Global Catalogs not available

  • Thread starter Thread starter Ash Ridley
  • Start date Start date
A

Ash Ridley

Hi all,

Got a bit of a nightmare on my hands and I cant seem to fix it

We've run ADPrep to add a 2k3 server to my existing 2k domain and it went a
bit sour.

Unfortunately I've had to pick up this problem from a Junior so the details
are (unfortunately) a bit sketchy.

After running ADPrep none of the users could not log in (apparently the GC
couldnt be contacted) so he decided to demote the server to remove AD and
then install it back in again.

Needless to say that this didnt work (presumably because the problem had
spread to the other DC).

At this point I got pulled in and decided to do an authorative restore from
backup...which didnt cure the problem either.

I have identified several key problems, the main ones being that there is
currently no domain naming or schema master set (the other FSMOs roles are
fine) - unfortunately I am unable to seize these roles, the error is that I
dont have permission to do so and on further investigation the problem
appears to be that because a GC cannot be contacted (both DC's are set to be
GC's) the system cannot validate that the account I am using is a member of
enterprise admins (a GC error is generated when you go to view the Ent Admin
group membership)

The other obvious problem is that I have a ghost entry in AD sites and
services, it has the same name as my FSMO master DC (with a load of extra
characters on the end) and I am unable to remove it (which does not appear
in ADSIEdit)

I have managed to get users back on the system by disabling GC error
checking in the registry on both DC's (one of the few times I have been
thankful we use Lotus Notes and not Exchange)

Does anyone have any suggestions?

Ash
 
Sounds like you are having a exciting day.
The only way to go back from a schema update is to either restore all DCs
from backup or restore one or more and the ones that are not restored must
removed.

The "ghost" entry is most likly the DEL:abunchofnumbers
This is the place holder for the deleted object and should be removed by the
system.
Check out to this article to verify the DC was removed fully.
216498 How To Remove Data in Active Directory After an Unsuccessful Domain
http://support.microsoft.com/?id=216498

The global catalog isn't quite as straight forward.
The first thing to find out is if this is the only domain in the forest.
You can use DCdiag to confirm that the machines are reporting to be a GC.
If they are I would begin checking DNS and ensure that each GC is
registering its GC records in DNS and that you can query those records.

Another option that I would only suggest in a single domain env. and will
not help if this is a DNS problem. Uncheck all GCs ensure that each reports
a 1110 event in the DS log and then select one machine as a GC. Let it
complete and display a 1119 event and then the others should have no
problems updating.
 
Back
Top