Win2003 Active Directory member server cannot find DC

anonym00se

Distinguished
Jul 31, 2011
5
0
18,510
hi all-

I have an AD issue that is driving me to bash my head against a wall.

We have a member server that is no longer listed in AD, but *is* a member according to its spec. However, it cannot find the single DC we have on the same LAN. So basically the DC thinks it is no longer a member and it cannot rejoin? As though it had been removed from Active Directory while offline, and now cannot reconnect or is blocked? a simple ping definitely verified DNS *is* working and it can physically contact the server, but AD services are unavailable or inaccessible?

Problem is, this is our Blackberry enterprise server.. so deleting and recreating the server is not an option. :(

I have run dcdiag and netdiag on the domain controller but I'm not clear on how to resolve the errors shown, since the DNS records *look* correct to me.. Any help is appreciated.




*******
NETDIAG
*******

Computer Name: EDMSERVER01
DNS Host Name: edmserver01.XYZ.local
System info : Microsoft Windows Server 2003 (Build 3790)
Processor : EM64T Family 6 Model 15 Stepping 8, GenuineIntel
List of installed hotfixes :
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : Local Area Connection

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : edmserver01
IP Address . . . . . . . . : 192.20.20.10
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.20.20.4
Dns Servers. . . . . . . . : 208.67.222.222


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
No names have been found.

WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{2236CEE3-8A1B-45F7-AABE-8AE05CE4C5C4}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the name
'edmserver01.XYZ.local.'. [RCODE_SERVER_FAILURE]
The name 'edmserver01.XYZ.local.' may not be registered in DNS.
[FATAL] Could not open file C:\WINDOWS\system32\config\netlogon.dns for reading.
[FATAL] No DNS servers have the DNS records for this DC registered.


Redir and Browser test . . . . . . : Failed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{2236CEE3-8A1B-45F7-AABE-8AE05CE4C5C4}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{2236CEE3-8A1B-45F7-AABE-8AE05CE4C5C4}
The browser is bound to 1 NetBt transport.
[FATAL] Cannot send mailslot message to 'XYZ*' via browser. [ERROR_INVALID_FUNCTION]


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Failed
[FATAL] Cannot lookup package Kerberos.
The error occurred was: (null)


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully

********************************************
********************************************
---
DCDIAG
---


Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site\EDMSERVER01
Starting test: Connectivity
The host ecda2438-0557-4b28-96b3-d7a864516de0._msdcs.XYZ.local could not be resolved to an
IP address. Check the DNS server, DHCP, server name, etc
Although the Guid DNS name (ecda2438-0557-4b28-96b3-d7a864516de0._msdcs.XYZ.local) couldn't be resolved, the

server name (edmserver01.XYZ.local) resolved to the IP address (192.20.20.10) and was pingable. Check that the IP address is

registered correctly with the DNS server.
......................... EDMSERVER01 failed test Connectivity

Doing primary tests

Testing server: Default-First-Site\EDMSERVER01
Skipping all tests, because server EDMSERVER01 is
not responding to directory service requests

Running partition tests on : TAPI3Directory
Starting test: CrossRefValidation
......................... TAPI3Directory passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... TAPI3Directory passed test CheckSDRefDom

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running partition tests on : XYZ
Starting test: CrossRefValidation
......................... XYZ passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... XYZ passed test CheckSDRefDom

Running enterprise tests on : XYZ.local
Starting test: Intersite
......................... XYZ.local passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355
A Good Time Server could not be located.
......................... XYZ.local failed test FsmoCheck

***************************************
 

anonym00se

Distinguished
Jul 31, 2011
5
0
18,510
**UPDATE - run Netdiag x64 which CAN properly read the netlogon.dns file on Windows 2003 x64..


**********
NETDIAG x64
**********







Computer Name: EDMSERVER01
DNS Host Name: edmserver01.XYZ.local
System info : Microsoft Windows Server 2003 R2 (Build 3790)
Processor : EM64T Family 6 Model 15 Stepping 8, GenuineIntel
List of installed hotfixes :
KB2079403
KB2115168
KB2121546
KB2124261
KB2141007
KB2158563
KB2160329
KB2183461-IE7
KB2229593
KB2259922
KB2279986
KB2286198
KB2296011
KB2296199
KB2345886
KB2347290
KB2360131-IE7
KB2360937
KB2378111
KB2387149
KB2393802
KB2412687
KB2419635
KB2423089
KB2440591
KB2443105
KB2443685
KB2476490
KB2476687
KB2478953
KB2478960
KB2478971
KB2479628
KB2481109
KB2482017-IE7
KB2483185
KB2485376
KB2485663
KB2497640-IE7
KB2503658
KB2503665
KB2506212
KB2506223
KB2507618
KB2507938
KB2508272
KB2508429
KB2509553
KB2510581
KB2511455
KB2524375
KB2525694
KB2530548-IE7
KB2535512
KB2536276
KB2544521-IE7
KB2544893
KB2555917
KB921503
KB924667-v2
KB925398_WMP64
KB925876
KB925902
KB926122
KB926139
KB926141
KB927891
KB929123
KB930178
KB932168
KB932596
KB933360
KB933729
KB935839
KB935840
KB936021
KB936357
KB936782
KB938127
KB938127-IE7
KB938464
KB939653
KB939653-IE7
KB941202
KB941568
KB941569
KB941644
KB941672
KB941693
KB942615-IE7
KB942763
KB942830
KB942831
KB943055
KB943460
KB943485
KB943729
KB944653
KB945553
KB946026
KB948496
KB948590
KB949014
KB950759-IE7
KB950760
KB950762
KB950974
KB951066
KB951072-v2
KB951698
KB951746
KB951748
KB952069
KB952954
KB953838-IE7
KB953839
KB954155
KB954211
KB954550-v7
KB954600
KB955069
KB955759
KB955839
KB956390-IE7
KB956391
KB956744
KB956802
KB956803
KB956841
KB956844
KB957095
KB957097
KB958215-IE7
KB958644
KB958687
KB958690
KB958869
KB960225
KB960714-IE7
KB960715
KB960803
KB960859
KB961063
KB961118
KB961260-IE7
KB961371
KB961371-v2
KB961501
KB967715
KB967723
KB968389
KB968537
KB968816
KB969059
KB969805
KB969897-IE7
KB969898
KB969947
KB970238
KB970483
KB970653-v3
KB971029
KB971032
KB971468
KB971486
KB971513
KB971557
KB971633
KB971657
KB971737
KB971961
KB972260-IE7
KB972270
KB973037
KB973346
KB973354
KB973507
KB973525
KB973540
KB973687
KB973815
KB973869
KB973904
KB973917
KB973917-v2
KB974112
KB974318
KB974392
KB974455-IE7
KB974571
KB975025
KB975467
KB975558_WM8
KB975560
KB975562
KB975713
KB976098-v2
KB976325-IE7
KB976749-IE7
KB977165
KB977290
KB977816
KB977914
KB978037
KB978207-IE7
KB978251
KB978262
KB978338
KB978542
KB978601
KB978695
KB978706
KB979306
KB979309
KB979482
KB979559
KB979683
KB979687
KB980182-IE7
KB980195
KB980218
KB980232
KB980436
KB981322
KB981349
KB981550
KB981793
KB981957
KB982132
KB982214
KB982381-IE7
KB982666
KB982802
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : Local Area Connection

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : edmserver01
IP Address . . . . . . . . : 192.20.20.10
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.20.20.4
Dns Servers. . . . . . . . :

AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names is missing.

WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{2236CEE3-8A1B-45F7-AABE-8AE05CE4C5C4}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Service', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Failed
[FIX] re-register DC DNS entry '_ldap._tcp.gc._msdcs.XYZ.local.' on DNS server '127.0.0.1' succeed.
[FIX] re-register DC DNS entry '_ldap._tcp.Default-First-Site._sites.gc._msdcs.XYZ.local.' on DNS server '127.0.0.1' succeed.
FIX PASS - netdiag re-registered missing DNS entries for this DC successfully on DNS server '127.0.0.1'.
[FATAL] No DNS servers have the DNS records for this DC registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{2236CEE3-8A1B-45F7-AABE-8AE05CE4C5C4}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{2236CEE3-8A1B-45F7-AABE-8AE05CE4C5C4}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully
 

anonym00se

Distinguished
Jul 31, 2011
5
0
18,510
And here's the updated dcdiag after netdiag /fix.. any suggestions as to these 4 remaining errors? Also, should any of these affect the 'lost' member server? The symptom I'm seeing is our biggest problem - that the BES cannot communicate with Exchange and AD because it cannot contact the AD.

How can I readd this server to AD without recreating it from scratch? Can it be demoted out of the domain and rejoin?

*******
DCDIAG
*******



Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site\EDMSERVER01
Starting test: Connectivity
......................... EDMSERVER01 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site\EDMSERVER01
Starting test: Replications
......................... EDMSERVER01 passed test Replications
Starting test: NCSecDesc
......................... EDMSERVER01 passed test NCSecDesc
Starting test: NetLogons
......................... EDMSERVER01 passed test NetLogons
Starting test: Advertising
Warning: EDMSERVER01 is not advertising as a time server.
......................... EDMSERVER01 failed test Advertising

Starting test: KnowsOfRoleHolders
......................... EDMSERVER01 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... EDMSERVER01 passed test RidManager
Starting test: MachineAccount
......................... EDMSERVER01 passed test MachineAccount
Starting test: Services
Could not open w32time Service on [EDMSERVER01]:failed with 1060: The specified service does not exist as an installed service.
......................... EDMSERVER01 failed test Services

Starting test: ObjectsReplicated
......................... EDMSERVER01 passed test ObjectsReplicated
Starting test: frssysvol
......................... EDMSERVER01 passed test frssysvol
Starting test: frsevent
There are warning or error events within the last 24 hours after the

SYSVOL has been shared. Failing SYSVOL replication problems may cause

Group Policy problems.
......................... EDMSERVER01 failed test frsevent

Starting test: kccevent
......................... EDMSERVER01 passed test kccevent
Starting test: systemlog
......................... EDMSERVER01 passed test systemlog
Starting test: VerifyReferences
......................... EDMSERVER01 passed test VerifyReferences

Running partition tests on : TAPI3Directory
Starting test: CrossRefValidation
......................... TAPI3Directory passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... TAPI3Directory passed test CheckSDRefDom

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running partition tests on : XYZ
Starting test: CrossRefValidation
......................... XYZ passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... XYZ passed test CheckSDRefDom

Running enterprise tests on : XYZ.local
Starting test: Intersite
......................... XYZ.local passed test Intersite
Starting test: FsmoCheck
Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
A Time Server could not be located.
The server holding the PDC role is down.
Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 1355
A Good Time Server could not be located.
......................... XYZ.local failed test FsmoCheck

 

anonym00se

Distinguished
Jul 31, 2011
5
0
18,510
I've resolved a few of these errors by reinstalling the Windows Time service on the domain controller. However the replication error still remains. Any suggestions?

**********

Starting test: frsevent
There are warning or error events within the last 24 hours after the

SYSVOL has been shared. Failing SYSVOL replication problems may cause

Group Policy problems.
......................... EDMSERVER01 failed test frsevent