Jump to content

Recommended Posts

Posted

Did an inplace upgrade from 2012r2 to 2019 on all 3 of my domain controllers back in January and thought all was well until last week when I was starting to see some GPO errors when running gpupdate on some computers.

 

Turns out DC-01 which also holds FMSO roles and Certificate Authority stopped replicating and no matter how much troubleshoot I cannot get it to replicate again!

 

So I am thinking, move FMSO roles to roles to another DC (which is easy enough) - but what about moving the CA? Never done this, so no idea how easy/difficult it is.

 

Once moved all roles, I will demote the server and then spin up a new VM to take its place.

 

Anyone moved their CA to a different server? Any gotchas i need to worry about?

 

Cheers

Posted

Thankfully I don’t have to do any moving of roles as found a solution which seems to have worked a treat.

 

Stop dfsr service

Give admin full control of system volume information folder

Move dfsr folder to a safe location

Restarted dfsr service

 

Dfsr folder was recreated and folders were resync’d

 

Probably not the correct way of doing things but it worked.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...