免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 3321 | 回复: 1
打印 上一主题 下一主题

[Server 2003] 添加额外域控制器的问题? [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2004-05-08 21:04 |只看该作者 |倒序浏览
我在主域上建了 aaa 用户, 加入了 schema admins和enterprise admins 组,但在另一台机器升级成 abc.com 额外域控制器的时候不管用 aaa 还是 administrator 用户还是提示一样的错误
The operation failed because: Failed to modify the necessary properties for the machine account JOB-YOYO$
\"Access is denied. \"
实在想不通,是什么原因?

论坛徽章:
0
2 [报告]
发表于 2004-05-09 16:09 |只看该作者

FYI

When you try to promote a replica domain controller, you receive:

The operation failed because: Failed to modify the necessary properties for the machine account %computername%$ \"Access Denied\"
The %SystemRoot%\\Debug\\Dcpromolog folder contains entries similar to:
MM/DD HH:MM:SS [INFO] Configuring the server account
MM/DD HH:MM:SS [INFO] NtdsSetReplicaMachineAccount returned 5
MM/DD HH:MM:SS [INFO] DsRolepSetMachineAccountType returned 5
MM/DD HH:MM:SS [INFO] Error - Failed to modify the necessary properties for the machine account %COMPUTERNAME%$(5)
During the promotion of a replica domain controller, the UserAccountControl attribute for the computer you are promoting is modified to define its\' role as a domain controller. The computer you are promoting tries to:
1. Perform a LDAP search against an existing domain controller for its computer account (ObjectClass=user,ObjectClass=computer,SamAccountName=%ComputerName%$).

2. Update the UserAccountControl attribute, indicating a change from a member server to a domain controller.

3. Move the computer account object (CAO) from the current container or organizational unit (OU), to the domain controller\'s OU of the domain.

4. Source the schema, configuration, and domain naming contexts for replication, from domain controllers that already exist.

For steps 2 and 3 to succeed, the source domain controller used by the new replica must have successfully replicated and applied the security policy, as identified by Event ID 1704 in the application log, after Dcpromo has run.

The operation failed because the Enable computer and users accounts to be trusted for delegation user right, required to update the UserAccountControl, has not been granted. This right is granted to the Administrators group, in the defaut domain controllers policy.

To fix the problem:

Make sure that existing domain controllers have applied security policy and that the Enable computer and users accounts to be trusted for delegation user right has been granted to the Administrators group (Default Domain Controller Policy / Computer Configuration / Windows Settings / Security Settings / Local Policies).

If a domain controller does not have this right, confirm that GPOs have replicated, and then manually apply the policy by typing the following command:

secedit /refreshpolicy machine_policy

NOTE: If the Application event log contains:

Event ID 1704: Security Policy in the Group policy objects are applied successfully. the GPOs have been appliced.

If you\'re in a hurry, stop the Netlogon service on the source domain controller that doesn\'t have this right, to discover another DC that does.
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP