rejoining a crashed Windows 2003 Enterprise DC/standalone root CA

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I had an issue which caused one of my Windows 2003 DCs to crash. I have a
native Windows 2003 active directory domain/forest with three DCs, two in
the main site, one at a remote site connected via VPN tunnel (multi-T1). My
DCs were having trouble replicating (SRX050720606527). I was able to get
all but one of my DCs to replicate SYSVOL properly. One of my main site DCs
refused to replicate, and during the course of my repairs I inadvertently
blue screened the DC. It appears unrecoverable.

Assuming that I have to reinstall Windows 2003 on this machine and rejoin it
to the domain and promote it to a DC, I was concerned about what pitfalls I
have to be concerned about. This DC is also a standalone root CA, so I will
have to reinstall the OS in a different directory to preserve the root
certificates. The standalone root CA was originally installed on this
machine when it was already in the domain as a domain controller, so it has
some addition functionality that it normally would not have. It only issues
certificates to my enterprise subordinate CA (two-tier PKI infrastructure).

One of my questions is will I be able to keep these certificates and reuse
them when I get this system back on-line?

The failed DC has no FSMO roles, so no issues there. It is also a DFS
Server, but I have other machines that replicate in the DFS hierarchy. Once
the failed DC is back on-line, adding a DFS share should not be a problem;
it is on its own RAID-5 array separate from the OS.


Should I delete the DC from the OU or leave it?

Any other words of wisdom or advice would be appreciated.

Edward W. Ray


.



Relevant Pages

  • Re: Switch from mixed to native mode : risks ?
    ... restore actions are within the scope of the domain by restoring all DCs ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... Before making the switch have backups of all DCs ... I want to switch my domain to native mode. ...
    (microsoft.public.windows.server.migration)
  • Re: DC replication from remote site
    ... At site B I have a Windows Server 2008 DC/GC/DNS/DHCP ... Will the 2008 DC just automatically look for another replication partner ... order to control which DCs the KCC creates partner objects with, ... You would create create an IP Subnet Object for the ...
    (microsoft.public.windows.server.sbs)
  • Re: Forgot to run AD PREP!!!
    ... Run AD Prep on another DC, then upgrade to Windows 2003, this way you know ... cannot change it to 2003 until ALL DCs are w2k3 like Dimitri said. ... have you seen my question about other DCs in that domain? ...
    (microsoft.public.windows.server.active_directory)
  • Re: problem of ntpd on W2K DCs
    ... Guess that those 3 DCs just need some kicks. ... Please nothe that the Windows multimedia timers are not necessarily used ... It does not modify the Windows system time in any way, ...
    (comp.protocols.time.ntp)
  • Re: Migration Active Directory from Windows 2000 to Windows 2003 Server
    ... Windows 2000, Windows Server 2003 ... replicates from the Win 2k DCs to the Win 2k3 DCs. ...
    (microsoft.public.windows.server.migration)