[cifs-protocol] Error message while trying to demote Windows 2008r2
edgaro at microsoft.com
Tue Oct 9 13:48:47 MDT 2012
Did you have a look at dcpromo.log? Please check the log and see if you can spot at which step the error is occurring. Also check which DC owns the various FSMO roles.
Then review that step and processing at Samba's side.
The DC was in the process of locating a DSA to which any remaining updates and FSMO roles can be transferred as part of demoting an NDNC replica. (NDNC - Non-Domain Naming Context). In your case it was the DomainDnsZones partition. (Question: Did you have any particular DNS configuration? )
There was no target found. The error could be due to the following:
1. Failure to convert NC name into a DNS name,
You should see DsCrackNames () on the wire that includes these:
2. Failure to find another DC that hosts this NC
You will see something equivalent to DsGetDcName() on the wire. This is like a DC location.
The first time, if the DC could not find an appropriate entry in the cache that matches these
Flags = DS_AVOID_SELF | DS_IS_DNS_NAME | DS_RETURN_DNS_NAME | DS_ONLY_LDAP_NEEDED | DS_WRITABLE_REQUIRED | DS_DIRECTORY_SERVICE_REQUIRED
the second time, it will force the DC locator to refresh its cache.
Flags |= DS_FORCE_REDISCOVERY
3. Failure to translate the DSA DNS name into an DSA DN.
You will see an LDAP search on the wire. If it's successful, then it will extract the dsServiceName attribute.
The operation failed because Active Directory Domain Services could not transfer the remaining data in the directory partition DC=DomainDnsZones,DC=DomainName,DC=Local to Active Directory Domain Controller DCName
Error message when you run the "Adprep /rodcprep" command in Windows Server 2008: "Adprep could not contact a replica for partition DC=DomainDnsZones,DC=Contoso,DC=com"
dcpromo remove domain controller failed
Demoting a Domain Controller Error
Add or remove an application directory partition replica
From: Edgar Olougouna
Sent: Tuesday, October 02, 2012 4:27 PM
To: 'Matthieu Patou'; pfif at tridgell.net; cifs-protocol at samba.org
Subject: RE: Error message while trying to demote Windows 2008r2
I will review the code, trace this error and find out the possible reasons.
From: Matthieu Patou [mailto:mat at matws.net]
Sent: Tuesday, October 02, 2012 1:19 AM
To: Edgar Olougouna; pfif at tridgell.net; cifs-protocol at samba.org
Subject: Error message while trying to demote Windows 2008r2
Find attached the error message that we had in IOLab when trying to demote Windows DC.
I checked that the crossRef objects related to the DNS partitions have a msDS-NC-Replica-Locations attribute for the DC to demote and the other DC, I also checked that the nTDSDSA object for the samba DC has the attribute msDS-HasInstantiatedNCs and msDS-HasInstantiatedNCs set for those two applications NC.
Thanks for investigating.
More information about the cifs-protocol