- 2003 server joining domain problem
- Posted by goonaa on November 22nd, 2005
Hi all,
I have had to rebuild SBS2000 server after major HW failure, all XPPro
pc's have rejoined the new domain with no trouble, however I have one
2003 server which refuses to rejoin the domain.
I have done all the usual tasks;
· renamed server & reboot - error message "Cannot log you in
because the domain is available"
· moved server to workgroup - OK
· tried to move server back to domain - error message "Cannot log
you in because the domain is available"
· Removed computer account from AD - same as above
· Reset computer account in AD - same as above
I next turned my attentions to a possible DNS issue.
· Changed IP to dynamic which gives me all required and correct
information (as per XPPro pc's), & LMHOSTS & HOSTS have correct
entries. Went through process as above, still no joy.
· Reverted to static IP, still no joy.
I have run out of ideas to get this 2003 server to rejoin the domain,
next step is a rebuild but that is drastic for what should be a
straightforward exercise!
Any ideas anyone?
Regards
- Posted by John Oliver, Jr. [MVP] on November 23rd, 2005
Was this Windows 2003 Server a member server in your SBS Domain? Anything
in the event viewer when trying to join the server to the domain? Have you
tried running NETDIAG on the 2003 server?
--
John Oliver, Jr.
MCSE, MCT, CCNA, Exchange MVP
Microsoft Certified Partner
"goonaa" <chammond@bigpond.net.au> wrote in message
news:1132624462.292564.237670@g47g2000cwa.googlegr oups.com...
Hi all,
I have had to rebuild SBS2000 server after major HW failure, all XPPro
pc's have rejoined the new domain with no trouble, however I have one
2003 server which refuses to rejoin the domain.
I have done all the usual tasks;
· renamed server & reboot - error message "Cannot log you in
because the domain is available"
· moved server to workgroup - OK
· tried to move server back to domain - error message "Cannot log
you in because the domain is available"
· Removed computer account from AD - same as above
· Reset computer account in AD - same as above
I next turned my attentions to a possible DNS issue.
· Changed IP to dynamic which gives me all required and correct
information (as per XPPro pc's), & LMHOSTS & HOSTS have correct
entries. Went through process as above, still no joy.
· Reverted to static IP, still no joy.
I have run out of ideas to get this 2003 server to rejoin the domain,
next step is a rebuild but that is drastic for what should be a
straightforward exercise!
Any ideas anyone?
Regards
- Posted by goonaa on November 23rd, 2005
yes it was a member server and event viewer shows the following after
joining the domain;
Eventid 3260
This computer has been successfully joined to domain 'torque'.
then, when trying to login to the domain rather than the server;
Event id 5719
This computer was not able to set up a secure session with a domain
controller in domain TORQUE due to the following:
The remote procedure call failed and did not execute.
This may lead to authentication problems. Make sure that this computer
is connected to the network. If the problem persists, please contact
your domain administrator.
ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it
sets up the secure session to the primary domain controller emulator in
the specified domain. Otherwise, this computer sets up the secure
session to any domain controller in the specified domain.
then;
Event id 18
The time provider NtpClient failed to establish a trust relationship
between this computer and the torque.local domain in order to securely
synchronize time. NtpClient will try again in 15 minutes. The error
was: The trust relationship between this workstation and the primary
domain failed. (0x800706FD)
it appears that it thinls it has joined the domain then it has a messed
up SID and has to go back to a workgroup again.
this makes me very mad now!!
- Posted by John Oliver, Jr. [MVP] on November 23rd, 2005
Have you tried just going into ADUC on the SBS Server and deleting the
Windows 2003 server under Computers? You will have to rejoin the domain but
everything should work normally.
--
John Oliver, Jr.
MCSE, MCT, CCNA, Exchange MVP
Microsoft Certified Partner
"goonaa" <chammond@bigpond.net.au> wrote in message
news:1132726557.543686.271870@o13g2000cwo.googlegr oups.com...
- Posted by goonaa on November 23rd, 2005
done that - this is what happens, after entering the username and
password to join the domain, but before it comes back with the error
message, "remote procedure call failed and did not execute" the 2003
server appears in the ADUC on the SBS server as you would expect.
However as soon as the above error message is returned in the SBS ADUC
the 2003 server has a red cross by it. Reseting & enabling the 2003
computer account makes no difference and i have to go back to my
workgroup.
- Posted by John Oliver, Jr. [MVP] on November 23rd, 2005
Can you please post the relevant Event ID's associated with rpc call failure
in the Event Viewer on the SBS Server. Or look them at www.eventid.net to
see if you get any further. Also, is the Windows 2003 Server Multihomed or
does it have two NIC's? And just verify again that the Primary DNS Server on
the Windows 2003 NIC is the SBS Server. Also make sure the Date/Time is
correct on the Windows 2003 server.
--
John Oliver, Jr.
MCSE, MCT, CCNA, Exchange MVP
Microsoft Certified Partner
"goonaa" <chammond@bigpond.net.au> wrote in message
news:1132781186.919918.24120@g47g2000cwa.googlegro ups.com...
- Posted by AAFC on December 4th, 2005
Could it perhaps be a secure channel issue?
There is a utility from the resource kit that enables you to
verify/regenerate the secure channel but I do not remeber the name.
"goonaa" <chammond@bigpond.net.au> wrote in message
news:1132624462.292564.237670@g47g2000cwa.googlegr oups.com...
Hi all,
I have had to rebuild SBS2000 server after major HW failure, all XPPro
pc's have rejoined the new domain with no trouble, however I have one
2003 server which refuses to rejoin the domain.
I have done all the usual tasks;
· renamed server & reboot - error message "Cannot log you in
because the domain is available"
· moved server to workgroup - OK
· tried to move server back to domain - error message "Cannot log
you in because the domain is available"
· Removed computer account from AD - same as above
· Reset computer account in AD - same as above
I next turned my attentions to a possible DNS issue.
· Changed IP to dynamic which gives me all required and correct
information (as per XPPro pc's), & LMHOSTS & HOSTS have correct
entries. Went through process as above, still no joy.
· Reverted to static IP, still no joy.
I have run out of ideas to get this 2003 server to rejoin the domain,
next step is a rebuild but that is drastic for what should be a
straightforward exercise!
Any ideas anyone?
Regards