Urgent Case for serious error after promo dc 2008 in ad 2003


dear all,

  have 2 windows 2003 dc (p1, p2) in 2 site (hv , st). has network connection between 2 sites. add 1 more windows server 2008 in hv site , promoted domain controller today. however, after promoted came out few serious error , warning. please find below dcdiag log. please kindly give ideas..it urgent.

many thanks

best regards,

elroy


directory server diagnosis


performing initial setup:

   trying find home server...

   home server = pdndc1

   * identified ad forest. 
   done gathering initial info.


doing initial required tests

   
   testing server: default-first-site-name\pdndc1

      starting test: connectivity

         ......................... pdndc1 passed test connectivity



doing primary tests

   
   testing server: default-first-site-name\pdndc1

      starting test: advertising

         ......................... pdndc1 passed test advertising

      starting test: frsevent

         there warning or error events within last 24 hours after the

         sysvol has been shared.  failing sysvol replication problems may cause

         group policy problems. 
         ......................... pdndc1 passed test frsevent

      starting test: dfsrevent

         ......................... pdndc1 passed test dfsrevent

      starting test: sysvolcheck

         ......................... pdndc1 passed test sysvolcheck

      starting test: kccevent

         ......................... pdndc1 passed test kccevent

      starting test: knowsofroleholders

         ......................... pdndc1 passed test knowsofroleholders

      starting test: machineaccount

         ......................... pdndc1 passed test machineaccount

      starting test: ncsecdesc

         ......................... pdndc1 passed test ncsecdesc

      starting test: netlogons

         [pdndc1] user credentials not have permission perform this

         operation.

         the account used test must have network logon privileges

         for machine's domain.

         ......................... pdndc1 failed test netlogons

      starting test: objectsreplicated

         ......................... pdndc1 passed test objectsreplicated

      starting test: replications

         replication latency warning

         error: expected notification link missing.

         source pdndc02

         replication of new changes along path delayed.

         this problem should self-correct on next periodic sync.

         replication latency warning

         error: expected notification link missing.

         source pdndc02

         replication of new changes along path delayed.

         this problem should self-correct on next periodic sync.

         replication latency warning

         error: expected notification link missing.

         source pdndc02

         replication of new changes along path delayed.

         this problem should self-correct on next periodic sync.

         replication latency warning

         error: expected notification link missing.

         source pdndc02

         replication of new changes along path delayed.

         this problem should self-correct on next periodic sync.

         [replications check,pdndc1] dsreplicagetinfo(pending_ops, null)

         failed, error 0x2105 "replication access denied."

         ......................... pdndc1 failed test replications

      starting test: ridmanager

         ......................... pdndc1 passed test ridmanager

      starting test: services

         ......................... pdndc1 passed test services

      starting test: systemlog

         an error event occurred.  eventid: 0x0000168f

            time generated: 06/13/2013   17:08:14

            event string:

            dynamic deletion of dns record 'domaindnszones.pdn.ccms. 600 in 192.168.211.2' failed on following dns server:  


         an error event occurred.  eventid: 0x0000168f

            time generated: 06/13/2013   17:08:14

            event string:

            dynamic deletion of dns record '_ldap._tcp.domaindnszones.pdn.ccms. 600 in srv 0 100 389 pdndc1.pdn.ccms.' failed on following dns server:  


         an error event occurred.  eventid: 0x0000168f

            time generated: 06/13/2013   17:08:14

            event string:

            dynamic deletion of dns record '_ldap._tcp.default-first-site-name._sites.domaindnszones.pdn.ccms. 600 in srv 0 100 389 pdndc1.pdn.ccms.' failed on following dns server:  


         an error event occurred.  eventid: 0x0000168f

            time generated: 06/13/2013   17:08:14

            event string:

            dynamic deletion of dns record 'forestdnszones.pdn.ccms. 600 in 192.168.211.2' failed on following dns server:  


         an error event occurred.  eventid: 0x0000168f

            time generated: 06/13/2013   17:08:14

            event string:

            dynamic deletion of dns record '_ldap._tcp.forestdnszones.pdn.ccms. 600 in srv 0 100 389 pdndc1.pdn.ccms.' failed on following dns server:  


         an error event occurred.  eventid: 0x0000168f

            time generated: 06/13/2013   17:08:14

            event string:

            dynamic deletion of dns record '_ldap._tcp.default-first-site-name._sites.forestdnszones.pdn.ccms. 600 in srv 0 100 389 pdndc1.pdn.ccms.' failed on following dns server:  


         a warning event occurred.  eventid: 0x000003f6

            time generated: 06/13/2013   17:11:58

            event string:

            name resolution name www.msftncsi.com timed out after none of configured dns servers responded.

         a warning event occurred.  eventid: 0x8000001d

            time generated: 06/13/2013   17:28:41

            event string:

            key distribution center (kdc) cannot find suitable certificate use smart card logons, or kdc certificate not verified. smart card logon may not function correctly if problem not resolved. correct problem, either verify existing kdc certificate using certutil.exe or enroll new kdc certificate.

         a warning event occurred.  eventid: 0x80001421

            time generated: 06/13/2013   17:28:57

            event string:

            windows process activation service (was) encountered error attempting built in iis_iusrs group.  there may problems in viewing , setting security permissions iis_iusrs group.  this happens if machine has been joined , promoted domain controller in legacy domain.  please see online more information , solutions problem.  the data field contains error number.

         a warning event occurred.  eventid: 0x000003f6

            time generated: 06/13/2013   17:29:35

            event string:

            name resolution name www.msftncsi.com timed out after none of configured dns servers responded.

         a warning event occurred.  eventid: 0x000727aa

            time generated: 06/13/2013   17:31:19

            event string:

            winrm service failed create following spns: wsman/pdndc1.pdn.ccms; wsman/pdndc1. 


         a warning event occurred.  eventid: 0x00001695

            time generated: 06/13/2013   17:43:48

            event string:

            dynamic registration or deletion of 1 or more dns records associated dns domain 'domaindnszones.pdn.ccms.' failed.  these records used other computers locate server domain controller (if specified domain active directory domain) or ldap server (if specified domain application partition).  


         a warning event occurred.  eventid: 0x00001695

            time generated: 06/13/2013   17:43:48

            event string:

            dynamic registration or deletion of 1 or more dns records associated dns domain 'forestdnszones.pdn.ccms.' failed.  these records used other computers locate server domain controller (if specified domain active directory domain) or ldap server (if specified domain application partition).  


         a warning event occurred.  eventid: 0x00001695

            time generated: 06/13/2013   17:43:48

            event string:

            dynamic registration or deletion of 1 or more dns records associated dns domain 'pdn.ccms.' failed.  these records used other computers locate server domain controller (if specified domain active directory domain) or ldap server (if specified domain application partition).  


         ......................... pdndc1 failed test systemlog

      starting test: verifyreferences

         ......................... pdndc1 passed test verifyreferences

   
   
   running partition tests on : forestdnszones

      starting test: checksdrefdom

         ......................... forestdnszones passed test checksdrefdom

      starting test: crossrefvalidation

         ......................... forestdnszones passed test

         crossrefvalidation

   
   running partition tests on : domaindnszones

      starting test: checksdrefdom

         ......................... domaindnszones passed test checksdrefdom

      starting test: crossrefvalidation

         ......................... domaindnszones passed test

         crossrefvalidation

   
   running partition tests on : schema

      starting test: checksdrefdom

         ......................... schema passed test checksdrefdom

      starting test: crossrefvalidation

         ......................... schema passed test crossrefvalidation

   
   running partition tests on : configuration

      starting test: checksdrefdom

         ......................... configuration passed test checksdrefdom

      starting test: crossrefvalidation

         ......................... configuration passed test crossrefvalidation

   
   running partition tests on : pdn

      starting test: checksdrefdom

         ......................... pdn passed test checksdrefdom

      starting test: crossrefvalidation

         ......................... pdn passed test crossrefvalidation

   
   running enterprise tests on : pdn.ccms

      starting test: locatorcheck

         ......................... pdn.ccms passed test locatorcheck

      starting test: intersite

         ......................... pdn.ccms passed test intersite

yes, run right after wait 24 hours , many of errors false positives.

--
paul bergson
mvp - directory services
mcitp: enterprise administrator
mcts, mct, mcse, mcsa, security+, bs csci
2008, vista, 2003, 2000 (early achiever), nt4
twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson

please no e-mails, questions should posted in newsgroup. posting provided "as is" no warranties, , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...