新升级的域控制器显示许多错误,但 dcpromo 没有抱怨?

新升级的域控制器显示许多错误,但 dcpromo 没有抱怨?

我有一个被分成四个站点的域。在我的一个远程站点中,我升级了一个新的 DC,并将在几周内停用现有的 DC。我在执行 dcpromo 时没有收到任何错误,但升级后我不得不推迟几天重启服务器。

重新启动后,发现这个新的 DC 上存在一些严重的问题:

  1. 目录服务日志充满了事件 1864 ( This directory server has not recently received replication information from a number of directory servers.)、2089 ( This directory partition has not been backed up since at least the following number of days.) 和 2093 ( The remote server which is the owner of a FSMO role is not responding. This server has not replicated with the FSMO role owner recently.)。
  2. 系统日志包含许多事件 1006(The processing of Group Policy failed. Windows could not authenticate to the Active Directory service on a domain controller. (LDAP Bind function call failed). Look in the details tab for error code and description.) - 来自详细信息选项卡的信息如下:

    SupportInfo1 1
    SupportInfo2 5012 
    ProcessingMode 0 
    ProcessingTimeInMilliseconds 2184 
    ErrorCode 49 
    ErrorDescription Invalid Credentials 
    DCName
    

    以及错误 4()和错误 5782()。The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server kelethdc01$. The target name used was E3514235-4B06-11D1-AB04-00C04FC2DCD2/2ee10a9d-dcf0-4940-b2e5-25044f90869c/[email protected]. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (DOMAIN.COM) is different from the client domain (DOMAIN.COM), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.Dynamic registration or deregistration of one or more DNS records failed with the following error: TCP/IP network protocol not installed.

有人能指出这里可能发生了什么,以及如何纠正吗?

答案1

我以前没有见过这种情况,但我最初的想法是,由于 Kerberos 票证是基于时间的,因此dcpromo重新启动之间的延迟可能会导致此问题。

您是否尝试过取消新服务器的推广并执行新的 dcpromo 并重新启动?

答案2

关于“此目录分区至少在以下天数内未备份。”。执行系统状态备份并备份 Active Directory 时,它会更新分区上的属性。

您可以使用以下命令确认是否/何时执行备份:

repadmin /showbackup <dcname>

可以抑制属性的更新。如果此消息仅针对架构分区显示,则可能已将其关闭。

相关内容