DC's are unable to perform BIND.


hi everyone,

i getting weird error having hard time troubleshooting. environment has 3 domain controllers, dc1 dc2 , dc3. getting errors when performing manual replications, getting access denied when opening gpmc (as aduc, sites , services, etc) console when connected dc. 

dc1 , dc2 have trouble connecting other domain controllers. unable force sync these domain controllers using repadmin /syncall.

here result of repadmin /syncall on dc1 , dc2:

callback message: error contacting server a9326fa6-e465-4a55-8fe4-143f4d2100e8._msdcs.fqdn.com (network error): 5 (0x5):        access denied.    callback message: error contacting server 3dc7a026-c031-4bdc-915f-f200e0aebcba._msdcs.fqdn.com (network error): 5 (0x5):        access denied.    callback message: error contacting server 83ce846e-4d0a-485e-a414-4ac5abc39bc5._msdcs.fqdn.com (network error): 5 (0x5):        access denied.        syncall exited fatal win32 error: 8440 (0x20f8):        naming context specified replication operation invalid.    

from dc3 dc1 , dc2 works fine.

repadmin /showrepl on each dc shows successful directory partitions.


from dc1 , dc2, here result repadmin /bind dc3

error: ldap lookup operation failed following error:   

ldap error 49(0x31): invalid credentials   

server win32 error 0(0x0):   

extended information:


does have idea on how can further troubleshoot this?

 

hi all,

i figured out why throwing error message. logged domain controller domain admin account , worked fine. narrowed down personal account. have domain similar namespace , had put in *.contoso.com address in credential manager. because have similar dns suffixes, used expired credential domain throwing access denied messages. all-in-all, user error. d'oh!

thanks everyone's suggestions , trying solve this. 



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Motherboard replacement

Cannot create Full Text Search catalog after upgrading to V12 - Database is not fully started up or it is not in an ONLINE state

Remote Desktop App - Error 0x207 or 0x607