Tech Support > Operating Systems > Windows 2003 > Active Directory Schema Mismatch
Active Directory Schema Mismatch
Posted by Kurt on March 4th, 2004


Hello All,
I am getting 3 messages in my Directory services event
log, complaining about the active directory Schema has a
mismatch. The messages are as follows:
1)
The local domain controller could not replicate the
following object from the source domain controller at the
following network address because of an Active Directory
schema mismatch.

Object:
CN=Myserver,CN=Servers,CN=First Administrative
Group,CN=Administrative Groups,CN=My Domain,CN=Microsoft
Exchange,CN=Servi
Network address:xxxx-xxxxx-xxxxx-xxxxx-
xxxxx._msdcs.MyDomain.com

Active Directory will attempt to synchronize the schema
before attempting to synchronize the following directory
partition.
Directory partition:CN=Configuration,DC=My Domain,DC=com
2)
Replication of Naming Context
CN=Configuration,DC=Mydomain,DC=com from source
xxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx has been aborted.
Replication requires consistent
schema but last attempt to sync the schema had failed. It
is crucial that schema
replication functions properly. See previous errors for
more diagnostics. If this
issue persists, please contact Microsoft Product Support
Services for assistance.
Error 8418: The replication operation failed because of a
schema mismatch between the servers involved..
3) This was an error about duplicate event logs being
supressed.


I have 2 2003 server that are DC and one that is just a
member server. The member server is the computer that
the DC's are complaining about. The member server is
also an Exchange server 2003. Is there any way to restart
the replication process over and push it down to my
member server. Any help wil be greatly appreciated.

Kurt

Posted by Chriss3 on March 4th, 2004


Kurt, Do you familiar with the repadmin tool? To use repadmin tool at the
particular Domain Controller install the Windows Server Support Tools from
your Windows Server CD. Type the follow If you run the repadmin /showreps /v
command and post back the results. Also have a look at the KB below here.

Active Directory Replication Delayed When Indexed Attributes Rebuilt During
Schema Upgrade:
http://support.microsoft.com/default...b;en-us;307323

--
Regards
Christoffer Andersson

No email replies please - reply in the newsgroup

"Kurt" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:6fb601c40209$37b693d0$a401280a@phx.gbl...


Posted by Kurt on March 4th, 2004


Thanks Chris,
Here is the output of that command.::
Souwest-energy\SWESRV02

DC Options: IS_GC

Site Options: (none)

DC object GUID: c7625196-b33d-49f1-be2f-ad7670908baa

DC invocationID: 593f6a3c-61a0-4376-80b8-1cc238500007



==== INBOUND NEIGHBORS
======================================



DC=souwest-energy,DC=com

Souwest-energy\SWESRV04\0ADEL:be390433-376d-42ca-82c7-
e76c9e9fcf3a (deleted DSA) via RPC

DC object GUID: baaa2d59-c34c-4278-be7a-
f4717b95e3f5

Address: baaa2d59-c34c-4278-be7a-
f4717b95e3f5._msdcs.souwest-energy.com

DC invocationID: 84f4b72b-14f2-44e8-a4f8-
8028ea10a658

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 402736/OU, 402736/PU

Last attempt @ 2004-03-04 11:56:41 failed, result
8524 (0x214c):

The DSA operation is unable to proceed
because of a DNS lookup failure.

348 consecutive failure(s).

Last success @ 2004-02-18 09:21:31.

Souwest-energy\SWESRV03 via RPC

DC object GUID: b68c649c-d625-4864-836f-
efc254021f26

Address: b68c649c-d625-4864-836f-
efc254021f26._msdcs.souwest-energy.com

DC invocationID: 55f1015f-71d4-427a-9a6a-
0fa344dc2390

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 316007/OU, 316007/PU

Last attempt @ 2004-03-04 11:56:41 was successful.

Souwest-energy\SWESRV01 via RPC

DC object GUID: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540

Address: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540._msdcs.souwest-energy.com

DC invocationID: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 779202/OU, 779202/PU

Last attempt @ 2004-03-04 11:56:41 was successful.



CN=Configuration,DC=souwest-energy,DC=com

Souwest-energy\SWESRV04\0ADEL:be390433-376d-42ca-82c7-
e76c9e9fcf3a (deleted DSA) via RPC

DC object GUID: baaa2d59-c34c-4278-be7a-
f4717b95e3f5

Address: baaa2d59-c34c-4278-be7a-
f4717b95e3f5._msdcs.souwest-energy.com

DC invocationID: 84f4b72b-14f2-44e8-a4f8-
8028ea10a658

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 402713/OU, 402713/PU

Last attempt @ 2004-03-04 11:56:41 failed, result
8524 (0x214c):

The DSA operation is unable to proceed
because of a DNS lookup failure.

348 consecutive failure(s).

Last success @ 2004-02-18 09:18:55.

Souwest-energy\SWESRV03 via RPC

DC object GUID: b68c649c-d625-4864-836f-
efc254021f26

Address: b68c649c-d625-4864-836f-
efc254021f26._msdcs.souwest-energy.com

DC invocationID: 55f1015f-71d4-427a-9a6a-
0fa344dc2390

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 315933/OU, 315933/PU

Last attempt @ 2004-03-04 11:56:41 was successful.

Souwest-energy\SWESRV01 via RPC

DC object GUID: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540

Address: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540._msdcs.souwest-energy.com

DC invocationID: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 775355/OU, 775355/PU

Last attempt @ 2004-03-04 11:56:41 was delayed
for a normal reason, result 8418 (0x20e2):

The replication operation failed because of a schema
mismatch between the servers involved.

Last success @ 2004-03-03 14:23:17.



CN=Schema,CN=Configuration,DC=souwest-energy,DC=com

Souwest-energy\SWESRV04\0ADEL:be390433-376d-42ca-82c7-
e76c9e9fcf3a (deleted DSA) via RPC

DC object GUID: baaa2d59-c34c-4278-be7a-
f4717b95e3f5

Address: baaa2d59-c34c-4278-be7a-
f4717b95e3f5._msdcs.souwest-energy.com

DC invocationID: 84f4b72b-14f2-44e8-a4f8-
8028ea10a658

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 402533/OU, 402533/PU

Last attempt @ 2004-03-04 11:56:41 failed, result
8524 (0x214c):

The DSA operation is unable to proceed
because of a DNS lookup failure.

348 consecutive failure(s).

Last success @ 2004-02-18 08:50:32.

Souwest-energy\SWESRV03 via RPC

DC object GUID: b68c649c-d625-4864-836f-
efc254021f26

Address: b68c649c-d625-4864-836f-
efc254021f26._msdcs.souwest-energy.com

DC invocationID: 55f1015f-71d4-427a-9a6a-
0fa344dc2390

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 315859/OU, 315859/PU

Last attempt @ 2004-03-04 11:56:41 was successful.

Souwest-energy\SWESRV01 via RPC

DC object GUID: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540

Address: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540._msdcs.souwest-energy.com

DC invocationID: fd46fdac-cb1c-4ef5-b62d-
55ac5b56d540

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 779204/OU, 779204/PU

Last attempt @ 2004-03-04 11:56:41 was successful.



DC=DomainDnsZones,DC=souwest-energy,DC=com

Souwest-energy\SWESRV03 via RPC

DC object GUID: b68c649c-d625-4864-836f-
efc254021f26

Address: b68c649c-d625-4864-836f-
efc254021f26._msdcs.souwest-energy.com

DC invocationID: 55f1015f-71d4-427a-9a6a-
0fa344dc2390

SYNC_ON_STARTUP DO_SCHEDULED_SYNCS WRITEABLE

USNs: 315834/OU, 315834/PU

Last attempt @ 2004-03-04 11:56:42 was successful.


Posted by Chriss3 on March 4th, 2004


I suppose you have correct the DNS Lookup problem.

The DSA operation is unable to proceed
because of a DNS lookup failure

Have you performed the AD Prep tools for preparing the forest and domain for
Windows Server 2003 Domain Controllers?

--
Regards
Christoffer Andersson

No email replies please - reply in the newsgroup

"Kurt" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:74df01c40217$c2d1f6e0$a101280a@phx.gbl...


Posted by Kurt on March 4th, 2004


I wasn't actually sure which server was the problem.
From taking a cursery look at the output it looks like
the problem is swesrv04 but that is a deleted server??
Please advise.
Kurt

Posted by Chriss3 on March 4th, 2004


Hi Kurt, I have to ask are you Swedish?

it look more likes swesrv04.

How ever remove all demounted Domain Controllers from the Active Directory.

Are the adprep tools preformed on your domain in order to upgrade the schema
compability for Windows Server 2003 Domain Controllers?

--
Regards
Christoffer Andersson

No email replies please - reply in the newsgroup

"Kurt" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:70db01c4022d$e2e949e0$a501280a@phx.gbl...


Posted by kurt on March 5th, 2004


Hello Chris
I am not swedish the SWE part of the name stands for the company that I work for. I thought that I had removed the demoted/crashed domain controller (i.e. swesrv04). The adprep tools were run both the forsestprep and domainprep. this setup was work as of about 2 days ago. I'm not really sure what happened.

Posted by Chriss3 on March 5th, 2004


Hi Kurt.

We have to find out if the preparation was successful. First Check the logs
of adprep you can find them in the follow location:
%SystemRoot%\system32\debug\adprep\logs

Each time ADPrep is executed, a new log file is generated that contains the
actions taken during that particular invocation. The log files are named
based on the time and date ADPrep was run.

Do you familiar with ADSI Edit tool? since you used repadmin I suppose you
have Windows Server Support Tools installed, Start ADSI Edit from the
startmenu or type ADSIedit.msc in the run field. How to find he
Windows2003Update object in the Configuration Naming Context and the Domain
Naming Context are found in the follow article:
http://www.microsoft.com/technet/pro...on126121120120

I also have to ask, where all existing Windows 2000 Domain Controllers
running SP4?

Dose Exchange 2000 exist in the organization?

Also make sure the DNS problems reported in repadmin /showreps /v are
corrected.

Have a nice weekend.
--
Regards
Christoffer Andersson

No email replies please - reply in the newsgroup

"kurt" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:9022ED5E-6B46-4650-9C16-03B52790EBFE@microsoft.com...
controller (i.e. swesrv04). The adprep tools were run both the forsestprep
and domainprep. this setup was work as of about 2 days ago. I'm not really
sure what happened.



Posted by Kurt on March 5th, 2004


Hello Chris,
I am really trying to get rid of the server swesrv01
and make a member server the exchange server. Would it
be easier if I just transfer all of the FSMO roles to my
other servers and demote this server. Please advise


removed the demoted/crashed domain controller (i.e.
swesrv04). The adprep tools were run both the
forsestprep and domainprep. this setup was work as of
about 2 days ago. I'm not really sure what happened.

Posted by Chriss3 on March 5th, 2004


Hi Kurt, this is the most simple way to do this and get raid of the problem
I suppose. Sorry I'm have it hard to give thing up But a Demote and a
Promote can be the best way when we deal with the time Keeps us updated
how the demote and the promote goes. Have a nice day

--
Regards
Christoffer Andersson

No email replies please - reply in the newsgroup

"Kurt" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:78ef01c402cb$a9085a10$a301280a@phx.gbl...


Posted by Kurt on March 5th, 2004


The adprep commands worked fine without failures.
I did look at the adsi tool but couldn't find the place
that you were talking about.

I have 2 DC's that are win2k3 and 1 DC that is w2k. The
exchange servers are as follows:
1 w2k DC
1 w2k3 Member server

Will the demote and promote break my exchange server??
which machine do I demote and promote??

Please advise
Kurt
#XSLTsection126121120120

Posted by Chriss3 on March 5th, 2004


Demote an Promote the particular Domain Controller there the Schema Mismatch
where reported.

There is a fix if you running Exchange 2000 for ADPrep

http://support.microsoft.com/default.aspx?kbid=314649.
--
Regards
Christoffer Andersson

No email replies please - reply in the newsgroup

"Kurt" <anonymous@discussions.microsoft.com> skrev i meddelandet
news:7c2e01c402f6$0a4ee710$a001280a@phx.gbl...



Similar Posts