iSteve Posted January 5, 2023 Posted January 5, 2023 Hi all, We have two 2008r2 DCs on a legacy domain; DC01 and DC02. DC02 has been shut down for several months and will no loner replicate with DC01. This of course creates issues when attempting migration to a newer OS, or when trying to demote DC02 and remove the AD role. DC01 holds all the FSMO roles. We have set a reg key to allow divergent sync - which I believe should allow the two DCs to sync even if the tombstone date has expired. We've forced a sync, which appeared successful. Going in to AD Sites & Services, we can replicate from DC01 to DC02 successfully. However, if we attempt to remove the AD role from DC02, it says that the tombstone lifetime has been too long and replication is disabled. If we try to update the schema using adprep, we get the same complaint, so it seems like the forced sync has not been successful. Can anyone advise on what might be happening here, and how to get DC02 back in sync with DC01, or how to remove DC02 leaving DC01 as the sole DC (which we will then upgrade) Thanks!
psydii Posted January 5, 2023 Posted January 5, 2023 (edited) Try this. The magic is MS LOL apparently. https://community.spiceworks.com/topic/2146253-windows-server-how-to-fix-a-tombstoned-domain-controller Double check each command and research each step before proceeding - since these are all tools we seldom use, and mistakes can be unrecoverable, and who knows if the author had a technical editor who check their post for egregious errors. "Don't immediately go into your production Active Directory forest and start wildly deleting things" Ryan Ries (author of MS LOL) https://learn.microsoft.com/en-gb/archive/blogs/askds/introducing-lingering-object-liquidator-v2 Edited January 5, 2023 by psydii 1
iSteve Posted January 5, 2023 Author Posted January 5, 2023 Hi psydii We've been through those steps on the Spiceworks post earlier today. We've installed and looked at the MS LOL tool. There are no lingering objects. The force replications between two DCs section was successful, but the failure with the tombstone date being too long still persists when trying to demote DC02, or when trying to update DC01 with adprep.
psydii Posted January 5, 2023 Posted January 5, 2023 Is DC02 actually needed for anything in particular? Could you just shut it down and then manually remove it from the domain? https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-manually-removing-a-domain-controller-server/ba-p/280564 1
iSteve Posted January 5, 2023 Author Posted January 5, 2023 It's not required. I was attempting to cleanly remove it to avoid any quirky problems down the line. If shutting it down and then deleting it from DC01 as per the link will sort it out, we can do that. Thanks!
HPlum78 Posted January 18, 2023 Posted January 18, 2023 https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/replication-error-8614 This is the MS take on this..
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now