Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cannot Reset Password 2

Status
Not open for further replies.

SIO3

MIS
Nov 14, 2007
69
NG

Hello Guyz,

Need some help.

I got a call from a user whose password has expired and decided to reset it on the DC. "Windows cannot complete Password change for Mavison because: the system cannot find the specified file." is the message I am getting.

What could be wrong?
 
Sorry Guyz, I have been out of the office.

pagy,
There was power outage. But I am not sure of any software installtion outside Microsoft updates. And I have been wondering on how to do a "Restore" on the DC.

markdmac,
Posting all outputs of DCDIAG and will take up a lenghty space. or what do you think?
 
Microsoft Windows [Version 5.2.3790]
(C) Copyright 1985-2003 Microsoft Corp.
This the DCDIAG output. NETDIAG is just too lengthy for posting here,


C:\WINDOWS>DCDIAG

Domain Controller Diagnosis

Performing initial setup:
[ict-dc-001] LDAP bind failed with error 1323,
Unable to update the password. The value provided as the current password is
incorrect..
***Error: The machine could not attach to the DC because the credentials
were incorrect. Check your credentials or specify credentials with
/u:<domain>\<user> & /p:[<password>|*|""]
 
Can't really help you with incomplete information. We need more data that we might not even know to aqsk for because we can't review the entire results. Post all the output from DCDIAG and NETDIAG.

Your alternative is to set up a virtual machine, make that a new DC and transfer the FSMO roles to it. Make it a GC too. This will preserve your AD.

Then run DCPROMO on the failed machine and remove it as a DC. It will still be a member of the domain and still hold your user data and preserve the NTFS permissions.

Reboot and run DCPROMO again to make it a DC again, then transfer FSMO roles back and make it a GC too. Finally run DCPROMO on the virtual server to gracefully remove it from AD.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
You can post all the output from netdiag, no reason you can't do that here.

Paul
MCTS: Exchange 2007, Configuration
MCSA:2003
MCSE:2003
MCITP:Enterprise Administrator

If there are no stupid questions, then what kind of questions do stupid people ask? Do they get smart just in time to ask questions?
Scott Adams
 
Actually I can post all the outputs, I was only considering the length of the output of NETDIAG.

Here is the result of NETDIAG...

C:\WINDOWS>NETDIAG
[ERROR] Cannot open NetDiag.log to log output.

........................................

Computer Name: ICT-DC-001
DNS Host Name: ict-dc-001.ict.local
System info : Microsoft Windows Server 2003 (Build 3790)
Processor : x86 Family 15 Model 4 Stepping 1, GenuineIntel
List of installed hotfixes :
KB921503
KB923561
KB924667-v2
KB925398_WMP64
KB925902
KB927891
KB929123
KB930178
KB931784
KB932168
KB933729
KB933854
KB935839
KB935840
KB936021
KB936357
KB936782
KB938127
KB938464
KB938759-v4
KB941202
KB941568
KB941569
KB941644
KB941672
KB941693
KB942763
KB942830
KB942831
KB943055
KB943460
KB943484
KB943485
KB944338
KB944653
KB945553
KB946026
KB947864
KB948496
KB948590
KB948745
KB949014
KB950759
KB950762
KB950974
KB951066
KB951072-v2
KB951698
KB951746
KB951748
KB952004
KB952069
KB952954
KB953838
KB953839
KB954211
KB954600
KB955069
KB955839
KB956390
KB956391
KB956572
KB956802
KB956803
KB956841
KB957095
KB957097
KB958215
KB958644
KB958687
KB958690
KB959426
KB960225
KB960714
KB960715
KB960803
KB961063
KB961064
KB961373
KB963027
KB967715
Q147222


Netcard queries test . . . . . . . : Failed
Enumeration failed. [ERROR_ACCESS_DENIED]
[FATAL] - None of the netcard drivers provided satisfactory results.



Per interface results:

Adapter : Local Area Connection 2

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : ict-dc-001
IP Address . . . . . . . . : 192.168.100.1
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.100.5
Dns Servers. . . . . . . . : 192.168.100.1


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Failed
No gateway reachable for this adapter.


WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.

Adapter : Local Area Connection

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : ict-dc-001
Autoconfiguration IP Address : 169.254.204.54
Subnet Mask. . . . . . . . : 255.255.0.0
Default Gateway. . . . . . :
Dns Servers. . . . . . . . :

AutoConfiguration results. . . . . . : Failed
[WARNING] AutoConfiguration is in use. DHCP not available.

Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.


WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{4CBCF2EB-EC39-4093-93D6-1FCDCC219F8A}
NetBT_Tcpip_{D7B45A7B-E5F5-4442-BB19-261073C00273}
2 NetBt transports currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Failed

[FATAL] NO GATEWAYS ARE REACHABLE.
You have no connectivity to other network segments.
If you configured the IP protocol manually then
you need to add at least one valid gateway.


NetBT name test. . . . . . . . . . : Failed
[FATAL] Failed to read NBT interface info from the registry.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the name
'ict-dc-001.ict.local.'. [ERROR_TIMEOUT]
The name 'ict-dc-001.ict.local.' may not be registered in DNS.
[FATAL] Could not open file C:\WINDOWS\system32\config\netlogon.dns for read
ing.
[FATAL] No DNS servers have the DNS records for this DC registered.


Redir and Browser test . . . . . . : Failed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{4CBCF2EB-EC39-4093-93D6-1FCDCC219F8A}
NetBT_Tcpip_{D7B45A7B-E5F5-4442-BB19-261073C00273}
The redir is bound to 2 NetBt transports.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{4CBCF2EB-EC39-4093-93D6-1FCDCC219F8A}
NetBT_Tcpip_{D7B45A7B-E5F5-4442-BB19-261073C00273}
The browser is bound to 2 NetBt transports.
[FATAL] Cannot send mailslot message to '\\ICT*\MAILSLOT\NET\NETLOGON' via r
edir. [ERROR_NO_SYSTEM_RESOURCES]


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Failed
[WARNING] Cannot call DsBind to ict-dc-001.ict.local (192.168.111.1). [RPC_S
_INVALID_AUTH_IDENTITY]


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Failed
[FATAL] Cannot do NTLM authenticated ldap_bind to 'ict-dc-001.ict.local': In
valid Credentials.
[FATAL] Cannot do Negotiate authenticated ldap_bind to 'ict-dc-001.ict.local
': Invalid Credentials.
[WARNING] Failed to query SPN registration on DC 'ict-dc-001.ict.local'.
[FATAL] No LDAP servers work in the domain 'ICT'.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
Failed to enumerate the RAS connections on this machine.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully
 
DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the name
'ict-dc-001.ict.local.'. [ERROR_TIMEOUT]
The name 'ict-dc-001.ict.local.' may not be registered in DNS.
[FATAL] Could not open file C:\WINDOWS\system32\config\netlogon.dns for read
ing.
[FATAL] No DNS servers have the DNS records for this DC registered.

AD is dependent on DNS. Start looking here. First recycle the DNS service.

Also, all of your NICs are reporting that there is no gateway available. Verify TCP/IP configuration on your NICs. You have a NIC on the server that is set to use DHCP, yet it says that DHCP is unavailable. Either set that to static or if it is not used disable the card.

On the server type the following at a command prompt:
Code:
IPCONFIG /FLUSHDNS <enter>
IPCONFIG /REGISTERDNS <enter>

Check your Gateway, can your server browse the Internet? It is configured for 192.168.100.5 is that the correct gateway?

Netcard queries test . . . . . . . : Failed
Enumeration failed. [ERROR_ACCESS_DENIED]
[FATAL] - None of the netcard drivers provided satisfactory results.

This isn't very good. WMI is having problems. Check WMI permissions.

1. Click Start, click Run, type compmgmt.msc, and then click OK.
2. Under Computer Management (Local), expand Services and Applications, right-click WMI Control, and then click Properties.
3. Click the Security tab, expand Root, click CIMV2, and then click Security.

Make sure that Administrators have all permissions checked.
Local Service and Network service should each have Execute Methods, Provider Write and Enable Account.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
markdmac...many thanks once again, I am trying to get the GC & FSMO of the DC onto a virtual or a PC Server.

Meanwhile 'ipconfig/registerdns' on the DC as administrator reveled the following result.

-Registrattion of DNS Records failed: Access is denied.

Please note that the DC is also a DNS & DHCP server.
 
It is possible that the only real problem is that your DNS is messed up, creating a new server will hopefully fix that up. Check to see if your DNS is AD integrated.

I'm thinking you don't want it to be AD integrated on the bad system. Then set it to be integrated on the virtual. Once you have fixed the bad server you could set that one to AD integrated too.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
My DNS has always been AD integrated.

While I am still working on getting an alternative server to transfer the FSMO roles, let me say here that I have just noticed that I could actually change expired passwords using ctrl-alt-del on vista machines, if only the user can remember the former password.

creating new users accounts,resetting passwords at the DC & reseting passwords of users that cannot even remember their previous passwords are the issues.
 
OK, so where are you in setting up the temporary DC. That should have taken no more than a few hours.

If your current DNS is AD integrated and it is corrupt, you will be replicating the corrupted AD. You will be better served creating a fresh DNS in my opinion.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
The Temporary DC was build and FSMO roles & GC was transfered to it. On it I can reset passwords without hassles.

The main DC was demoted and promoted again after which I tried reseting password on it but got same old error message.
"Windows cannot complete Password change for Mavison because: the system cannot find the specified file."

Is there anything I did not
 
I would recommend that you demote the bad DC. Make it just a member server and make sure that it is no longer in AD. YOu can run the script in my FAQ to do a metadata cleanup. The script is from an old collegue of mine at Microsoft, not one of my own. faq96-4733

Once you are certain the DC is no longer listed in AD, check the DNS records very carefully and remove any entries in there other than the host record.

I then recommend that you rename the server. Once that is done you can run DCPROMO again to install AD on the server. Verify that you are getting a good AD Sync. Try running REPADMIN /SYNCALL. You shoudl get back a reply that there were no errors. If there are then you have some investigation to do.

Once syncronization is happening, try resetting a password then.

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
markdmac... I just cannot thank you enough for staying with me on this issue.

I want state the following
1. The main DC is also my only AD integrated DNS server.
2. It also house's Userdata and other informations

Hence renaming it may cause some other issue or what do you think?

 
You are welcome. We've all been there and need soem help sometimes.

If you have done as you stated above and you have added a second DC, then transferred all 5 FSMO roles to it and made it a GC AND you used DCPROMO to remove AD from the original DC, then that box was just a member server at that time. User data and security will not be affected because you have introduced another DC and the server is still a member of the domain, just not a DC. You will need to repoint user drive mappings, an easy task if you follow my login script FAQ. faq329-5798

If you did not actually do the DCPROMO then that explains why there was no change in the ability to reset passwords.

Does that make sense to you?

I hope you find this post helpful.

Regards,

Mark

Check out my scripting solutions at
Work SMARTER not HARDER. The Spider's Parlor's Admin Script Pack is a collection of Administrative scripts designed to make IT Administration easier! Save time, get more work done, get the Admin Script Pack.
 
I did exactly that; ie move all 5 FSMO + GC to the temporary DC. Then used DCPROMO to demote & promote the main DC.

I am not good at handling script. I am thinking of running DCPromo on the main DC again to demote it to a member server and then manually delete any remaining NTDS & Sysvol folders and files in safemode.

I want to also remove the DNS & rebuild it again.

I guess this plan can help
 
many thanks all,

markdmac, thanks for all your efforts.

This cause of this issue was corrupt administrator's profile.Using another admin account made all the difference.
And all is now well with creating and resetting users accounts on my domain controller.

This thread is now closed.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top