Re: dcpromo failed



Ran all the diags and then some (dcidag /test:dns, portqry, netmon, etc...).
Speaking in general terms everything seems to be ok. I would post the
result, but I don't want to reveal the infrastructure and cleaning up the
file would take way too long.



To answer Cary's questions:



We do have multiple domains.

We do have multiple sites defined in AD.



A note. I was just able to add two other domain controllers in to the same
domain/site. This is the only domain controller that fails. The only
difference between the successful promotions and the failure is the failing
dcpromo box is running the 64-bit version of Server.



Furthermore, subsequent attempts of performing a dcpromo errors out with:



The operation failed because:

An LDAP connection could not be established with the domain controller
contosodom1.contoso.com.

"The specified server cannot perform the requested operation."







"Paul Bergson [MVP-DS]" <pbergson@xxxxxxxxxxxxxxxxx> wrote in message
news:uv1BYFQqHHA.3484@xxxxxxxxxxxxxxxxxxxxxxx
You could run diagnostics against the domain to see if there are any
issues with it.

If you don't have the tools installed, install them from your server
install disk.
d:\support\tools\setup.exe

Run dcdiag, netdiag and repadmin in verbose mode.
-> DCDIAG /V /C /D /E /s:yourdcname > c:\dcdiag.log
-> netdiag.exe /v > c:\netdiag.log (On each dc)
-> repadmin.exe /showrepl dc* /verbose /all /intersite > c:\repl.txt

**Note: Using the /E switch in dcdiag will run diagnostics against ALL
dc's in the forest. If you have significant numbers of DC's this test
could generate significant detail and take a long time. You also want to
take into account slow links to dc's will also add to the testing time.

When complete search for fail, error and warning messages.


--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"doh" <doh@xxxxxxxxxxx> wrote in message news:f46tm0$kvo$1@xxxxxxxxxxx
Running into wall with dcpromo.

All DCs in the forest are Server 2003 R2 32-bit

New DC to be added is Server 2003 R2 64-bit

Execute dcpromo (attempted with enterprise admin account and domain admin
account) and it goes through the entire process including replication
until:

The operation failed because:

Active Directory could not create the NTDS Settings object for this
domain controller CN=NTDS
Settings,CN=NEWDOMAINCONTROLLER,CN=Servers,CN=New-Site,CN=Sites,CN=Configuration,DC=contoso,DC=com
on the remote domain controller contosodom1.contoso.com. Ensure the
provided network credentials have sufficient permissions.

"The RPC server is unavailable."


Any clues?





.



Relevant Pages

  • Re: I hate IIS - "Server Application Unavailable" error message
    ... this is on a Win2003 Server. ... complaints or warnings installing IIS for me. ... as the SYSTEM account on a domain controller, although I would encrypt the section. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Unable To Add DC
    ... I have reloaded it with 2003 server again and given ... I have gone into active directory users and computers then ... it still had the old domain controller in there, ... account SERVERNAME$ to a domain controller ...
    (microsoft.public.windows.server.active_directory)
  • Re: I hate IIS - "Server Application Unavailable" error message
    ... Open the IIS Manager and, in the properties for the "Default Web Site" ... How To: Create a Service Account for an ASP.NET 2.0 Application: ... This is a server that sits in the basement. ... problem is you now leave a big hole into your domain controller. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Multiple Sites
    ... Note that you want that domain controller physical secured to ... controllers not being able to replicate for a couple of weeks. ... any users or groups at that site after the install it may be OK. ... it would need to point to itself as it's primary preferred dns server. ...
    (microsoft.public.windows.server.networking)
  • Re: AD
    ... to run dcpromo to make it a member server, ... since the Domain Controller was not ... >> reset it's account but I was unable to it. ...
    (microsoft.public.win2000.active_directory)

Loading