本身有二台Server2012R2的Domain Controller, 在windows update後常常出現認證錯誤,然後在我多次CHECKPOINT後發現在不能replication. 現在我先停了一台, 打算再開一台新的取代他, 但當我裝好新的後,想JOIN DOMAIN時,出現錯誤, "嘗試加入網域 無法完成此功能"
然後看Debug如下
02/08/2020 17:49:06:094 -----------------------------------------------------------------
02/08/2020 17:49:06:094 NetpValidateName: checking to see if 'SCH-ROOT2' is valid as type 1 name
02/08/2020 17:49:06:094 NetpCheckNetBiosNameNotInUse for 'SCH-ROOT2' [MACHINE] returned 0x0
02/08/2020 17:49:06:094 NetpValidateName: name 'SCH-ROOT2' is valid for type 1
02/08/2020 17:49:06:141 -----------------------------------------------------------------
02/08/2020 17:49:06:141 NetpValidateName: checking to see if 'sch-root2' is valid as type 5 name
02/08/2020 17:49:06:141 NetpValidateName: name 'sch-root2' is valid for type 5
02/08/2020 17:49:06:188 -----------------------------------------------------------------
02/08/2020 17:49:06:188 NetpValidateName: checking to see if 'YTT.EDU.HK' is valid as type 3 name
02/08/2020 17:49:07:400 NetpCheckDomainNameIsValid [ Exists ] for 'YTT.EDU.HK' returned 0x0
02/08/2020 17:49:07:431 NetpValidateName: name 'YTT.EDU.HK' is valid for type 3
02/08/2020 17:49:11:977 -----------------------------------------------------------------
02/08/2020 17:49:11:977 NetpDoDomainJoin
02/08/2020 17:49:11:977 NetpDoDomainJoin: using current computer names
02/08/2020 17:49:11:977 NetpDoDomainJoin: NetpGetComputerNameEx(NetBios) returned 0x0
02/08/2020 17:49:11:977 NetpDoDomainJoin: NetpGetComputerNameEx(DnsHostName) returned 0x0
02/08/2020 17:49:11:977 NetpMachineValidToJoin: 'SCH-ROOT2'
02/08/2020 17:49:11:977 OS Version: 6.3
02/08/2020 17:49:11:977 Build number: 9600 (9600.winblue_gdr.140221-1952)
02/08/2020 17:49:11:977 SKU: Windows Server 2012 R2 Standard
02/08/2020 17:49:11:977 Architecture: 64-bit (AMD64)
02/08/2020 17:49:11:977 NetpDomainJoinLicensingCheck: ulLicenseValue=1, Status: 0x0
02/08/2020 17:49:11:977 NetpGetLsaPrimaryDomain: status: 0x0
02/08/2020 17:49:11:977 NetpMachineValidToJoin: status: 0x0
02/08/2020 17:49:11:977 NetpJoinDomain
02/08/2020 17:49:11:977 HostName: sch-root2
02/08/2020 17:49:11:977 NetbiosName: SCH-ROOT2
02/08/2020 17:49:11:977 Domain: YTT.EDU.HK
02/08/2020 17:49:11:977 MachineAccountOU: (NULL)
02/08/2020 17:49:11:977 Account: YTT.EDU.HK\tss
02/08/2020 17:49:11:977 Options: 0x25
02/08/2020 17:49:11:977 NetpLoadParameters: loading registry parameters...
02/08/2020 17:49:11:977 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
02/08/2020 17:49:11:977 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
02/08/2020 17:49:11:977 NetpLoadParameters: status: 0x2
02/08/2020 17:49:11:977 NetpValidateName: checking to see if 'YTT.EDU.HK' is valid as type 3 name
02/08/2020 17:49:14:908 NetpCheckDomainNameIsValid [ Exists ] for 'YTT.EDU.HK' returned 0x0
02/08/2020 17:49:14:908 NetpValidateName: name 'YTT.EDU.HK' is valid for type 3
02/08/2020 17:49:14:908 NetpDsGetDcName: trying to find DC in domain 'YTT.EDU.HK', flags: 0x40001010
02/08/2020 17:49:29:908 NetpDsGetDcName: failed to find a DC having account 'SCH-ROOT2$': 0x525, last error is 0x0
02/08/2020 17:49:30:133 NetpLoadParameters: loading registry parameters...
02/08/2020 17:49:30:133 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
02/08/2020 17:49:30:133 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
02/08/2020 17:49:30:133 NetpLoadParameters: status: 0x2
02/08/2020 17:49:30:299 NetpDsGetDcName: status of verifying DNS A record name resolution for 'sch-root.ytt.edu.hk': 0x0
02/08/2020 17:49:30:299 NetpDsGetDcName: found DC '\sch-root.ytt.edu.hk' in the specified domain
02/08/2020 17:49:30:299 NetpJoinDomainOnDs: NetpDsGetDcName returned: 0x0
02/08/2020 17:49:30:299 NetpDisableIDNEncoding: using FQDN ytt.edu.hk from dcinfo
02/08/2020 17:49:30:299 NetpDisableIDNEncoding: DnsDisableIdnEncoding(UNTILREBOOT) on 'ytt.edu.hk' succeeded
02/08/2020 17:49:30:299 NetpJoinDomainOnDs: NetpDisableIDNEncoding returned: 0x0
02/08/2020 17:49:32:925 NetpJoinDomainOnDs: status of connecting to dc '\sch-root.ytt.edu.hk': 0x0
02/08/2020 17:49:32:925 NetpGetDnsHostName: PrimaryDnsSuffix defaulted to DNS domain name: ytt.edu.hk
02/08/2020 17:49:32:925 NetpProvisionComputerAccount:
02/08/2020 17:49:32:925 lpDomain: YTT.EDU.HK
02/08/2020 17:49:32:925 lpHostName: sch-root2
02/08/2020 17:49:32:925 lpMachineAccountOU: (NULL)
02/08/2020 17:49:32:925 lpDcName: sch-root.ytt.edu.hk
02/08/2020 17:49:32:925 lpMachinePassword: (null)
02/08/2020 17:49:32:925 lpAccount: YTT.EDU.HK\tss
02/08/2020 17:49:32:925 lpPassword: (non-null)
02/08/2020 17:49:32:925 dwJoinOptions: 0x25
02/08/2020 17:49:32:925 dwOptions: 0x40000003
02/08/2020 17:49:32:964 NetpLdapBind: Verified minimum encryption strength on sch-root.ytt.edu.hk: 0x0
02/08/2020 17:49:32:964 NetpLdapGetLsaPrimaryDomain: reading domain data
02/08/2020 17:49:32:964 NetpGetNCData: Reading NC data
02/08/2020 17:49:32:964 NetpGetDomainData: Lookup domain data for: DC=ytt,DC=edu,DC=hk
02/08/2020 17:49:32:964 NetpGetDomainData: Lookup crossref data for: CN=Partitions,CN=Configuration,DC=ytt,DC=edu,DC=hk
02/08/2020 17:49:32:964 NetpLdapGetLsaPrimaryDomain: result of retrieving domain data: 0x0
02/08/2020 17:49:32:964 NetpCheckForDomainSIDCollision: returning 0x0(0).
02/08/2020 17:49:32:980 NetpGetComputerObjectDn: Cracking DNS domain name ytt.edu.hk/ into Netbios on \sch-root.ytt.edu.hk
02/08/2020 17:49:32:980 NetpGetComputerObjectDn: Crack results: name = YTT
02/08/2020 17:49:32:980 NetpGetComputerObjectDn: Cracking account name YTT\SCH-ROOT2$ on \sch-root.ytt.edu.hk
02/08/2020 17:49:32:980 NetpGetComputerObjectDn: Crack results: Account does not exist
02/08/2020 17:49:32:980 NetpCreateComputerObjectInDs: NetpGetComputerObjectDn failed: 0x534
02/08/2020 17:49:32:980 NetpProvisionComputerAccount: LDAP creation failed: 0x534
02/08/2020 17:49:32:980 ldap_unbind status: 0x0
02/08/2020 17:49:32:980 NetpJoinCreatePackagePart: status:0x534.
02/08/2020 17:49:32:980 NetpAddProvisioningPackagePart: status:0x534.
02/08/2020 17:49:32:980 NetpJoinDomainOnDs: Function exits with status of: 0x534
02/08/2020 17:49:32:980 NetpJoinDomainOnDs: status of disconnecting from '\sch-root.ytt.edu.hk': 0x0
02/08/2020 17:49:32:997 NetpResetIDNEncoding: DnsDisableIdnEncoding(RESETALL) on 'ytt.edu.hk' returned 0x0
02/08/2020 17:49:32:997 NetpJoinDomainOnDs: NetpResetIDNEncoding on 'ytt.edu.hk': 0x0
02/08/2020 17:49:32:997 NetpDoDomainJoin: status: 0x534
02/08/2020 17:49:33:080 -----------------------------------------------------------------
02/08/2020 17:49:33:080 NetpDoDomainJoin
02/08/2020 17:49:33:080 NetpDoDomainJoin: using current computer names
02/08/2020 17:49:33:080 NetpDoDomainJoin: NetpGetComputerNameEx(NetBios) returned 0x0
02/08/2020 17:49:33:080 NetpDoDomainJoin: NetpGetComputerNameEx(DnsHostName) returned 0x0
02/08/2020 17:49:33:080 NetpMachineValidToJoin: 'SCH-ROOT2'
02/08/2020 17:49:33:080 OS Version: 6.3
02/08/2020 17:49:33:080 Build number: 9600 (9600.winblue_gdr.140221-1952)
02/08/2020 17:49:33:080 SKU: Windows Server 2012 R2 Standard
02/08/2020 17:49:33:080 Architecture: 64-bit (AMD64)
02/08/2020 17:49:33:080 NetpDomainJoinLicensingCheck: ulLicenseValue=1, Status: 0x0
02/08/2020 17:49:33:080 NetpGetLsaPrimaryDomain: status: 0x0
02/08/2020 17:49:33:080 NetpMachineValidToJoin: status: 0x0
02/08/2020 17:49:33:080 NetpJoinDomain
02/08/2020 17:49:33:080 HostName: sch-root2
02/08/2020 17:49:33:080 NetbiosName: SCH-ROOT2
02/08/2020 17:49:33:080 Domain: YTT.EDU.HK
02/08/2020 17:49:33:080 MachineAccountOU: (NULL)
02/08/2020 17:49:33:080 Account: YTT.EDU.HK\tss
02/08/2020 17:49:33:080 Options: 0x27
02/08/2020 17:49:33:080 NetpLoadParameters: loading registry parameters...
02/08/2020 17:49:33:080 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
02/08/2020 17:49:33:080 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
02/08/2020 17:49:33:080 NetpLoadParameters: status: 0x2
02/08/2020 17:49:33:080 NetpValidateName: checking to see if 'YTT.EDU.HK' is valid as type 3 name
02/08/2020 17:49:35:900 NetpCheckDomainNameIsValid [ Exists ] for 'YTT.EDU.HK' returned 0x0
02/08/2020 17:49:35:900 NetpValidateName: name 'YTT.EDU.HK' is valid for type 3
02/08/2020 17:49:35:900 NetpDsGetDcName: trying to find DC in domain 'YTT.EDU.HK', flags: 0x40001010
02/08/2020 17:49:50:916 NetpDsGetDcName: failed to find a DC having account 'SCH-ROOT2$': 0x525, last error is 0x0
02/08/2020 17:49:53:894 NetpLoadParameters: loading registry parameters...
02/08/2020 17:49:53:894 NetpLoadParameters: DNSNameResolutionRequired not found, defaulting to '1' 0x2
02/08/2020 17:49:53:894 NetpLoadParameters: DomainCompatibilityMode not found, defaulting to '0' 0x2
02/08/2020 17:49:53:894 NetpLoadParameters: status: 0x2
02/08/2020 17:49:54:065 NetpDsGetDcName: status of verifying DNS A record name resolution for 'sch-root.ytt.edu.hk': 0x0
02/08/2020 17:49:54:065 NetpDsGetDcName: found DC '\sch-root.ytt.edu.hk' in the specified domain
02/08/2020 17:49:54:065 NetpJoinDomainOnDs: NetpDsGetDcName returned: 0x0
02/08/2020 17:49:54:065 NetpDisableIDNEncoding: using FQDN ytt.edu.hk from dcinfo
02/08/2020 17:49:54:065 NetpDisableIDNEncoding: DnsDisableIdnEncoding(UNTILREBOOT) on 'ytt.edu.hk' succeeded
02/08/2020 17:49:54:065 NetpJoinDomainOnDs: NetpDisableIDNEncoding returned: 0x0
02/08/2020 17:49:54:065 NetpJoinDomainOnDs: status of connecting to dc '\sch-root.ytt.edu.hk': 0x0
02/08/2020 17:49:54:065 NetpGetDnsHostName: PrimaryDnsSuffix defaulted to DNS domain name: ytt.edu.hk
02/08/2020 17:49:54:065 NetpProvisionComputerAccount:
02/08/2020 17:49:54:065 lpDomain: YTT.EDU.HK
02/08/2020 17:49:54:065 lpHostName: sch-root2
02/08/2020 17:49:54:065 lpMachineAccountOU: (NULL)
02/08/2020 17:49:54:065 lpDcName: sch-root.ytt.edu.hk
02/08/2020 17:49:54:065 lpMachinePassword: (null)
02/08/2020 17:49:54:065 lpAccount: YTT.EDU.HK\tss
02/08/2020 17:49:54:065 lpPassword: (non-null)
02/08/2020 17:49:54:065 dwJoinOptions: 0x27
02/08/2020 17:49:54:065 dwOptions: 0x40000003
02/08/2020 17:49:54:272 NetpLdapBind: Verified minimum encryption strength on sch-root.ytt.edu.hk: 0x0
02/08/2020 17:49:54:272 NetpLdapGetLsaPrimaryDomain: reading domain data
02/08/2020 17:49:54:272 NetpGetNCData: Reading NC data
02/08/2020 17:49:54:272 NetpGetDomainData: Lookup domain data for: DC=ytt,DC=edu,DC=hk
02/08/2020 17:49:54:272 NetpGetDomainData: Lookup crossref data for: CN=Partitions,CN=Configuration,DC=ytt,DC=edu,DC=hk
02/08/2020 17:49:54:272 NetpLdapGetLsaPrimaryDomain: result of retrieving domain data: 0x0
02/08/2020 17:49:54:272 NetpCheckForDomainSIDCollision: returning 0x0(0).
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Cracking DNS domain name ytt.edu.hk/ into Netbios on \sch-root.ytt.edu.hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Crack results: name = YTT
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Cracking account name YTT\SCH-ROOT2$ on \sch-root.ytt.edu.hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Crack results: Account does not exist
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Cracking Netbios domain name YTT\ into root DN on \sch-root.ytt.edu.hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Crack results: name = DC=ytt,DC=edu,DC=hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Got DN CN=SCH-ROOT2,CN=Computers,DC=ytt,DC=edu,DC=hk from the default computer container
02/08/2020 17:49:54:272 NetpModifyComputerObjectInDs: Initial attribute values:
02/08/2020 17:49:54:272 objectClass = Computer
02/08/2020 17:49:54:272 SamAccountName = SCH-ROOT2$
02/08/2020 17:49:54:272 userAccountControl = 0x1000
02/08/2020 17:49:54:272 DnsHostName = sch-root2.ytt.edu.hk
02/08/2020 17:49:54:272 ServicePrincipalName = HOST/sch-root2.ytt.edu.hk RestrictedKrbHost/sch-root2.ytt.edu.hk HOST/SCH-ROOT2 RestrictedKrbHost/SCH-ROOT2
02/08/2020 17:49:54:272 unicodePwd =
02/08/2020 17:49:54:272 NetpModifyComputerObjectInDs: Computer Object does not exist in OU
02/08/2020 17:49:54:272 NetpModifyComputerObjectInDs: Attribute values to set:
02/08/2020 17:49:54:272 objectClass = Computer
02/08/2020 17:49:54:272 SamAccountName = SCH-ROOT2$
02/08/2020 17:49:54:272 userAccountControl = 0x1000
02/08/2020 17:49:54:272 DnsHostName = sch-root2.ytt.edu.hk
02/08/2020 17:49:54:272 ServicePrincipalName = HOST/sch-root2.ytt.edu.hk RestrictedKrbHost/sch-root2.ytt.edu.hk HOST/SCH-ROOT2 RestrictedKrbHost/SCH-ROOT2
02/08/2020 17:49:54:272 unicodePwd =
02/08/2020 17:49:54:272 NetpMapGetLdapExtendedError: Parsed [0x2010] from server extended error string: 00002010: SvcErr: DSID-031A12D2, problem 5003 (WILL_NOT_PERFORM), data 0
02/08/2020 17:49:54:272 NetpModifyComputerObjectInDs: ldap_add_s failed: 0x35 0x3eb
02/08/2020 17:49:54:272 NetpCreateComputerObjectInDs: NetpModifyComputerObjectInDs failed: 0x3eb
02/08/2020 17:49:54:272 NetpCreateComputerObjectInDsW2K: Try again setting password separately from creation i.e. DC may be W2K
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Cracking DNS domain name ytt.edu.hk/ into Netbios on \sch-root.ytt.edu.hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Crack results: name = YTT
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Cracking account name YTT\SCH-ROOT2$ on \sch-root.ytt.edu.hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Crack results: Account does not exist
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Cracking Netbios domain name YTT\ into root DN on \sch-root.ytt.edu.hk
02/08/2020 17:49:54:272 NetpGetComputerObjectDn: Crack results: name = DC=ytt,DC=edu,DC=hk
02/08/2020 17:49:54:288 NetpGetComputerObjectDn: Got DN CN=SCH-ROOT2,CN=Computers,DC=ytt,DC=edu,DC=hk from the default computer container
02/08/2020 17:49:54:288 NetpModifyComputerObjectInDs: Initial attribute values:
02/08/2020 17:49:54:288 objectClass = Computer
02/08/2020 17:49:54:288 SamAccountName = SCH-ROOT2$
02/08/2020 17:49:54:288 userAccountControl = 0x1000
02/08/2020 17:49:54:288 DnsHostName = sch-root2.ytt.edu.hk
02/08/2020 17:49:54:288 ServicePrincipalName = HOST/sch-root2.ytt.edu.hk RestrictedKrbHost/sch-root2.ytt.edu.hk HOST/SCH-ROOT2 RestrictedKrbHost/SCH-ROOT2
02/08/2020 17:49:54:288 NetpModifyComputerObjectInDs: Computer Object does not exist in OU
02/08/2020 17:49:54:288 NetpModifyComputerObjectInDs: Attribute values to set:
02/08/2020 17:49:54:288 objectClass = Computer
02/08/2020 17:49:54:288 SamAccountName = SCH-ROOT2$
02/08/2020 17:49:54:288 userAccountControl = 0x1000
02/08/2020 17:49:54:288 DnsHostName = sch-root2.ytt.edu.hk
02/08/2020 17:49:54:288 ServicePrincipalName = HOST/sch-root2.ytt.edu.hk RestrictedKrbHost/sch-root2.ytt.edu.hk HOST/SCH-ROOT2 RestrictedKrbHost/SCH-ROOT2
02/08/2020 17:49:54:288 NetpMapGetLdapExtendedError: Parsed [0x2010] from server extended error string: 00002010: SvcErr: DSID-031A12D2, problem 5003 (WILL_NOT_PERFORM), data 0
02/08/2020 17:49:54:288 NetpModifyComputerObjectInDs: ldap_add_s failed: 0x35 0x3eb
02/08/2020 17:49:54:288 NetpCreateComputerObjectInDs: NetpModifyComputerObjectInDs failed: 0x3eb
02/08/2020 17:49:54:288 ldap_unbind status: 0x0
02/08/2020 17:49:54:288 NetpJoinCreatePackagePart: status:0x3eb.
02/08/2020 17:49:54:288 NetpAddProvisioningPackagePart: status:0x3eb.
02/08/2020 17:49:54:288 NetpJoinDomainOnDs: Function exits with status of: 0x3eb
02/08/2020 17:49:54:288 NetpJoinDomainOnDs: status of disconnecting from '\sch-root.ytt.edu.hk': 0x0
02/08/2020 17:49:54:288 NetpResetIDNEncoding: DnsDisableIdnEncoding(RESETALL) on 'ytt.edu.hk' returned 0x0
02/08/2020 17:49:54:288 NetpJoinDomainOnDs: NetpResetIDNEncoding on 'ytt.edu.hk': 0x0
02/08/2020 17:49:54:288 NetpDoDomainJoin: status: 0x3eb
請問我可以怎樣做???謝謝大大們
現在我先停了一台, 打算再開一台新的取代他
如果想用一台取代舊的就是將 "舊的" 先移除 DC 降成一般成員 , 再離來 AD
然後用原來的名稱再安裝新的 Server 加入 AD
再變成 DC
不想這樣做那就是 ....
用一台新的 名稱(與停機那台名不同) .. 加入 AD 再變成 DC ..
再將那台停機的 DC 移除 AD ..
我名字不是用一樣的
DC 不能同步時再加新的 DC 可能不能加 (AD 不知道
要新加入的 DC 信任哪台 DC 同步 ... )
理論上要先同步才能再加一台 DC ....
先在 AD 裡面把那 台您認為不正常的 DC 砍掉吧 ...
AD 裡面只有一台DC 時, 再加一台 DC 一般都會成功的
但我還沒到PROMOTE那一步,我只是JOIN DOMAIN已經不行了
JOIN DOMAIN 失敗 你的 DC 有相當大的問題了 .... :(
先將 AD 將五大角色都轉移到單台 DC, 卸除到只有這單 DC
把同步失敗的可能都拿掉, 先備份這台 DC (備份 AD)
JOIN DOMAIN 先搞定吧
不好意思...看不懂,請問我要怎樣做?
卸除到只單台 DC ....
JOIN DOMAIN 先搞定