. After restarting DHCP server service
didn't start.
We try to reinstall DHCP server, but it doesn't slove problem, DHCP service
still was unstartable. We moved DHCP to another DC controler.
Except DHCP everything else works ok.
After few days we restarted secont DC - after installing APARS [ms fixes],
and the same thing happen to the second DC controller, but also now we cannot
add any workstation to domain.
We move DHCP on another machine and
We wolud like to add anoteher DC - w2k3 but
We executed:
Adprep /forestprep - successful
but
Adprep /domainprep finished with Error
We seized all FSMO roles to second DC -
on the first DC every 5 min [default local policy refresh interval] we had
error in application log:
SCECLI 1202 Events
0x2: The system cannot find the file specified.
after seizing FSMO roles on the second DC, error on first DC disappeard but
begun on the second DC.
we enabled debuging as MS recomends:
http://support.microsoft.com/kb/324383/en-us
but this doesn't change %SYSTEMROOT%\security\logs\winlogon.log don't add
any ohter insertions- there is still only one error:
----Configure Security Policy...
Warning 2: The system cannot find the file specified.
Error opening SAM account domain.
System Access configuration completed with error.
Other Errors:
Errors Raised after try different things:
--------------------------------------------------------------------------------------------------------
adprep /domainprep
error:
[Status/Consequence]
For backward compatibility, Adprep requires that the Anonymous Logon securi
he pre-Windows 2000 Compatible Access security group if the Everyone group
in controllers running Windows Server 2003, the Everyone group no longer in
[User Action]
Check the log file Adprep.log in the system root System32\Debug\Adprep\Logs
mation.
Adprep encountered a Win32 error.
Error code: 0x2 Error message: The system cannot find the file specified..
--------------------------------------------------------------------------------------------------------
Changing Password:
Unable to change the password of this account due to the following error:
2: The system cannot find the file specified
Please consult your system administrator
--------------------------------------------------------------------------------------------------------
Policy propagation - [winlogon.log]: 2 errors:
1st error:
Error 0 to send control flag 1 over to server.
GPLinkDomain GPO_INFO_FLAG_BACKGROUND )
GPLinkOrganizationUnit GPO_INFO_FLAG_BACKGROUND )
-------------
2nd error:
----Configure Security Policy...
Warning 2: The system cannot find the file specified.
Error opening SAM account domain.
System Access configuration completed with error.
--------------------------------------------------------------------------------------------------------
Similar errors when I execute netdom to reset kerberos secure channel :
"failed - file not found"
--------------------------------------------------------------------------------------------------------
Similar error when I use nltest to reset machine passwords:
.
- Follow-Ups:
- Re: How to restore or recreate Active Directory System Object
- From: Paul Williams [MVP]
- Re: How to restore or recreate Active Directory System Object
- Prev by Date: Printing with Remote Desktop
- Next by Date: Re: ADFS System.Web.Security.SingleSignOn.WebSsoConfigurationExcep
- Previous by thread: Printing with Remote Desktop
- Next by thread: Re: How to restore or recreate Active Directory System Object
- Index(es):
Relevant Pages
|