AD Fun after user enforced shutdown

Jools PB 96 Reputation points
2020-07-29T18:15:21.4+00:00

Hi All,

I've got a problem with a server at a charity I volunteer at, where it appears one on the DCs at one of their remote site was shut down on the button.

The following day, the server involved started complaining about a target account being incorrect when a user was trying to access a share. I went through the logs and found the credentials that the servers use to communicate was skewed. The cure, it turned out was "netdom resetpwd" run on the server from a remote DC. All of a sudden, DNS pops up and things seem to be working again.

Following morning, I get a call from one of the other offices complaining that they can't access shares on the server in their building. So, log in, same error. Go to the first server that broke (server 2016) run netdom reset and it fails with:

The machine account password for the local machine could not be reset.

The target account name is incorrect.

The command failed to complete successfully.

So, go to another DC - same, another - same, finally, last DC in the organisation succeeds, and all the errors in the log on the 2nd server disappear and DNS comes back up.

So, try to access the shares on the second server from the others in the organisation and get the same error about target accounts. Go to the server that succeeded in the netdom passwrd reset and that one opens all the shares on the second server. So, somewhere along the line, AD seems to got out of sync.

I've tried syncing and on all the servers, it return sync completed with no errors, but they don't seem to getting along. There are no errors logged in event viewer which seems odd and aside from the share access, everything appears to be fine.

Could someone please point in the best direction for getting these boxes talking to each other again. There are three dcs which work fine (sharewise) together but won't talk to the other two, and the other two which work fine with each other but won't talk to the other 3.

If you want log or dcdiag outputs, please let me know the parameters and I'll post the result.

Thanks,

Jools

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,149 questions
0 comments No comments
{count} votes

Accepted answer
  1. Jools PB 96 Reputation points
    2020-07-31T16:06:11.683+00:00

    I appear to have had a bit of a result (hopefully).

    Having begun picking through the logs to sort out individual errors, the one that was bugging was the target name error. Hunting it down, I came across a technet article on server 2003 that used the IP of the server in the netdom resetpwd command instead of the computer name. Waited for the building to empty and ran the command on one of the remote servers and bingo, password successfully reset.

    So, I now only have an SChannel problem to sort and it looks like it may be a fix.

    So, once again, thanks for your help. You kept me going when I was just running round in circles getting frustrated. Top marks for you.

    Best of luck to you,

    Jools


11 additional answers

Sort by: Most helpful
  1. Dave Patrick 426.4K Reputation points MVP
    2020-07-29T18:23:09.537+00:00

    You might try demote, reboot, promo the problematic one.

    0 comments No comments

  2. Jools PB 96 Reputation points
    2020-07-29T19:27:18.247+00:00

    As two of the 5 seem to work together and three out of 5 seem to work together, but the two groups don't seem to, would this be on both the ones that aren't working?

    0 comments No comments

  3. Dave Patrick 426.4K Reputation points MVP
    2020-07-29T19:36:11.95+00:00

    You'll probably need to verify the domain health (dcdiag, repadmin tools) then you can take appropriate actions. If you wanted some help along this line then please run;

    • Dcdiag /v /c /d /e /s:%computername% >c:\dcdiag.log
    • repadmin /showrepl >C:\repl.txt
    • ipconfig /all > C:\dc1.txt
    • ipconfig /all > C:\dc2.txt
    • (etc. as other DC's exist)

    then put unzipped text files up on OneDrive and share a link.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  4. Jools PB 96 Reputation points
    2020-07-29T21:28:43.95+00:00

    Hi,

    Tried pasting the link and got this:

    WAF v2 has determined your request exceeded the normal web request and has blocked your request.

    do you have a way I can send you the link directly?