6

I have a small 2 DC domain using Win 2008 R2 machines. Recently, one had to be restored using backup exec system recovery.

Now the two are failing replication. I have ran DCDIAG on both (see below) and see that several things fail with target principal name incorrect. Upon checking DNS, as well as the SETSPN commands to check, both DCs seem to have entries on each other, so I am not sure what I am doing wrong or what the next steps are.

Any help would be greatly appreciated!

Domain controllers:

  • Terminal-Dogma
  • Central-Dogma (This is the one that was recently restored)

DCDiag for Terminal-Dogma (PasteBin)

DCDiag for Central-Dogma (PasteBin)

Greg Askew
  • 34,339
  • 3
  • 52
  • 81
DontStealMyFish
  • 108
  • 1
  • 2
  • 12

1 Answers1

4

You probably need to reset secure channel from the domain controller that is not the PDCE (CENTRAL, assuming the logs are correct and TERMINAL is the PDCE). See the following for the procedure:

Error Message "Target Principal Name is Incorrect" When Manually Replicating Data Between Domain Controllers
https://support.microsoft.com/en-us/kb/288167

On domain controllers that are experiencing this issue, disable the Kerberos Key Distribution Center service (KDC). To do so:

  • Click Start, point to Programs, click Administrative Tools, and then click Services.
  • Double-click KDC, set the startup type to Disabled, and then restart the computer.

After the computer restarts, use the Netdom utility to reset the secure channels between these domain controllers and the PDC Emulator operations master role holder. To do so, run the following command from the domain controllers other than the PDC Emulator operations master role holder:

netdom resetpwd /server:server_name /userd:domain_name\administrator /passwordd:administrator_password  

Where server_name is the name of the server that is the PDC Emulator operations master role holder.

Change the KDC service startup mode back to automatic and restart.

Greg Askew
  • 34,339
  • 3
  • 52
  • 81
  • Very nice. Terminal-Dogma was the PDC and contained the needed roles, so after running the suggested command on Central-Dogma (using Terminal-dogma as the in the command) it works. I was able to replicate AD manually using sites and services. – DontStealMyFish Dec 06 '15 at 18:11