Click here to get back home

Downgrade BDC to simple server

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Downgrade BDC to simple server Jean Paul Mertens 08-20-2007
Posted by Jean Paul Mertens on August 20, 2007, 2:13 am
Please log in for more thread options
Hello to all,

I have a problem with a BDC (windows 2000 server) who does not see that the
PDC (SBS 2000) is back on-line. I have got my PDC crashed,and for some
reason the NT-Mirror had stopped some time ago. I have taken the PDC out of
the network, and the BDC took over the security with no problem. I have put
my (early stopped) mirror disk as master and restored alle backups so that
the PDC is ok. I have put the PDC back in the network and had to disconnect
(temporary set them to workgroup) all workstations and servers from the
domain and then reconnect them to the domain. So far so good until I tried
to do the same with my BDC but he keeps saying that there is no PDC so he
can not disconnect and he is not trusted by the domain any more. I cant stop
the AD becourse the server is BDC etc.. I'm turning in a round so my BDC in
no more reachable by the domain and vise versa.

The problem is , if I run DCPromo (on the BDC) I got the answer that a
domain
controller could not be contacted for the domain so he would not continue.
The message window says that I have to take out the server out of the domain
by making him member of a workgroup and then rejoin the domain. Bus as long
as AD is running on the machine I can not leave the domain (In the system
properties I can not change the identification of the computer becourse he
aims to be a domaincontroller...

and so we are back to start.

Is there a tool (or a way) to force the BDC server to stop from thinking he
has to stay a domain on his own so that I can downgrade the BDC to a simple
server, take is 'out of the domain' and reconnect it to the 'new domain'

Many tanks in advance

Jean Paul





Posted by SuperGumby [SBS MVP] on August 20, 2007, 2:51 am
Please log in for more thread options
Jean Paul,
Several questions were asked and ideas discussed in response to your first
post on this, please refer back to the original thread.

> Hello to all,
>
> I have a problem with a BDC (windows 2000 server) who does not see that
> the
> PDC (SBS 2000) is back on-line. I have got my PDC crashed,and for some
> reason the NT-Mirror had stopped some time ago. I have taken the PDC out
> of
> the network, and the BDC took over the security with no problem. I have
> put
> my (early stopped) mirror disk as master and restored alle backups so that
> the PDC is ok. I have put the PDC back in the network and had to
> disconnect
> (temporary set them to workgroup) all workstations and servers from the
> domain and then reconnect them to the domain. So far so good until I tried
> to do the same with my BDC but he keeps saying that there is no PDC so he
> can not disconnect and he is not trusted by the domain any more. I cant
> stop
> the AD becourse the server is BDC etc.. I'm turning in a round so my BDC
> in
> no more reachable by the domain and vise versa.
>
> The problem is , if I run DCPromo (on the BDC) I got the answer that a
> domain
> controller could not be contacted for the domain so he would not continue.
> The message window says that I have to take out the server out of the
> domain
> by making him member of a workgroup and then rejoin the domain. Bus as
> long
> as AD is running on the machine I can not leave the domain (In the system
> properties I can not change the identification of the computer becourse he
> aims to be a domaincontroller...
>
> and so we are back to start.
>
> Is there a tool (or a way) to force the BDC server to stop from thinking
> he
> has to stay a domain on his own so that I can downgrade the BDC to a
> simple
> server, take is 'out of the domain' and reconnect it to the 'new domain'
>
> Many tanks in advance
>
> Jean Paul
>
>
>
>



Posted by Jean Paul Mertens on August 20, 2007, 2:55 am
Please log in for more thread options
Indeed but no one was of any use...

grts

> Jean Paul,
> Several questions were asked and ideas discussed in response to your first
> post on this, please refer back to the original thread.
>
>> Hello to all,
>>
>> I have a problem with a BDC (windows 2000 server) who does not see that
>> the
>> PDC (SBS 2000) is back on-line. I have got my PDC crashed,and for some
>> reason the NT-Mirror had stopped some time ago. I have taken the PDC out
>> of
>> the network, and the BDC took over the security with no problem. I have
>> put
>> my (early stopped) mirror disk as master and restored alle backups so
>> that
>> the PDC is ok. I have put the PDC back in the network and had to
>> disconnect
>> (temporary set them to workgroup) all workstations and servers from the
>> domain and then reconnect them to the domain. So far so good until I
>> tried
>> to do the same with my BDC but he keeps saying that there is no PDC so he
>> can not disconnect and he is not trusted by the domain any more. I cant
>> stop
>> the AD becourse the server is BDC etc.. I'm turning in a round so my BDC
>> in
>> no more reachable by the domain and vise versa.
>>
>> The problem is , if I run DCPromo (on the BDC) I got the answer that a
>> domain
>> controller could not be contacted for the domain so he would not
>> continue.
>> The message window says that I have to take out the server out of the
>> domain
>> by making him member of a workgroup and then rejoin the domain. Bus as
>> long
>> as AD is running on the machine I can not leave the domain (In the system
>> properties I can not change the identification of the computer becourse
>> he
>> aims to be a domaincontroller...
>>
>> and so we are back to start.
>>
>> Is there a tool (or a way) to force the BDC server to stop from thinking
>> he
>> has to stay a domain on his own so that I can downgrade the BDC to a
>> simple
>> server, take is 'out of the domain' and reconnect it to the 'new domain'
>>
>> Many tanks in advance
>>
>> Jean Paul
>>
>>
>>
>>
>
>



Posted by Paul Adare on August 20, 2007, 3:10 am
Please log in for more thread options
On Mon, 20 Aug 2007 08:55:39 +0200, Jean Paul Mertens wrote:

> Indeed but no one was of any use...

Ok, but that's not a reason to restart the thread again. Continue the
discussion in the existing thread.

Posted by SuperGumby [SBS MVP] on August 20, 2007, 3:14 am
Please log in for more thread options
So, return to the original thread and ask. This allows both you and people
willing to contribute to track the issue.

The mirror you returned to is out of sync with the 2nd DC, the method of
restore needs to be discussed but the event logs will contain errors
indicating the problems.

You need to clarify whether the workstations were removed from the domain
and rejoined while the SBS was offline or whether this was at the time of
SBS coming back online. If both DC's were online at the time there's some
reason to doubt the status of all workstations.

I would not, at this time, perform a 'DCPromo /forceremoval' (something
easily found in the MS KB's) on the 2nd DC due to the indeterminate state of
the DC-DC relationship and that of the workstations to either DC.

You need to stop 'doing stuff' and start 'working through the problem'.

and you need to do so in the original thread.

> Indeed but no one was of any use...
>
> grts
>
>> Jean Paul,
>> Several questions were asked and ideas discussed in response to your
>> first post on this, please refer back to the original thread.
>>
>>> Hello to all,
>>>
>>> I have a problem with a BDC (windows 2000 server) who does not see that
>>> the
>>> PDC (SBS 2000) is back on-line. I have got my PDC crashed,and for some
>>> reason the NT-Mirror had stopped some time ago. I have taken the PDC out
>>> of
>>> the network, and the BDC took over the security with no problem. I have
>>> put
>>> my (early stopped) mirror disk as master and restored alle backups so
>>> that
>>> the PDC is ok. I have put the PDC back in the network and had to
>>> disconnect
>>> (temporary set them to workgroup) all workstations and servers from the
>>> domain and then reconnect them to the domain. So far so good until I
>>> tried
>>> to do the same with my BDC but he keeps saying that there is no PDC so
>>> he
>>> can not disconnect and he is not trusted by the domain any more. I cant
>>> stop
>>> the AD becourse the server is BDC etc.. I'm turning in a round so my BDC
>>> in
>>> no more reachable by the domain and vise versa.
>>>
>>> The problem is , if I run DCPromo (on the BDC) I got the answer that a
>>> domain
>>> controller could not be contacted for the domain so he would not
>>> continue.
>>> The message window says that I have to take out the server out of the
>>> domain
>>> by making him member of a workgroup and then rejoin the domain. Bus as
>>> long
>>> as AD is running on the machine I can not leave the domain (In the
>>> system
>>> properties I can not change the identification of the computer becourse
>>> he
>>> aims to be a domaincontroller...
>>>
>>> and so we are back to start.
>>>
>>> Is there a tool (or a way) to force the BDC server to stop from thinking
>>> he
>>> has to stay a domain on his own so that I can downgrade the BDC to a
>>> simple
>>> server, take is 'out of the domain' and reconnect it to the 'new domain'
>>>
>>> Many tanks in advance
>>>
>>> Jean Paul
>>>
>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
Simple user/password management? July 6, 2005, 11:50 am
Simple File Sharing question December 14, 2005, 10:26 pm
Simple question regarding Windows 2003 Firewall April 1, 2007, 11:35 pm
Using AD server as a ldap server and 4k bit server certificate key October 13, 2005, 10:28 pm
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm
creat a domain trust between Windows 2000 server, it show error message:"PRC server is unavailable" July 3, 2006, 3:59 pm
SP-1 to a Windows 2003 Server running SQL Server 2000 with out SP- July 5, 2005, 5:20 pm
Re: Subordinate CA server renewal with an online CA root server July 17, 2008, 8:48 am
web server September 11, 2006, 12:52 am
Server Hardening July 5, 2005, 9:34 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap