Awhile back I set up a domain named xxx.com but followed the 81-page
"Step-by-Step Guide to Implementing Domain Rename" procedure at
http://www.microsoft.com/technet/dow...ainrename.mspx to the
best of my ability. But I must have missed something there.
Most everything has worked out fine. But I keep getting a persistent error
when when I run netdiag /fix:
DNS test . . . . . . . . . . . . . : Failed
[FATAL] Failed to fix: DC DNS entry xxx.com. re-registeration on DNS
server '192.168.254.13' failed.
DNS Error code: DNS_ERROR_RCODE_NOT_IMPLEMENTED
[FATAL] Failed to fix: DC DNS entry xxx.com. re-registeration on DNS
server '192.168.254.13' failed.
DNS Error code: DNS_ERROR_RCODE_NOT_IMPLEMENTED
[FATAL] Failed to fix: DC DNS entry _ldap._tcp.xxx.com. re-registeration
on DNS server '192.168.254.13' failed.
and many more such.
I can edit C:\WINDOWS\system32\config\netlogon.dns and netlogon.dns to
either remove bogus xxx.com entries or change them to xxx.net and when I run
netdiag /fix after doing that it doesn't complain. But as soon as I restart
the netlogon service, those two files revert to the way they were and netdiag
/fix fails the same way. Looking at netlogon.dns it looks for the most part
as if there are duplicate entries for xxx.com and xxx.net.
When I go into Administrative Tools\DNS everthing looks just fine: there are
no traces left there of xxx.com.
Related symptom #1: Every time I restart the NetLogon service, I get a
couple Event ID: 5781, Source: NETLOGON errors in the System Event Viewer,
the first of which reads:
Dynamic registration or deletion of one or more DNS records associated with
DNS domain 'xxx.com.' failed. These records are used by other computers to
locate this server as a domain controller (if the specified domain is an
Active Directory domain) or as an LDAP server (if the specified domain is an
application partition).
Possible causes of failure include:
- TCP/IP properties of the network connections of this computer contain
wrong IP address(es) of the preferred and alternate DNS servers - no, this is
OK
- Specified preferred and alternate DNS servers are not running - this is
OK too
- DNS server(s) primary for the records to be registered is not running -
this is OK
- Preferred or alternate DNS servers are configured with wrong root hints -
I don't know where to find this
- Parent DNS zone contains incorrect delegation to the child zone
authoritative for the DNS records that failed registration - I don't think I
set up any child zones
USER ACTION
Fix possible misconfiguration(s) specified above and initiate registration
or deletion of the DNS records by running 'nltest.exe /dsregdns' (I ran this
and it returned 'Flags: 0
Connection Status = 0 0x0 NERR_Success
The command completed successfully') from the command prompt or by
restarting Net Logon service. Nltest.exe is available in the Microsoft
Windows Server Resource Kit CD.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp
Related symptoms #2 (and my most pressing problem): I can't run
Administrative Tools\Domain Security Policy 'cause it keeps saying, "Failed
to open the Group Policy Object. You may not have appropriate rights."
Details: "The network path was not found".
I'm doing all this from the Administrator account for the domain.
I've scoured the registry for all instances of xxx.com and replaced them
with xxx.net. I looked for all instances of xxx.com on the C drive but
mainly only found the C:\WINDOWS\system32\config\netlogon.dns and
netlogon.dns files and a bunch of log entries.
So I don't know what else to try.


Reply With Quote

Bookmarks