如何为域重新安装 AD DS

如何为域重新安装 AD DS

旧服务器:服务器新服务器:AUTHSRV 我正在实验室里玩耍,当我添加新服务器时我似乎没有正确删除旧的 AD DS 服务器,所以现在我无法将新计算机添加到 AD DS。

这是我收到的错误: 在此处输入图片描述

我应该从哪个方向去查明导致这种情况的原因?

我最终从 Active Directory 站点和服务中删除了旧服务器,但我不确定这是否正确。

编辑:

PS C:\Users\administrator.INTERNAL> ntdsutil
C:\Windows\system32\ntdsutil.exe: metadata cleanup
metadata cleanup: remove selected server SERVER
Binding to localhost ...
Connected to localhost using credentials of locally logged on user.
LDAP error 0x22(34 (Invalid DN Syntax).
Ldap extended error message is 0000208F: NameErr: DSID-03100225, problem 2006 (BAD_NAME), data 8350, best match of:
        'CN=Ntds Settings,SERVER'

Win32 error returned is 0x208f(The object name has bad syntax.)
)
Unable to determine the domain hosted by the Active Directory Domain Controller (5). Please use the connection menu to s
pecify it.

编辑:

PS C:\Users\administrator.INTERNAL> dcdiag

Directory Server Diagnosis

Performing initial setup:
   Trying to find home server...
   Home Server = authsrv
   * Identified AD Forest.
   Done gathering initial info.

Doing initial required tests

   Testing server: CITY-HQ\AUTHSRV
      Starting test: Connectivity
         ......................... AUTHSRV passed test Connectivity

Doing primary tests

   Testing server: CITY-HQ\AUTHSRV
      Starting test: Advertising
         ......................... AUTHSRV passed test Advertising
      Starting test: FrsEvent
         ......................... AUTHSRV passed test FrsEvent
      Starting test: DFSREvent
         There are warning or error events within the last 24 hours after the SYSVOL has been shared.  Failing SYSVOL
         replication problems may cause Group Policy problems.
         ......................... AUTHSRV failed test DFSREvent
      Starting test: SysVolCheck
         ......................... AUTHSRV passed test SysVolCheck
      Starting test: KccEvent
         ......................... AUTHSRV passed test KccEvent
      Starting test: KnowsOfRoleHolders
         Warning:
         CN=NTDS Settings\0ADEL:05f209fb-df38-424f-8660-52a43ce83c8e,CN=SERVER\0ADEL:fe8837d6-377c-4763-a3b8-409b2235ef9
e,CN=Servers,CN=CITY-HQ,CN=Sites,CN=Configuration,DC=internal,DC=DOMAIN,DC=com
         is the Schema Owner, but is deleted.
         ......................... AUTHSRV failed test KnowsOfRoleHolders
      Starting test: MachineAccount
         ......................... AUTHSRV passed test MachineAccount
      Starting test: NCSecDesc
         ......................... AUTHSRV passed test NCSecDesc
      Starting test: NetLogons
         ......................... AUTHSRV passed test NetLogons
      Starting test: ObjectsReplicated
         ......................... AUTHSRV passed test ObjectsReplicated
      Starting test: Replications
         ......................... AUTHSRV passed test Replications
      Starting test: RidManager
         ......................... AUTHSRV passed test RidManager
      Starting test: Services
         ......................... AUTHSRV passed test Services
      Starting test: SystemLog
         ......................... AUTHSRV passed test SystemLog
      Starting test: VerifyReferences
         ......................... AUTHSRV passed test VerifyReferences


   Running partition tests on : ForestDnsZones
      Starting test: CheckSDRefDom
         ......................... ForestDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... ForestDnsZones passed test CrossRefValidation

   Running partition tests on : DomainDnsZones
      Starting test: CheckSDRefDom
         ......................... DomainDnsZones passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... DomainDnsZones passed test CrossRefValidation

   Running partition tests on : Schema
      Starting test: CheckSDRefDom
         ......................... Schema passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Schema passed test CrossRefValidation

   Running partition tests on : Configuration
      Starting test: CheckSDRefDom
         ......................... Configuration passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... Configuration passed test CrossRefValidation

   Running partition tests on : internal
      Starting test: CheckSDRefDom
         ......................... internal passed test CheckSDRefDom
      Starting test: CrossRefValidation
         ......................... internal passed test CrossRefValidation

   Running enterprise tests on : internal.DOMAIN.com
      Starting test: LocatorCheck
         ......................... internal.DOMAIN.com passed test LocatorCheck
      Starting test: Intersite
         ......................... internal.DOMAIN.com passed test Intersite
PS C:\Users\administrator.INTERNAL>

答案1

你应该做一个元数据清理从您的 AD 中删除已退役 DC 的痕迹。

您还应该确保所有 FSMO 角色均由任一活动域控制器承担,抢占角色如果不是的话。

运行诊断工具还可能提供有关域控制器整体运行状况的有用信息。

根据您的 dcdiag 输出,您删除的 DC 仍然是架构所有者(并且可能还具有其他 FSMO 角色)。

你需要强行夺取角色,它们对于正在运行的 AD 至关重要。您的元数据清理可能会成功。

相关内容