Adding a 2000 AD child domain under a 2003 AD forest root domain

S

Shawn

I'm setting up a test environment to role our NT 4.0 domain/W2K workstation
to AD. I have set up an Windows 2003 AD server as my empty forest root
server.

Next I'm attempting to add a child domain with my NT 4 (PDC) upgraded to
Win2K AD (hardware limited). During the the dcpromo, I'm getting the
following error:

-------------
Active Directory Installation Failed

The operation failed because:

An ldap read of operational attributes from server <my forest root DC>
failed.

"An error occurred while installing the directory service. For more
information, see the event log"
--------------

It appears to find the AD forest root (based on logs), using an enterprise
account that I set up on the forest root AD server.

Any thoughts on what might be the cause? Is there a schema issue between
2000 and 2003 that may be causing this?

Do I need to add the child domain computer account to the forest root
somewhere before I attempt dcpromo?

The only log I get on my <2000DC> (that I'm dcpromo-ing) is the following:
-----------
The session setup to the windows NT or windows 2000 domain controller
(unknown) for the domain <2000DC domain> failed because the domain
controller does not have an account for the computer <2000DC>.
----------

P.S. I'll give ya more info...just let me know.

Thanks in advance.

Shawn
 
T

Tim Hines, MCSA, MCSE

Take a look at the dcpromo.log file on the server
(\winnt\debug\dcpromo.log). Post the exact errors in the newsgroup. You
should also verify that the Domain Naming Master and all other FSMO role
holders are available on the network.

--
--
Tim Hines, MCSE, MCSA
Windows 2000 Directory Services

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
 
S

Shawn

Update:

Rebuilt Forest Root with Win2K AD and adding child domain worked flawlessly.

Must have been schema difference???
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top