G
Gary Roach
I'm trying to upgrade a couple of domain controllers that were running NT
4.0. both were in the same domain - one was a pdc, one a bdc. i upgraded the
pdc to windows server 2003 without incident. however, when i upgraded the
bdc and specified in the active directory installation wizard that it was to
be a second domain controller in an existing domain, it seemed to work
properly except that when it rebooted for the final time and tried to boot
up, i got the following:
lsass.exe
Security Accounts Manager initialization failed because of the following
error: The specified domain either does not exist or could not be contacted.
Error Status: 0xc00000df. Please click OK to shutdown this system and reboot
into Domain Services Restore Mode, check the event log for more detailed
information.
I rebooted into DSRM and checked the event log and found nothing much of
interest in the old bdc machine, but i found the following in the upgraded
pdc:
The computer BDC tried to connect to the server PDC using the trust
relationship established by the NTDOMAIN domain. However, the computer lost
the correct security identifier (SID) when the domain was reconfigured.
Reestablish the trust relationship.
This SID must have been lost when the bdc was upgraded because after the pdc
was upgraded the bdc worked find and i could run service manager on it and
see both machines. now my question is: how do i reestablish the trust
relationship? i tried demoting the bdc machine using dcpromo but it told me
i couldn't run it from DSRM. i can't boot into normal mode because i keep
getting the original error message. i looked at the "computer name" page of
the system properties to see if i could rejoin the domain that way but the
domain is listed as "unknown" and both it and the computer name are greyed
out. what do i do?
thanks for any help
4.0. both were in the same domain - one was a pdc, one a bdc. i upgraded the
pdc to windows server 2003 without incident. however, when i upgraded the
bdc and specified in the active directory installation wizard that it was to
be a second domain controller in an existing domain, it seemed to work
properly except that when it rebooted for the final time and tried to boot
up, i got the following:
lsass.exe
Security Accounts Manager initialization failed because of the following
error: The specified domain either does not exist or could not be contacted.
Error Status: 0xc00000df. Please click OK to shutdown this system and reboot
into Domain Services Restore Mode, check the event log for more detailed
information.
I rebooted into DSRM and checked the event log and found nothing much of
interest in the old bdc machine, but i found the following in the upgraded
pdc:
The computer BDC tried to connect to the server PDC using the trust
relationship established by the NTDOMAIN domain. However, the computer lost
the correct security identifier (SID) when the domain was reconfigured.
Reestablish the trust relationship.
This SID must have been lost when the bdc was upgraded because after the pdc
was upgraded the bdc worked find and i could run service manager on it and
see both machines. now my question is: how do i reestablish the trust
relationship? i tried demoting the bdc machine using dcpromo but it told me
i couldn't run it from DSRM. i can't boot into normal mode because i keep
getting the original error message. i looked at the "computer name" page of
the system properties to see if i could rejoin the domain that way but the
domain is listed as "unknown" and both it and the computer name are greyed
out. what do i do?
thanks for any help