Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Windows 2003 Server AD question

Hi!

I am onsite today and am starting to install a new Windows 2003 server and some workstations. The server is setup, but when I went to setup Active Directory, I had forgot to setup DNS first. The AD setup prompted me to install DNS, which I did, but now when the server starts, I get these event codes:

4015: The DNS server has encountered a critical error from the Active Directory. Check that the AD is functioning properly.....

and

4004: The DNS server was unable to complete directory service enumeration of zone ..

I have looked it up online, but have not found a clear answer. Any ideas? The server has been running for about 45 minutes and those errors only happened on reboot (each time). After the computer has booted, there are no more errors.

A piece of info I found, said that if the DNS server starts before AD, these errors show up.

Did I miss a step? Any help would be great.

Dave

__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 10-04-2007, 02:49 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
Join Date: Nov 2003
Location: Seattle
Posts: 1,785
I think the easiest fix if you haven't done a ton of work putting users and such in would be to demote and repromote it and see what happens.

Go to a command prompt and run DCPromo and kill off the domain and then again to rebuild it.

If DNS isn't functioning properly when the domain is built, it can be fixed, but it's very rarely worth the time unless you have something you're trying to rescue.
__________________
Rob
1980 SC - 2011 Tiguan - 2018 Tesla M3P
Old 10-04-2007, 03:40 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
I actually had to do that anyway. I used the wrong domain name. We'll see if it happens again.

Thanks,

Dave
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 10-04-2007, 03:47 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
Join Date: May 2001
Location: Hurst, TX. USA
Posts: 804
Actually, I know how to fix this without demoting the server. (5 years working for Microsoft in the Active Directory Support group).

Check your DNS settings on the server. It needs to register in DNS when it starts AD. It sounds like you have it pointed at a different DNS server that doesn't allow dynamic updates.

Point it to itself for DNS.
__________________
Clay Perrine
74 914 1.8L (Frodrick)
73 914 /6 4.0L 964 motor (Igor)
70 914 /6 Factory Six. (Elwood)
95 BMW 540i (Inga)
Old 10-04-2007, 04:02 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Registered
 
robs944's Avatar
 
Join Date: Dec 2000
Location: Aiken, SC
Posts: 343
Garage
slodave
I have seen this on some AD environments that I have worked on.
Do you have only 1 DC in this domain? If you have 2 than you can point DC1 primary DNS settings to DC2 and vise versa.
Have you run netdiag to see if you get a failure?

Of course it sounds like you may have found your problem.

Clay Perrine
5 years of MS AD support- do you have any hair left?
If you point it to itself I think you may get the same errors in the log, since when the DC is booting up AD may not be fully initialized (depending on what else is starting up on the DC).

Just a thought.

Rob
__________________
Rob
87 944 * 89 951
"When I die, I want to go peacefully like my Grandfather did, in his sleep -- not screaming, like the passengers in his car."
Old 10-04-2007, 04:30 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
Join Date: Dec 2002
Location: www.fakelife.com
Posts: 1,672
Send a message via AIM to SlowToady
You're running DHCP, also, right? I got this exact same error on a 2003 Server I manage. How I fixed it was to configure DNS Dynamic update credentials.

I remember doing it from the command line, but I can't seem to find or remember the commands, so instead, I'm going to point you to the TechNet article I found about it.

TechNet: DNs Dynamic update credentials

Let us know if that works for you.
__________________
I turn away with fear and horror from this lamentable sore of continuous functions without derivatives. --Charles Hermite

Fakelife.com Nothing to do with archery anymore. Porsche/BMW/Ferrari/Honda videos
Old 10-04-2007, 05:22 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
I forgot to check the logs before I left this evening, but after demoting and recreating the AD (I used the wrong domain), the error on startup - at least one service failed.... did not show up. I'll check the logs in the morning.

Thanks for the advice and help!

Dave
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 10-04-2007, 05:24 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
The same three errors were there today. After the server boots and logs those three, they do not appear again. I wonder if it has to do with the services loading out of order. I am still in the setup stage of the workstations, so I am not worrying about it too much and the wkstations are not having any problems with DHCP, DNS or authenticating against the server.

The server is managing DNS, DHCP and AD. DNS is pointing to itself.

Dave
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 10-05-2007, 02:36 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Slackerous Maximus
 
HardDrive's Avatar
 
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,164
All evil in the world of AD comes back to DNS.

Is the DNS suffix on the DC correct?

Are the SRV record being created correctly? You should have a delegation record in the zone file, and a seperate .msdcs zone with your SRV records for the domain. If the SRV records are not being created properly, the DC does know its a DC! All boxes, DCs included, rely on the SRV records to confirm which machines are DCs.

__________________
2022 Royal Enfield Interceptor.
2012 Harley Davidson Road King
2014 Triumph Bonneville T100.
2014 Cayman S, PDK.
Mercedes E350 family truckster.
Old 10-05-2007, 06:30 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Reply


 


All times are GMT -8. The time now is 01:08 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.