As far as I know, yes.  This child domain had been working OK as of
about a week ago.  Some replication issues on one of the child DCs
showed up.  That DC was DCpromo'd out.  Some time went by and then it
was dcpromo'd in again.  The current issue appears to be ldap
connectivity between the child domain controllers and my root DC/PDC.

Mike Thommes

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
[EMAIL PROTECTED]
Sent: Wednesday, June 08, 2005 1:02 PM
To: [email protected]
Subject: RE: [ActiveDir] nltest, adfind errors

Is your child site delegation setup properly?  Are all the entries for
DCs in your child site correct?

:m:dsm:cci:mvp

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Thommes,
Michael M.
Sent: Wednesday, June 08, 2005 11:27 AM
To: [email protected]
Subject: [ActiveDir] nltest, adfind errors

Running these commands on a child domain controller:

nltest /sc_query:anl.gov /server:rhino221
I_NetLogonControl failed: Status = 1355 0x54b ERROR_NO_SUCH_DOMAIN

nltest /sc_query:anl.gov /server:tiger201
Flags: 30 HAS_IP  HAS_TIMESERV
Trusted DC Name \\rhino221.anl.gov
Trusted DC Connection Status Status = 0 0x0 NERR_Success
The command completed successfully

nltest /sc_query:anl.gov /server:hippo308
Flags: 30 HAS_IP  HAS_TIMESERV
Trusted DC Name \\rhino221.anl.gov
Trusted DC Connection Status Status = 0 0x0 NERR_Success
The command completed successfully

nltest /sc_query:anl.gov /server:bison752
Flags: 30 HAS_IP  HAS_TIMESERV
Trusted DC Name \\rhino221.anl.gov
Trusted DC Connection Status Status = 0 0x0 NERR_Success
The command completed successfully

Rhino221 holds the FSMO roles.  DNS A and SRV records seem to be OK.  

joe's adfind tool works fine from a non-privileged account on a
workstation to the child domain in searching for accounts named admin* ,
yet fails when the same adfind command is run from a root DC:

C:\SYSMGR\bin>adfind -b dc=bio,dc=anl,dc=gov -f samaccountname=admin*

AdFind V01.26.00cpp Joe Richards ([EMAIL PROTECTED]) February 2005

Using server: rhino221.anl.gov
Directory: Windows Server 2003

ldap_get_next_page_s: [rhino221.anl.gov] Error 0xa (10) - Referral

REFERRAL: ldap://bio.anl.gov/dc=bio,dc=anl,dc=gov

0 Objects returned


I am stumped!  Any thoughts out there?  Thanks.

Mike Thommes
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive:
http://www.mail-archive.com/activedir%40mail.activedir.org/


List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to