Promoted Windows 2003 DC can´t authenticate computers

  • Thread starter Thread starter Dan Pinheiro
  • Start date Start date
D

Dan Pinheiro

Server A: DC windows 2003 Standard English (No service pack and hotfixes)
Server B: Member server Windows 2003 Enterprise Edition Portuguese (Brazil)
promoted to DC (SP 1 installed. No hotfixes)
Domain Functional Level --> Mixed Windows 2000
Forest Functional Level --> Windows 2000

The need is deactivate the Server A and activate Server B as DC.

Before promote server B to DC, I refined all errors in server A, then
executed Netdiag, DCdiag, various tests were done and no errors returned.
Promoted Server B to DC, defined the primary DNS to itself, transferred all
FSMO roles via ntdsutil from server A, set as GC, again executed various
tests with dcdiag, netdiag, replmon, nslookup. Replication validated. Both
servers works fine. W32 Time seems to works fine too. No errors in both
servers event logs and clients authenticating correctly (confirmed through
logon audit).
The problem appears when I make Server A offline.
During Server B reboot, the message "preparing network connections" delays
for 05 min. When finally the server loads, the events 40961 and 40962 are
logged (http://support.microsoft.com/kb/82371). I defined in
the Registry the Netlogon and W32time services as dependents of DNS service,
but the error continues.
When I set the primary dns in the client to Server B and try to logon, show
message about error with computer account. Event 5722 is logged in the
server, about problems with the secure channel between client and the server
(same error with netdom). If I do logon using client local credentials, and
try to access server share, the
window login request is showed and I can access the shares normally after
put the domain login and password. I also can remove and rejoin the client
from domain, but after the reboot the same error occurs.
Enough turn on Server A to everything works fine, including computer
authentication in server B.
It seems that Server B depends on some resource/service from Server A, but
i can´t identify!!
Any idea? Did I forget something?
Tks a lot

Dan Pinheiro
Rio de Janeiro - Brasil.
 
Before promote the Server B, I installled the DNS service (no zones
defined). After DCpromo the domain zones were replicated automatically. All
zones are AD integrated.
Tks.

Dan Pinheiro
Rio de Janeiro - Brasil
 
Hi
If the File Replication Service tries to authenticate before the directory
service has started, you will receive these events.If Active Directory
starts successfully, you should ignore these Event IDs. If they continue to
appear on subsequent restarts, you will have to troubleshoot the directory
service.

run
netdiag /fix

Check errors in:
netdiag /debug
dcdiag /test:dns /v





I Hop that helps

Best Regards
Systems Administrator
MCSA + Exchange
 
Back
Top