Documente Academic
Documente Profesional
Documente Cultură
After you promote a Windows 2000 Server computer to act as a domain controller, you may experience the following issues:
The computer account for the new domain controller does appear in the Domain Controllers container when you open that container from another domain controller. However, it may be listed in the Domain Controllers container when you viewed it using its own Active Directory Users and Computers snap-in.
When you right-click My Computer, click Properties, and then click the Network Identification tab, the following text is not displayed: Note: The identification of the computer cannot be changed because: - The computer is a domain controller.
If you run the Repadmin.exe utility (that is available in the Windows 2000 Support Tools) with the /showreps switch, you receive the following output:
==== INBOUND NEIGHBORS ====================================== CN=Schema,CN=Configuration,DC=example,DC=com CN=Configuration,DC=example,DC=com Site-Name\Server1 via RPC 63 consecutive failure(s). Last success @ <date> <time>. Replication access was denied. Last attempt @ <date> <time> failed, result 8453: objectGuid: 0d519219-b957-4a80-9d39-ec4d51e2181e Site-Name\Server1 via RPC
DC=example,DC=com 64 consecutive failure(s). Last success @ <date> <time>. Replication access was denied. Last attempt @ <date> <time> failed, result 8453: objectGuid: 0d519219-b957-4a80-9d39-ec4d51e2181e Site-Name\Server1 via RPC 64 consecutive failure(s). Last success @ <date> <time>. Replication access was denied. Last attempt @ <date> <time> failed, result 8453: objectGuid: 0d519219-b957-4a80-9d39-ec4d51e2181e
If you run the Active Directory Replication Monitor utility (Replmon.exe) (that is available in the Windows 2000 Support Tools), you receive the following output:
Server2
CN=Schema,CN=Configuration,DC=example,DC=com
Site-Name\Server1
8453
Failure Reason:
Domain Controller Name: Domain Controller Name: Failure Reason: Failure Code: Replication Partner: Directory Partition: Failure Reason: Failure Code: Replication Partner: Directory Partition:
Server2
CN=Configuration,DC=example,DC=com
Site-Name\Server1
8453
Server2
DC=mvlp,DC=local
Site-Name\Server1
8453
If you run the DCdiag.exe utility (that is available in the Windows 2000 Support Tools), you receive a "Replication access was denied" message. If you run the Netdiag.exe utility, you receive the following output:
[ERROR_NO_TRUST_SAM_ACCOUNT]
These issues may occur if the computer account is not updated correctly during the domain controller promotion procedure (Dcpromo). Back to the top RESOLUTION
301423 How to Install the Windows 2000 Support Tools to a Windows 2000 Server-Based Computer 2. Start the ADSI Edit snap-in. To do so, click Start, point to Programs, point to Windows 2000 Support Tools, point to Tools, and then click ADSI Edit. 3. Expand Domain NC [server.example.com] (where server is the name of the domain controller and example.com is the name of the domain. 4. 5. Expand DC=example,DC=com. Expand OU=Domain Controllers, right-click CN=ServerName (where ServerName is the domain controller with which you experience the issues that are described in the "Symptoms" section of this article), and then click Properties. 6. 7. Click the Attributes tab (if it is not already selected). In the Select which properties to view list, click Both, and then click userAccountControl in the Select a property to view list. 8. 9. If the Value(s) box does not contain 532480, type 532480 in the Edit Attribute box, and then click Set. Click Apply, click OK, and then quit the ADSI Edit snap-in.