[long] DCDiag error on Win2k3

M

M. Baur

Hi all,

I would move some user from one DC in our RootDomain to our ChildDomain
with the MoveTree command. This doesn't work (Error: No authority could be
contacted for authentication).
So I searching the cause of this and I start the command dcdiag /e to see
if all is ok on my DC topology. I got this error:


[output start]

Testing server: RootDom\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity

Testing server: ChildDom\DC3
Starting test: Connectivity
[DC3] LDAP bind failed with error 8341,
A directory service error has occurred..
......................... DC3 failed test Connectivity

Testing server: RootDom\DC2
Starting test: Connectivity
......................... DC2 passed test Connectivity

Testing server: ChildDom\DC4
Starting test: Connectivity
[DC4] LDAP bind failed with error 8341,
A directory service error has occurred..
......................... DC4 failed test Connectivity

[cut]


Running enterprise tests on : domain.com
Starting test: Intersite
Doing intersite inbound replication test on site RootDom:
*Warning: Remote bridgehead ChildDom\DC3 has some replication
syncs failing. It will be 1 hours 10 minutes before the
bridgehead is considered ineligible to be a bridgehead.
Remote bridgehead ChildDom\DC3 also couldn't be contacted by
dcdiag. Check this server.
*Warning: Remote bridgehead ChildDom\DC4 has some replication
syncs failing. It will be 1 hours 10 minutes before the
bridgehead is considered ineligible to be a bridgehead.
Remote bridgehead ChildDom\DC4 also couldn't be contacted by
dcdiag. Check this server.
***Error: The remote site ChildDom, has no servers that can act as
bridgeheads between the ChildDom and the local site RootDom for
the writeable NC DomainDnsZones. Replication will not continue
until this is resolved.
***Error: The remote site ChildDom, has no servers that can act as
bridgeheads between the ChildDom and the local site RootDom for
the writeable NC ChildDom. Replication will not continue until
this is resolved.
Doing intersite inbound replication test on site ChildDom:
[DC3] DsBindWithSpnEx() failed with error -2146892976,
The system detected a possible attempt to compromise security.
Please ensure that you can contact the server that authenticated
you..
***Error: The current ISTG is down in site ChildDom and further
dcdiag could not contact any other servers in the site that could
take the ISTG role. Ensure there is at least one up DC. Must
abandon inbound intersite replication test for this site.
......................... domain.com failed test Intersite

[output stop]


All the DC's are pingable, all the users can work without problem, all
seems to work. I try to reset the trust, flush the DNS (delete the dns
server end recreate the two zone). All seems ok with the ReplMon tools.

As anybody an idea?

Thanx in advance
 
P

ptwilliams

How is your DNS setup for each domain? Where do the DCs point for DNS?

Run netdiag /v as well.


--

Paul Williams
_________________________________________
http://www.msresource.net - Under construction, but coming soon...


Join us in our new forums!
http://forums.msresource.net
_________________________________________


M. Baur said:
Hi all,

I would move some user from one DC in our RootDomain to our ChildDomain
with the MoveTree command. This doesn't work (Error: No authority could be
contacted for authentication).
So I searching the cause of this and I start the command dcdiag /e to see
if all is ok on my DC topology. I got this error:


[output start]

Testing server: RootDom\DC1
Starting test: Connectivity
......................... DC1 passed test Connectivity

Testing server: ChildDom\DC3
Starting test: Connectivity
[DC3] LDAP bind failed with error 8341,
A directory service error has occurred..
......................... DC3 failed test Connectivity

Testing server: RootDom\DC2
Starting test: Connectivity
......................... DC2 passed test Connectivity

Testing server: ChildDom\DC4
Starting test: Connectivity
[DC4] LDAP bind failed with error 8341,
A directory service error has occurred..
......................... DC4 failed test Connectivity

[cut]


Running enterprise tests on : domain.com
Starting test: Intersite
Doing intersite inbound replication test on site RootDom:
*Warning: Remote bridgehead ChildDom\DC3 has some replication
syncs failing. It will be 1 hours 10 minutes before the
bridgehead is considered ineligible to be a bridgehead.
Remote bridgehead ChildDom\DC3 also couldn't be contacted by
dcdiag. Check this server.
*Warning: Remote bridgehead ChildDom\DC4 has some replication
syncs failing. It will be 1 hours 10 minutes before the
bridgehead is considered ineligible to be a bridgehead.
Remote bridgehead ChildDom\DC4 also couldn't be contacted by
dcdiag. Check this server.
***Error: The remote site ChildDom, has no servers that can act as
bridgeheads between the ChildDom and the local site RootDom for
the writeable NC DomainDnsZones. Replication will not continue
until this is resolved.
***Error: The remote site ChildDom, has no servers that can act as
bridgeheads between the ChildDom and the local site RootDom for
the writeable NC ChildDom. Replication will not continue until
this is resolved.
Doing intersite inbound replication test on site ChildDom:
[DC3] DsBindWithSpnEx() failed with error -2146892976,
The system detected a possible attempt to compromise security.
Please ensure that you can contact the server that authenticated
you..
***Error: The current ISTG is down in site ChildDom and further
dcdiag could not contact any other servers in the site that could
take the ISTG role. Ensure there is at least one up DC. Must
abandon inbound intersite replication test for this site.
......................... domain.com failed test Intersite

[output stop]


All the DC's are pingable, all the users can work without problem, all
seems to work. I try to reset the trust, flush the DNS (delete the dns
server end recreate the two zone). All seems ok with the ReplMon tools.

As anybody an idea?

Thanx in advance
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top