Hi all,
Having major problems here.
Currently have 2 Windows 2003 DC’s and I need to replace one of these with a new Win 2008 R2 machine.
What’s bugging me the most is this is the 4th time I’ve started from scratch with this new server – the first time the DCPROMO seemed to run ok and it was only when I was configuring IIS that this screwed it all up and I had to start again. It screwed it so bad infact that I’d already transferred the FSMO roles across to it (http://support.microsoft.com/kb/324801) and was unable to run DCPROMO again to remove the server from the AD Config.
So I transferred the FSMO roles back on the primary server. I then ran these procedures to remove all old traces of the server: http://support.microsoft.com/?id=216498.
I can confirm that 10.61.15.5, Server1, has control of all 5 roles, and both it and the other DC (10.16.15.6) are running fine, as they always have done.
Then started all over again with the new server, from a clean format. I’ve installed
DHCP, and copied across the config from one of the other two machines, as per here:
http://support.microsoft.com/kb/962355
Then installed the ADDS role, and then ran DCPROMO again. For the longest time I was continually getting an error stating that I had DHCP configured on the Network Adapter, but I’ve now (I think) disable IPv6 completely and disabled all other network adapters (server has 4). The last time I ran DCPROMO I didn’t get the error.
DCPROMO runs and the machine gets a restart. The IP properties are set up so the new server has an ip of 10.61.15.4 (the others are 10.61.15.5 and .6 respectively). Subnet is set to 255.255.555.0 and default gateway 10.61.15.1.
The DNS was set, before running DCPROMO, to look at 10.61.15.5 as otherwise I was unable to run DCPROMO as it told me it couldn’t find a domain controller.
I then restart and get Event ID 4013 errors on boot up, and dcdiag gives me the following:
4013 ERROR:
Source DNS
EVENT ID 4013
The DNS server is waiting for Active Directory Domain Services (AD DS) to signal that the initial synchronization of the directory has been completed. The DNS server service cannot start until the initial synchronization is complete because critical DNS data might not yet be replicated onto this domain controller. If events in the AD DS event log indicate that there is a problem with DNS name resolution, consider adding the IP address of another DNS server for this domain to the DNS server list in the Internet Protocol properties of this computer. This event will be logged every two minutes until AD DS has signaled that the initial synchronization has successfully completed.
DCDIAG RESULTS:
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = slgc-lri-svr-01
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01
Starting test: Connectivity
......................... SLGC-LRI-SVR-01 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01
Starting test: Advertising
......................... SLGC-LRI-SVR-01 passed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... SLGC-LRI-SVR-01 passed test FrsEvent
Starting test: DFSREvent
......................... SLGC-LRI-SVR-01 passed test DFSREvent
Starting test: SysVolCheck
......................... SLGC-LRI-SVR-01 passed test SysVolCheck
Starting test: KccEvent
A warning event occurred. EventID: 0x80000B46
Time Generated: 07/14/2010 13:21:37
Event String:
The security of this directory server can be significantly enhanced by configuring the server to reject SASL (Negotiate, Kerberos, NTLM, or Digest) LDAP binds that do not request signing (integrity verification) and LDAP simple binds that are performed on a cleartext (non-SSL/TLS-encrypted) connection. Even if no clients are using such binds, configuring the server to reject them will improve the security of this server.
......................... SLGC-LRI-SVR-01 passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... SLGC-LRI-SVR-01 passed test
KnowsOfRoleHolders
Starting test: MachineAccount
......................... SLGC-LRI-SVR-01 passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=leicester,DC=serco,DC=com
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=leicester,DC=serco,DC=com
......................... SLGC-LRI-SVR-01 failed test NCSecDesc
Starting test: NetLogons
......................... SLGC-LRI-SVR-01 passed test NetLogons
Starting test: ObjectsReplicated
......................... SLGC-LRI-SVR-01 passed test
ObjectsReplicated
Starting test: Replications
REPLICATION LATENCY WARNING
ERROR: Expected notification link is missing.
Source SERVER1
Replication of new changes along this path will be delayed.
This problem should self-correct on the next periodic sync.
REPLICATION LATENCY WARNING
ERROR: Expected notification link is missing.
Source SERVER1
Replication of new changes along this path will be delayed.
This problem should self-correct on the next periodic sync.
REPLICATION LATENCY WARNING
ERROR: Expected notification link is missing.
Source SERVER1
Replication of new changes along this path will be delayed.
This problem should self-correct on the next periodic sync.
REPLICATION LATENCY WARNING
ERROR: Expected notification link is missing.
Source SERVER1
Replication of new changes along this path will be delayed.
This problem should self-correct on the next periodic sync.
......................... SLGC-LRI-SVR-01 passed test Replications
Starting test: RidManager
......................... SLGC-LRI-SVR-01 passed test RidManager
Starting test: Services
......................... SLGC-LRI-SVR-01 passed test Services
Starting test: SystemLog
An error event occurred. EventID: 0x0000040B
Time Generated: 07/14/2010 12:29:20
Event String:
The DHCP service was unable to create or lookup the DHCP Users local group on this computer. The error code is in the data.
An error event occurred. EventID: 0x0000040C
Time Generated: 07/14/2010 12:29:20
Event String:
The DHCP server was unable to create or lookup the DHCP Administrators local group on this computer. The error code is in the data.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 12:29:25
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 12:39:54
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 12:39:55
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 12:40:11
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 12:40:32
Event String:
Name resolution for the name slgc-lri-svr-01.leicester.serco.com timed out after none of the configured DNS servers responded.
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 12:51:00
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 12:51:01
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 12:51:19
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
An error event occurred. EventID: 0x00000456
Time Generated: 07/14/2010 13:05:40
Event String:
The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.
A warning event occurred. EventID: 0x8000001D
Time Generated: 07/14/2010 13:08:39
Event String:
The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 13:08:50
Event String:
Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:16:01
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:16:05
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:16:47
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:16:51
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:17:31
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:17:35
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:18:01
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:18:05
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x80000431
Time Generated: 07/14/2010 13:18:32
Event String:
The attempt by user LEICESTER\administrator to restart/shutdown computer SLGC-LRI-SVR-01 failed
A warning event occurred. EventID: 0x8000001D
Time Generated: 07/14/2010 13:21:30
Event String:
The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 13:21:41
Event String:
Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:22:03
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x000727AA
Time Generated: 07/14/2010 13:24:09
Event String:
The WinRM service failed to create the following SPNs: WSMAN/slgc-lri-svr-01.leicester.serco.com; WSMAN/slgc-lri-svr-01.
......................... SLGC-LRI-SVR-01 failed test SystemLog
Starting test: VerifyReferences
......................... SLGC-LRI-SVR-01 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : leicester
Starting test: CheckSDRefDom
......................... leicester passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... leicester passed test CrossRefValidation
Running enterprise tests on : leicester.serco.com
Starting test: LocatorCheck
......................... leicester.serco.com passed test LocatorCheck
Starting test: Intersite
......................... leicester.serco.com passed test Intersite
I can see the AD has replicated across as I can browse users and computers etc, but I don’t want the DNS setup this way as it’s not set like this on the other servers. So I go into IP properties and see that the system has auto added the alternate DNS of 127.0.0.1. The preferred is still set to 10.61.15.5, which now needs changing to that of this new server, and the 127.0.0.0 removed.
It takes 20 minutes to get past the Apply computer setting dialog too even when set to look at 10.61.15.5.
Once I change these settings it cannot replicate, connect to the internet, and the problem then is the network adapter reports it cannot connect to a network (unidentified network) and the server has no access to the DC to replicate at all then.
Running dcdia
g now gives following:
Directory Server Diagnosis
Performing initial setup:
Trying to find home server...
Home Server = slgc-lri-svr-01
* Identified AD Forest.
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01
Starting test: Connectivity
......................... SLGC-LRI-SVR-01 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\SLGC-LRI-SVR-01
Starting test: Advertising
Warning: SLGC-LRI-SVR-01 is not advertising as a time server.
......................... SLGC-LRI-SVR-01 failed test Advertising
Starting test: FrsEvent
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
......................... SLGC-LRI-SVR-01 passed test FrsEvent
Starting test: DFSREvent
......................... SLGC-LRI-SVR-01 passed test DFSREvent
Starting test: SysVolCheck
......................... SLGC-LRI-SVR-01 passed test SysVolCheck
Starting test: KccEvent
A warning event occurred. EventID: 0x80000828
Time Generated: 07/14/2010 13:43:03
Event String:
Active Directory Domain Services could not use DNS to resolve the IP address of the source domain controller listed below. To maintain the consistency of Security groups, group policy, users and computers and their passwords, Active Directory Domain Services successfully replicated using the NetBIOS or fully qualified computer name of the source domain controller.
A warning event occurred. EventID: 0x80000828
Time Generated: 07/14/2010 13:44:04
Event String:
Active Directory Domain Services could not use DNS to resolve the IP address of the source domain controller listed below. To maintain the consistency of Security groups, group policy, users and computers and their passwords, Active Directory Domain Services successfully replicated using the NetBIOS or fully qualified computer name of the source domain controller.
......................... SLGC-LRI-SVR-01 passed test KccEvent
Starting test: KnowsOfRoleHolders
......................... SLGC-LRI-SVR-01 passed test
KnowsOfRoleHolders
Starting test: MachineAccount
......................... SLGC-LRI-SVR-01 passed test MachineAccount
Starting test: NCSecDesc
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=ForestDnsZones,DC=leicester,DC=serco,DC=com
Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have
Replicating Directory Changes In Filtered Set
access rights for the naming context:
DC=DomainDnsZones,DC=leicester,DC=serco,DC=com
......................... SLGC-LRI-SVR-01 failed test NCSecDesc
Starting test: NetLogons
......................... SLGC-LRI-SVR-01 passed test NetLogons
Starting test: ObjectsReplicated
......................... SLGC-LRI-SVR-01 passed test
ObjectsReplicated
Starting test: Replications
......................... SLGC-LRI-SVR-01 passed test Replications
Starting test: RidManager
......................... SLGC-LRI-SVR-01 passed test RidManager
Starting test: Services
......................... SLGC-LRI-SVR-01 passed test Services
Starting test: SystemLog
An error event occurred. EventID: 0x00000456
Time Generated: 07/14/2010 13:05:40
Event String:
The processing of Group Policy failed. Windows could not determine if the user and computer accounts are in the same forest. Ensure the user domain name matches the name of a trusted domain that resides in the same forest as the computer account.
A warning event occurred. EventID: 0x8000001D
Time Generated: 07/14/2010 13:08:39
Event String:
The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 13:08:50
Event String:
Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:16:01
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:16:05
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:16:47
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:16:51
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:17:31
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:17:35
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x00000420
Time Generated: 07/14/2010 13:18:01
Event String:
The DHCP service has detected that it is running on a DC and has no credentials configured for use with Dynamic DNS registrations initiated by the DHCP service. This is not a recommended security configuration. Credentials for Dynamic DNS registrations may be configured using the command line "netsh dhcp server set dnscredentials" or via the DHCP Administrative tool.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:18:05
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x80000431
Time Generated: 07/14/2010 13:18:32
Event String:
The attempt by user LEICESTER\administrator to restart/shutdown computer SLGC-LRI-SVR-01 failed
A warning event occurred. EventID: 0x8000001D
Time Generated: 07/14/2010 13:21:30
Event String:
The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 13:21:41
Event String:
Name resolution for the name _ldap._tcp.dc._msdcs.leicester.serco.com timed out after none of the configured DNS servers responded.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:22:03
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
A warning event occurred. EventID: 0x000727AA
Time Generated: 07/14/2010 13:24:09
Event String:
The WinRM service failed to create the following SPNs: WSMAN/slgc-lri-svr-01.leicester.serco.com; WSMAN/slgc-lri-svr-01.
A warning event occurred. EventID: 0x8000001D
Time Generated: 07/14/2010 13:41:27
Event String:
The Key Distribution Center (KDC) cannot find a suitable certificate to use for smart card logons, or the KDC certificate could not be verified. Smart card logon may not function correctly if this problem is not resolved. To correct this problem, either verify the existing KDC certificate using certutil.exe or enroll for a new KDC certificate.
A warning event occurred. EventID: 0x00000C18
Time Generated: 07/14/2010 13:41:36
Event String:
The primary Domain Controller for this domain could not be located.
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 13:41:44
Event String:
Name resolution for the name slgc-lri-svr-01.leicester.serco.com timed out after none of the configured DNS servers responded.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:41:55
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
A warning event occurred. EventID: 0x000003F6
Time Generated: 07/14/2010 13:42:15
Event String:
Name resolution for the name leicester.serco.com timed out after none of the configured DNS servers responded.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:42:22
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:42:49
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:43:16
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:43:43
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:44:10
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:44:37
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:45:04
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
A warning event occurred. EventID: 0x00002724
Time Generated: 07/14/2010 13:45:15
Event String:
This computer has at least one dynamically assigned IPv6 address.For reliable DHCPv6 server operation, you should use only static IPv6 addresses.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:45:31
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 13:45:34
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
A warning event occurred. EventID: 0x00000081
Time Generated: 07/14/2010 13:45:35
Event String:
NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)
An error event occurred. EventID: 0x00000423
Time Generated: 07/14/2010 13:45:39
Event String:
The DHCP service failed to see a directory server for authorization.
An error event occurred. EventID: 0x00000423
Time Generated: 07/14/2010 13:45:52
Event String:
The DHCP service failed to see a directory server for authorization.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:45:58
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
An error event occurred. EventID: 0xC00038D6
Time Generated: 07/14/2010 13:46:25
Event String:
The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.
A warning event occurred. EventID: 0x00001695
Time Generated: 07/14/2010 13:47:29
Event String:
Dynamic registration or deletion of one or more DNS records associated with DNS domain 'leicester.serco.com.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).
A warning event occurred. EventID: 0x000727AA
Time Generated: 07/14/2010 13:47:36
Event String:
The WinRM service failed to create the following SPNs: WSMAN/slgc-lri-svr-01.leicester.serco.com; WSMAN/slgc-lri-svr-01.
An error event occurred. EventID: 0x0000168E
Time Generated: 07/14/2010 13:56:15
Event String:
The dynamic registration of the DNS record '_kerberos._tcp.dc._msdcs.leicester.serco.com. 600 IN SRV 0 100 88 slgc-lri-svr-01.leicester.serco.com.' failed on the following DNS server:
A warning event occurred. EventID: 0x00001695
Time Generated: 07/14/2010 13:56:15
Event String:
Dynamic registration or deletion of one or more DNS records associated with DNS domain 'leicester.serco.com.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).
A warning event occurred. EventID: 0x00001695
Time Generated: 07/14/2010 13:56:15
Event String:
Dynamic registration or deletion of one or more DNS records associated with DNS domain 'ForestDnsZones.leicester.serco.com.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).
A warning event occurred. EventID: 0x00001695
Time Generated: 07/14/2010 13:56:15
Event String:
Dynamic registration or deletion of one or more DNS records associated with DNS domain 'DomainDnsZones.leicester.serco.com.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).
......................... SLGC-LRI-SVR-01 failed test SystemLog
Starting test: VerifyReferences
......................... SLGC-LRI-SVR-01 passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Running partition tests on : DomainDnsZones
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Running partition tests on : Schema
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Running partition tests on : Configuration
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Running partition tests on : leicester
Starting test: CheckSDRefDom
......................... leicester passed test CheckSDRefDom
Starting test: CrossRefValidation
......................... leicester passed test CrossRefValidation
Running enterprise tests on : leicester.serco.com
Starting test: LocatorCheck
......................... leicester.serco.com passed test LocatorCheck
Starting test: Intersite
......................... leicester.serco.com passed test Intersite
I feel like I’m missing something here, I’ve spent 4 days trying to get this working and I’ve tried all sorts of stuff – too much to list. I’m open to any suggestions and will try anything. I’m not sure if the problem lies with the DNS settings somewhere, the AD config or the IP settings on the new server.
I’m sort of assuming the problem may lie somewhere with AD as like I say at the very beginning I believe I got it all working in the first place. The new server was most certainly pointing to itself for DNS at the very least, however I can’t confirm whether I got the 4013 errors or dcdiag errors as being totally honest this my first server migration and I wasn’t aware of the tools available – it’s only since I’ve had problems that I’m truly learning all about AD/DNS.
I’m really stuck – help me?!