老服务器:服务器新服务器:AUTHSRV我正在玩我的实验室,我似乎还没有正确删除我的旧AD DS服务器,当我添加我的新的,所以现在我不能添加新的计算机到AD DS。
这是我得到的错误:
我应该弄清楚是什么原因导致了这个问题呢?
我最终删除了从Active Directory站点和服务下的旧服务器,我不知道如果这是正确的。
编辑:
PS C:\Users\administrator.INTERNAL> ntdsutil C:\Windows\system32\ntdsutil.exe: metadata cleanup metadata cleanup: remove selected server SERVER Binding to localhost ... Connected to localhost using credentials of locally logged on user. LDAP error 0x22(34 (Invalid DN Syntax). Ldap extended error message is 0000208F: NameErr: DSID-03100225, problem 2006 (BAD_NAME), data 8350, best match of: 'CN=Ntds Settings,SERVER' Win32 error returned is 0x208f(The object name has bad syntax.) ) Unable to determine the domain hosted by the Active Directory Domain Controller (5). Please use the connection menu to s pecify it.
编辑:
PS C:\Users\administrator.INTERNAL> dcdiag Directory Server Diagnosis Performing initial setup: Trying to find home server... Home Server = authsrv * Identified AD Forest. Done gathering initial info. Doing initial required tests Testing server: CITY-HQ\AUTHSRV Starting test: Connectivity ......................... AUTHSRV passed test Connectivity Doing primary tests Testing server: CITY-HQ\AUTHSRV Starting test: Advertising ......................... AUTHSRV passed test Advertising Starting test: FrsEvent ......................... AUTHSRV passed test FrsEvent Starting test: DFSREvent There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. ......................... AUTHSRV failed test DFSREvent Starting test: SysVolCheck ......................... AUTHSRV passed test SysVolCheck Starting test: KccEvent ......................... AUTHSRV passed test KccEvent Starting test: KnowsOfRoleHolders Warning: CN=NTDS Settings\0ADEL:05f209fb-df38-424f-8660-52a43ce83c8e,CN=SERVER\0ADEL:fe8837d6-377c-4763-a3b8-409b2235ef9 e,CN=Servers,CN=CITY-HQ,CN=Sites,CN=Configuration,DC=internal,DC=DOMAIN,DC=com is the Schema Owner, but is deleted. ......................... AUTHSRV failed test KnowsOfRoleHolders Starting test: MachineAccount ......................... AUTHSRV passed test MachineAccount Starting test: NCSecDesc ......................... AUTHSRV passed test NCSecDesc Starting test: NetLogons ......................... AUTHSRV passed test NetLogons Starting test: ObjectsReplicated ......................... AUTHSRV passed test ObjectsReplicated Starting test: Replications ......................... AUTHSRV passed test Replications Starting test: RidManager ......................... AUTHSRV passed test RidManager Starting test: Services ......................... AUTHSRV passed test Services Starting test: SystemLog ......................... AUTHSRV passed test SystemLog Starting test: VerifyReferences ......................... AUTHSRV passed test VerifyReferences Running partition tests on : ForestDnsZones Starting test: CheckSDRefDom ......................... ForestDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... ForestDnsZones passed test CrossRefValidation Running partition tests on : DomainDnsZones Starting test: CheckSDRefDom ......................... DomainDnsZones passed test CheckSDRefDom Starting test: CrossRefValidation ......................... DomainDnsZones passed test CrossRefValidation Running partition tests on : Schema Starting test: CheckSDRefDom ......................... Schema passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Schema passed test CrossRefValidation Running partition tests on : Configuration Starting test: CheckSDRefDom ......................... Configuration passed test CheckSDRefDom Starting test: CrossRefValidation ......................... Configuration passed test CrossRefValidation Running partition tests on : internal Starting test: CheckSDRefDom ......................... internal passed test CheckSDRefDom Starting test: CrossRefValidation ......................... internal passed test CrossRefValidation Running enterprise tests on : internal.DOMAIN.com Starting test: LocatorCheck ......................... internal.DOMAIN.com passed test LocatorCheck Starting test: Intersite ......................... internal.DOMAIN.com passed test Intersite PS C:\Users\administrator.INTERNAL>
您应该执行元数据清理,以从您的AD中移除您的退役DC的痕迹。
您还应该确保所有FSMOangular色都由您的任何一个活动域控制器持有,如果不是,则将angular色夺取 。
运行一个dcdiag也可能会提供有关您的域控制器的整体健康状况的有用信息。
根据您的dcdiag输出,您删除的DC仍然是架构所有者(也可能具有其他FSMOangular色)。
你需要强行抓住angular色 ,对于一个正在运行的AD来说是至关重要的。 您的元数据清理可能会成功。