Principal target name error on only DC in Domain

  • Thread starter Edwin Plaggenmarsch
  • Start date
E

Edwin Plaggenmarsch

Hello,

On a school I work for (setup: 1DC with 1 Domain) a hard drive
crashed. I took the second drive of the mirror and placed it as the
first drive. Everything seemed normal, except for an extremely slow
startup, showing 'preparing network connections'. I could login
normally.
The clients can not login correctly anymore, when tried the message
'target account not found' is displayed. After that the loginscript
cannot be run normally (can not make mappings). I can ping the server
from the clients, with name and ip, but I can not map a drive nor does
typing '\\server' work, I get an error showing 'can not find target'.
On the server I can't run any Active Directory .msc, everytime I get
the error 'Principal target name incorrect'. Running DcDiag returns:
'[server] LDAP bind failed with error 31. A connected device does not
function properly'
I know these symptons are seen often, but always on a domain with
multiple DC's. So demoting is not an option, because this server will
not replicate with other DC's. Also turning off KDC will probably
result in an unbootable server, 'cause there's no other DC.
I've tried
http://support.microsoft.com/default.aspx?scid=kb;en-us;288167
and resetting the password with netdom.exe but nothing seems to work
(or I don't even get that far).
Does anybody have a clue? I'm really desperate because the school
begins in 2 days and there are a *lot* of accounts on that server...
Thanx in advance!

Edwin
 
J

Jerold Schulman

Hello,

On a school I work for (setup: 1DC with 1 Domain) a hard drive
crashed. I took the second drive of the mirror and placed it as the
first drive. Everything seemed normal, except for an extremely slow
startup, showing 'preparing network connections'. I could login
normally.
The clients can not login correctly anymore, when tried the message
'target account not found' is displayed. After that the loginscript
cannot be run normally (can not make mappings). I can ping the server
from the clients, with name and ip, but I can not map a drive nor does
typing '\\server' work, I get an error showing 'can not find target'.
On the server I can't run any Active Directory .msc, everytime I get
the error 'Principal target name incorrect'. Running DcDiag returns:
'[server] LDAP bind failed with error 31. A connected device does not
function properly'
I know these symptons are seen often, but always on a domain with
multiple DC's. So demoting is not an option, because this server will
not replicate with other DC's. Also turning off KDC will probably
result in an unbootable server, 'cause there's no other DC.
I've tried
http://support.microsoft.com/default.aspx?scid=kb;en-us;288167
and resetting the password with netdom.exe but nothing seems to work
(or I don't even get that far).
Does anybody have a clue? I'm really desperate because the school
begins in 2 days and there are a *lot* of accounts on that server...
Thanx in advance!

Edwin

See if tip 6049 in the 'Tips & Tricks' at http://www.jsiinc.com helps.



Jerold Schulman
Windows: General MVP
JSI, Inc.
http://www.jsiinc.com
 
E

Edwin Plaggenmarsch

Hello,

On a school I work for (setup: 1DC with 1 Domain) a hard drive
crashed. I took the second drive of the mirror and placed it as the
first drive. Everything seemed normal, except for an extremely slow
startup, showing 'preparing network connections'. I could login
normally.
The clients can not login correctly anymore, when tried the message
'target account not found' is displayed. After that the loginscript
cannot be run normally (can not make mappings). I can ping the server
from the clients, with name and ip, but I can not map a drive nor does
typing '\\server' work, I get an error showing 'can not find target'.
On the server I can't run any Active Directory .msc, everytime I get
the error 'Principal target name incorrect'. Running DcDiag returns:
'[server] LDAP bind failed with error 31. A connected device does not
function properly'
I know these symptons are seen often, but always on a domain with
multiple DC's. So demoting is not an option, because this server will
not replicate with other DC's. Also turning off KDC will probably
result in an unbootable server, 'cause there's no other DC.
I've tried
http://support.microsoft.com/default.aspx?scid=kb;en-us;288167
and resetting the password with netdom.exe but nothing seems to work
(or I don't even get that far).
Does anybody have a clue? I'm really desperate because the school
begins in 2 days and there are a *lot* of accounts on that server...
Thanx in advance!

Edwin


See if tip 6049 in the 'Tips & Tricks' at http://www.jsiinc.com helps.


Jerold Schulman
Windows: General MVP
JSI, Inc.
http://www.jsiinc.com


This was the solution to my problem. Thanx Jerold!

Edwin
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top