How do I create an additional domain controller primary domain controller?

Noel Pereira

2008-02-02 13:26:01 UTC

Permalink

Dear Meinolf,

Following error is appearing while seizing the roles.
"
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8

Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.) "

Please note that Primary Domain controller is no more Available and all the
systems are managing by Additional Domain Controller only. Please advise .


Regards

Abdul Rahuman.M


Hello Noel,
http://support.microsoft.com/kb/255504/en-us
Also make it a Global catalog server and DNS server, if not already done
before.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Sir,
Our Domain "SevenSeasgroup.co.ae" had two domain
controller .one
is Primary domain controller and other one is additional domain controller. A
week before primary domain controller was down(Operating System
corrupted) and it is inactive.Now we are managing all the users and
computers with additional domain controller and facing lot of problems
without primary domain controller. Please tell me the procedures to
promote this additional domain controller to Primary Domain
controller.
Regards
Abdul Rahuman.M

Meinolf Weber

2008-02-02 13:36:58 UTC

Permalink

Hello Noel,

Srcoll down in the document to the part SEIZE the FSMO roles.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Meinolf,
Following error is appearing while seizing the roles.
"
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.) "
Please note that Primary Domain controller is no more Available and
all the systems are managing by Additional Domain Controller only.
Please advise .
Regards
Abdul Rahuman.M


Hello Noel,
http://support.microsoft.com/kb/255504/en-us
Also make it a Global catalog server and DNS server, if not already
done before.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Sir,
Our Domain "SevenSeasgroup.co.ae" had two domain
controller .one
is Primary domain controller and other one is additional domain controller. A
week before primary domain controller was down(Operating System
corrupted) and it is inactive.Now we are managing all the users and
computers with additional domain controller and facing lot of problems
without primary domain controller. Please tell me the procedures to
promote this additional domain controller to Primary Domain
controller.
Regards
Abdul Rahuman.M

Meinolf Weber

2008-02-02 14:01:21 UTC

Permalink

Hello Noel,

Here is an article about it with more details what is shown during the seizing:
http://www.petri.co.il/seizing_fsmo_roles.htm

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Meinolf,
Following error is appearing while seizing the roles.
"
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.) "
Please note that Primary Domain controller is no more Available and
all the systems are managing by Additional Domain Controller only.
Please advise .
Regards
Abdul Rahuman.M


Hello Noel,
http://support.microsoft.com/kb/255504/en-us
Also make it a Global catalog server and DNS server, if not already
done before.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Sir,
Our Domain "SevenSeasgroup.co.ae" had two domain
controller .one
is Primary domain controller and other one is additional domain controller. A
week before primary domain controller was down(Operating System
corrupted) and it is inactive.Now we are managing all the users and
computers with additional domain controller and facing lot of problems
without primary domain controller. Please tell me the procedures to
promote this additional domain controller to Primary Domain
controller.
Regards
Abdul Rahuman.M

Meinolf Weber

2008-02-05 10:46:42 UTC

Permalink

Hello Noel,

The document also contains the Global catalog part.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i check
the roles are assigned to the Backup controller. And also please
advice me , how to make backup domain controller as global catalog
server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the failed DC
(http://support.microsoft.com/kb/255504), configuring the remaining
DC as Global Catalog and DNS server (this will likely require
repointing your clients to it as their primary), and cleaning up
any invalid metadata (http://support.microsoft.com/kb/216498)...
hth
Marcin

Noel Pereira

2008-02-05 11:44:02 UTC

Permalink

Ok. I have assigned FSMO roles to Backup Domain Controller. Please tell me ,
where can i go and check these roles were assigned properly.


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i check
the roles are assigned to the Backup controller. And also please
advice me , how to make backup domain controller as global catalog
server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the failed DC
(http://support.microsoft.com/kb/255504), configuring the remaining
DC as Global Catalog and DNS server (this will likely require
repointing your clients to it as their primary), and cleaning up
any invalid metadata (http://support.microsoft.com/kb/216498)...
hth
Marcin

Noel Pereira

2008-02-06 12:08:01 UTC

Permalink

Hello Meinolf,

Thanks for your king Cooperation. I have promoted Backup Domain
controller to PDC by seizing all five roles. Now while working on users and
computers ,When i attmept to display members of any security group , i got
the following error.

" A global catalog cannot be located to retrieve the icons
for the member list"

Then i configure this new PDC as global catalog server.After
that i am not getting any error when working on the "Active Directory users
and computers" Kindly advice me, is there any problem configuring 'global
catalog server' and 'infrastructure master' on the same Domain Controller ?.
what are the impacts will happen ? and please advice me how to solve this
issue ?


Regards

Abdul Rahuman


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i check
the roles are assigned to the Backup controller. And also please
advice me , how to make backup domain controller as global catalog
server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation failed. The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the failed DC
(http://support.microsoft.com/kb/255504), configuring the remaining
DC as Global Catalog and DNS server (this will likely require
repointing your clients to it as their primary), and cleaning up
any invalid metadata (http://support.microsoft.com/kb/216498)...
hth
Marcin

Meinolf Weber

2008-02-06 12:27:56 UTC

Permalink

Hello Noel,

No impact, if you have a single forest, single domain environment like you
have.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your king Cooperation. I have promoted Backup
Domain controller to PDC by seizing all five roles. Now while working
on users and computers ,When i attmept to display members of any
security group , i got the following error.
" A global catalog cannot be located to retrieve the
icons for the member list"
Then i configure this new PDC as global catalog
server.After that i am not getting any error when working on the
"Active Directory users and computers" Kindly advice me, is there any
problem configuring 'global catalog server' and 'infrastructure
master' on the same Domain Controller ?. what are the impacts will
happen ? and please advice me how to solve this issue ?
Regards
Abdul Rahuman


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i
check the roles are assigned to the Backup controller. And also
please advice me , how to make backup domain controller as global
catalog server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation
failed.
The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the failed
DC (http://support.microsoft.com/kb/255504), configuring the
remaining DC as Global Catalog and DNS server (this will likely
require repointing your clients to it as their primary), and
cleaning up any invalid metadata
(http://support.microsoft.com/kb/216498)...
hth
Marcin

Noel Pereira

2008-02-06 12:59:02 UTC

Permalink

Hello Meinolf,

Thanks for your advice. Now i have promoted a Backup
Domain Controller for this new PDC . After this operation, i cant able to
open anything in Active Directory on BDC.I am getting the following error
when i open "Active Directory Users and Computers" in BDC.

" Naming Information cannot be located because: The
Specified domain either does not exist or could not be contacted. ".

Please help me to make new Backup domain Controller in operational.


Regards

Abdul Rahuman.M
Tel:8033-306


Hello Noel,
No impact, if you have a single forest, single domain environment like you
have.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your king Cooperation. I have promoted Backup
Domain controller to PDC by seizing all five roles. Now while working
on users and computers ,When i attmept to display members of any
security group , i got the following error.
" A global catalog cannot be located to retrieve the
icons for the member list"
Then i configure this new PDC as global catalog
server.After that i am not getting any error when working on the
"Active Directory users and computers" Kindly advice me, is there any
problem configuring 'global catalog server' and 'infrastructure
master' on the same Domain Controller ?. what are the impacts will
happen ? and please advice me how to solve this issue ?
Regards
Abdul Rahuman


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i
check the roles are assigned to the Backup controller. And also
please advice me , how to make backup domain controller as global
catalog server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation
failed.
The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the failed
DC (http://support.microsoft.com/kb/255504), configuring the
remaining DC as Global Catalog and DNS server (this will likely
require repointing your clients to it as their primary), and
cleaning up any invalid metadata
(http://support.microsoft.com/kb/216498)...
hth
Marcin

Meinolf Weber

2008-02-06 13:06:31 UTC

Permalink

Hello Noel,

Just one note before. Since windows 2000 there are no longer the terms PDC/BDC,
all Dc's are the same, the differences are in the FSMO roles.

Did you run dcdiag and netdiag before starting with the new server on the
old machine to see that everything is ok and without errors?

Please describe the steps you have taken to promote the new machine. Also
post an ipconfig /all from both machines.


Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your advice. Now i have promoted a Backup
Domain Controller for this new PDC . After this operation, i cant able
to open anything in Active Directory on BDC.I am getting the following
error when i open "Active Directory Users and Computers" in BDC.
" Naming Information cannot be located because: The
Specified domain either does not exist or could not be contacted. ".
Please help me to make new Backup domain Controller in operational.
Regards
Abdul Rahuman.M
Tel:8033-306


Hello Noel,
No impact, if you have a single forest, single domain environment
like you have.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your king Cooperation. I have promoted Backup
Domain controller to PDC by seizing all five roles. Now while working
on users and computers ,When i attmept to display members of any
security group , i got the following error.
" A global catalog cannot be located to retrieve the icons for the
member list"
Then i configure this new PDC as global catalog
server.After that i am not getting any error when working on the
"Active Directory users and computers" Kindly advice me, is there any
problem configuring 'global catalog server' and 'infrastructure
master' on the same Domain Controller ?. what are the impacts will
happen ? and please advice me how to solve this issue ?
Regards
Abdul Rahuman


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i
check the roles are assigned to the Backup controller. And also
please advice me , how to make backup domain controller as global
catalog server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362, problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation
failed.
The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the
failed DC (http://support.microsoft.com/kb/255504), configuring
the remaining DC as Global Catalog and DNS server (this will
likely require repointing your clients to it as their primary),
and cleaning up any invalid metadata
(http://support.microsoft.com/kb/216498)...
hth
Marcin

Noel Pereira

2008-02-13 12:26:04 UTC

Permalink

Hello Meinolf,

Backup Domain Controller is done and i can open the
Active Directory. The Problem now is , What ever the modification i m doing
in the Primary Domain controller is not replicating in Backup Domain
Controller. So i planned to demote the BDC and Promote Again. When i start
Demoting , i could see a error message
" A Domain Controller could not be contacted for the domain
SevenSeasgroup.co.ae that contained an account for this Computer".

Please let me know what is this error ? Why the modification is not
replicating?

Regards

Abdul rahuman.M


Hello Noel,
Just one note before. Since windows 2000 there are no longer the terms PDC/BDC,
all Dc's are the same, the differences are in the FSMO roles.
Did you run dcdiag and netdiag before starting with the new server on the
old machine to see that everything is ok and without errors?
Please describe the steps you have taken to promote the new machine. Also
post an ipconfig /all from both machines.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your advice. Now i have promoted a Backup
Domain Controller for this new PDC . After this operation, i cant able
to open anything in Active Directory on BDC.I am getting the following
error when i open "Active Directory Users and Computers" in BDC.
" Naming Information cannot be located because: The
Specified domain either does not exist or could not be contacted. ".
Please help me to make new Backup domain Controller in operational.
Regards
Abdul Rahuman.M
Tel:8033-306


Hello Noel,
No impact, if you have a single forest, single domain environment
like you have.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your king Cooperation. I have promoted Backup
Domain controller to PDC by seizing all five roles. Now while working
on users and computers ,When i attmept to display members of any
security group , i got the following error.
" A global catalog cannot be located to retrieve the icons for the
member list"
Then i configure this new PDC as global catalog
server.After that i am not getting any error when working on the
"Active Directory users and computers" Kindly advice me, is there any
problem configuring 'global catalog server' and 'infrastructure
master' on the same Domain Controller ?. what are the impacts will
happen ? and please advice me how to solve this issue ?
Regards
Abdul Rahuman


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the FSMO
roles to the BackupDomain Controller. Please tell me , how can i
check the roles are assigned to the Backup controller. And also
please advice me , how to make backup domain controller as global
catalog server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
Ldap extended error message is 000020AF: SvcErr: DSID-03210362,
problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation
failed.
The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the
failed DC (http://support.microsoft.com/kb/255504), configuring
the remaining DC as Global Catalog and DNS server (this will
likely require repointing your clients to it as their primary),
and cleaning up any invalid metadata
(http://support.microsoft.com/kb/216498)...
hth
Marcin

Meinolf Weber

2008-02-13 12:54:58 UTC

Permalink

Hello Noel,

Do not demote in the moment. let's try to find your problem. As ia sked BEFORE:

Did you run dcdiag and netdiag before starting with the new server on the
old machine to see that everything is ok and without errors?

Please describe the steps you have taken to promote the new machine. Also
post an ipconfig /all from both machines.



Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Backup Domain Controller is done and i can open the
Active Directory. The Problem now is , What ever the modification i m doing
in the Primary Domain controller is not replicating in Backup Domain
Controller. So i planned to demote the BDC and Promote Again. When i start
Demoting , i could see a error message
" A Domain Controller could not be contacted for the domain
SevenSeasgroup.co.ae that contained an account for this Computer".
Please let me know what is this error ? Why the modification is not
replicating?
Regards
Abdul rahuman.M


Hello Noel,
Just one note before. Since windows 2000 there are no longer the
terms PDC/BDC, all Dc's are the same, the differences are in the FSMO
roles.
Did you run dcdiag and netdiag before starting with the new server on
the old machine to see that everything is ok and without errors?
Please describe the steps you have taken to promote the new machine.
Also post an ipconfig /all from both machines.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your advice. Now i have promoted a Backup
Domain Controller for this new PDC . After this operation, i cant able
to open anything in Active Directory on BDC.I am getting the
following
error when i open "Active Directory Users and Computers" in BDC.
" Naming Information cannot be located because: The Specified domain
either does not exist or could not be contacted. ".
Please help me to make new Backup domain Controller in operational.
Regards
Abdul Rahuman.M
Tel:8033-306


Hello Noel,
No impact, if you have a single forest, single domain environment
like you have.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,
Thanks for your king Cooperation. I have promoted Backup
Domain controller to PDC by seizing all five roles. Now while working
on users and computers ,When i attmept to display members of any
security group , i got the following error.
" A global catalog cannot be located to retrieve the icons for the
member list"
Then i configure this new PDC as global catalog
server.After that i am not getting any error when working on the
"Active Directory users and computers" Kindly advice me, is there any
problem configuring 'global catalog server' and 'infrastructure
master' on the same Domain Controller ?. what are the impacts will
happen ? and please advice me how to solve this issue ?
Regards
Abdul Rahuman


Hello Noel,
The document also contains the Global catalog part.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!!
http://www.blakjak.demon.co.uk/mul_crss.htm


Dear Marcin,
According to this microsoft Article
http://support.microsoft.com/kb/255504/en-us , i move all the
FSMO roles to the BackupDomain Controller. Please tell me , how
can i check the roles are assigned to the Backup controller. And
also please advice me , how to make backup domain controller as
global catalog server.
Regards
Abdul Rahuman.M


How are you trying to move the FSMO roles ?


Dear Marcin,
Following are the error when attempting to seize the roles.
Attempting safe transfer of domain naming FSMO before seizure.
ldap_modify_sW error 0x34(52 (Unavailable).
DSID-03210362,
problem 5002
(UN
AVAILABLE), data 8
Win32 error returned is 0x20af(The requested FSMO operation
failed.
The
current
FSMO holder could not be contacted.)
Please advice.
Regards
Abdul Rahuman.M


Start by seizing the FSMO roles that were assigned to the
failed DC (http://support.microsoft.com/kb/255504),
configuring the remaining DC as Global Catalog and DNS server
(this will likely require repointing your clients to it as
their primary), and cleaning up any invalid metadata
(http://support.microsoft.com/kb/216498)...
hth
Marcin

Can you have more than one primary domain controller?

Only one primary DC can be designated. According to security and reliability best practices, the server housing the primary DC should be solely dedicated to domain services.

How to add domain controller in an existing domain controller?

On the Deployment configuration page, select "Add Domain controller to an existing domain" . You need to specify the name of the domain in which the new DC will be added. The "Domain controller options" page appears next. Options to make this DC a DNS server and a Global Catalog are selected by default.

Can I have 2 domain controllers on the same domain?

Actually, In a larger environment, at least two domain controllers at each physical site should be DNS servers. This provides redundancy in the event that one DC goes offline unexpectedly. Note that domain-joined machines must be configured to use multiple DNS servers in order to take advantage of this.

What is an additional domain controller?

What Is A Domain Controller? A Domain Controller is found in a Windows Server domain. A DC is responsible for responding to requests for security authentication. Located in a Windows NT or Microsoft Windows network, the DC server is responsible for letting hosts access various domain resources in the Windows system.