ADPREP /forestprep fails
From: D.R. (dr_at_news.postalias)
Date: 01/12/05
- Previous message: jjhols: "RE: Enterpise CA Move"
- Next in thread: Bob Qin [MSFT]: "RE: ADPREP /forestprep fails"
- Reply: Bob Qin [MSFT]: "RE: ADPREP /forestprep fails"
- Messages sorted by: [ date ] [ thread ]
Date: Wed, 12 Jan 2005 15:19:39 -0500
ADPREP is failing near the end of the process, previously I had problems
with the inetOrgPerson due to our Cognos installation. After fixing that I
have proceeded beyond the schXX.ldf files and it now dies applying
permissions.
>From the ADPREP.LOG:
-------------
...
ADPREP was unable to modify the default security descriptor on object
CN=inetOrgPerson,CN=Schema,CN=Configuration,DC=domainx,DC=ext.[Status/Consequence]Adprep
attempts to merge the existing default security descriptors with the new
access control entry (ACE). [User Action] Check the log file Adprep.log in
the system root System32\Debug\Adprep\Logs directory for more information.
Adprep encountered a Win32 error. Error code: 0x57 Error message: The
parameter is incorrect..
...
-------------
I ran dsacls as the domain controller:
-------------
C:\>dsacls
\\localdc\CN=inetOrgPerson,CN=Schema,CN=Configuration,DC=domainx,DC=ext /A
Owner: NT AUTHORITY\SYSTEM
Group: DOMAINx\Domain Users
Audit list:
Effective Permissions on this object are:
All Everyone SPECIAL ACCESS <Inherited from parent>
DELETE
WRITE PERMISSIONS
CHANGE OWNERSHIP
CREATE CHILD
DELETE CHILD
WRITE SELF
WRITE PROPERTY
DELETE TREE
CONTROL ACCESS
Permissions inherited to subobjects are:
Inherited to all subobjects
All Everyone SPECIAL ACCESS <Inherited from parent>
DELETE
WRITE PERMISSIONS
CHANGE OWNERSHIP
CREATE CHILD
DELETE CHILD
WRITE SELF
WRITE PROPERTY
DELETE TREE
CONTROL ACCESS
Access list:
{This object is protected from inheriting permissions from the parent}
Effective Permissions on this object are:
Allow NT AUTHORITY\SYSTEM FULL CONTROL
The command completed successfully
------------
It looks as though the permissions are wrong, but I am unable to reset the
inheritance or add other users.
- Previous message: jjhols: "RE: Enterpise CA Move"
- Next in thread: Bob Qin [MSFT]: "RE: ADPREP /forestprep fails"
- Reply: Bob Qin [MSFT]: "RE: ADPREP /forestprep fails"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|