Single DC can not find GC.

Y

Yor Suiris

I have a restored a DC not connected to any computers. Seized all the roles.
Got DNS setup. But AD will not start. Using DCdiag I see that it can not
find any Global Catalog server, which would be it's self. I understand there
is an issue with the infrastrure Master and Global Cat on the same machine.
So how does it work with only one DC?
 
S

Simon Geary

The issue with the Infrastructure Master and GC being on the same server
only arises when you have multiple domains. In a single domain, all your
DC's should be a GC. Have you checked in Sites & Services to make sure the
single DC is a GC?
 
Y

Yor Suiris

Yes I have checked and in sites & services the box is checked.
But dcdiag shows that it can not contact any GCs. Of course the SYSVOL and
NETLOGON have not been shared out yet either. Which is the problem I am
battling. I did add a Reg Key to IgnoreGCFailures. Not sure if that worked
yet as I have just rebooted and will need to wait a bit to see if the SYSVOL
gets shared. If this does not work, might you have any Ideas? I want to
connect another machine to it so I can copy some stuff off it
Thanks for yor time...yor
 
S

S.J.Haribabu

Hi Yor Suiris,

Global Catalog and Infrastructure Master Role Conflict
===============================================
If the IM Flexible Single Master Operation (FSMO) role holder is also a
global catalog server, the phantom indexes are never created or updated on
that domain controller. This behavior occurs because a global catalog
server contains a partial replica of every object in Active Directory. The
IM does not store phantom versions of the foreign objects because it
already has a partial replica of the object in the local global catalog.

For this process to work properly in a multi-domain environment, the
infrastructure FSMO role holder cannot be a global catalog server. Note
that the first domain in the forest holds all five FSMO roles, and is also
a global catalog. Because of this, you must transfer either role to another
computer as soon as another domain controller is installed in the domain if
you plan to have multiple domains.

If the infrastructure FSMO role and global catalog role reside on the same
domain controller, you continually receive event ID 1419 in the directory
services event log. For additional information, click the article number
below to view the article in the Microsoft Knowledge Base:

251095 Event ID 1419 Generated on a Domain Controller
================================================
SYMPTOMS
Event error 1419 may be generated on a domain controller. This event may be
generated because there may be problems with an Infrastructure Flexible
Single Master Operation (FSMO) role holder performing its duties if it is
also a global catalog server.

The error message in Event Viewer may be similar to the following sample:

Event ID: 1419 Event Type: Error
Event Source: NTDS General
Event Category: Directory Access
Event ID: 1419
Date: 1/16/2000
Time: 9:58:21 AM
User: Everyone
Computer: Server1

Description:
This DC is both a Global Catalog and the Infrastructure Update master.
These two roles are incompatible. If another machine exists in the domain,
it should be made the Infrastructure Update master. The machine CN=NTDS
Settings,CN=Server4,CN=Servers,CN=West,CN=Sites,CN=Configuration,DC=PRODOM,D
C=com is a good candidate for this role. If all domain controllers in this
domain are Global Catalogs, then there are no Infrastructure Update tasks
to complete, and this message may be ignored.
CAUSE
This behavior can occur if a domain controller that resides in a
multiple-domain-controller domain in a multiple-domain forest holds the
Infrastructure FSMO role and is also a global catalog. The error message is
generated after another domain controller is installed in the domain. This
is most likely to occur on the first domain controller in the forest
because it holds all five FSMO roles and is also a global catalog server.
RESOLUTION
There are two ways to resolve this issue:
Transfer the Infrastructure FSMO role to another domain controller in the
domain.
Enable another domain controller in the forest to be the global catalog
server and disable this computer from being a global catalog server.

Yor Suiris - If you have any specific questions, please let me know. I
would be happy to help you.

Thanks,

(e-mail address removed)

This posting is provided "AS IS" with no warranties, and confers no rights.
 
Y

Yor Suiris

Thanks, But how do I add another DC when when the SYSVOL wont start? Seems
to be a catch 22. I need another DC to get this one to work, but I need this
one to work before I can add another DC......My brain hurts.
 
Y

Yor Suiris

Since you offered to help. Going through the logs and such. I get errors
about the FRS. and One suggests that I restore the system state using
advance options to set SYSVOL as primary. I hesitate to do this as the
current SystemState I have on tape is from when this machine was part of a
domain and am not sure if it will help or hurt.
Then the next event that keeps showing up is that FRS has detectd that the
replica root has changed from C:\winnt\sysvol\domain to
C:\winnt\sysvol\domain and a file needs to be created in the root
NTFRS_CMD_FILE_MOVE_ROOT.
So using Notepad I created a blank file with that name. But has not helped.
Was that the right way?
So is the System State restore my only option?
 
Y

Yor Suiris

OK I got it. I had to change the Journal size with registry edit. Rebooted
and now Sysvol is sharing out.

Thanks to all for the input. After all we're all in this together...yor
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top