Here is the dcdiag log:
Command Line: "dcdiag.exe /v /c /d /e /s:dc1"
Domain Controller Diagnosis
Performing initial setup:
* Connecting to directory service on server dc1.
dc1.currentTime = 20150821190923.0Z
dc1.highestCommittedUSN = 22914093
dc1.isSynchronized = 1
dc1.isGlobalCatalogReady = 1
* Collecting site info.
* Identifying all servers.
DC1.currentTime = 20150821190923.0Z
DC1.highestCommittedUSN = 22914093
DC1.isSynchronized = 1
DC1.isGlobalCatalogReady = 1
* Identifying all NC cross-refs.
* Found 2 DC(s). Testing 2 of them.
Done gathering initial info.
===============================================Printing out pDsInfo
GLOBAL:
ulNumServers=2
pszRootDomain=corp.mydomain.com
pszNC=
pszRootDomainFQDN=DC=corp,DC=mydomain,DC=com
pszConfigNc=CN=Configuration,DC=corp,DC=mydomain,DC=com
pszPartitionsDn=CN=Partitions,CN=Configuration,DC=corp,DC=mydomain,DC=com
iSiteOptions=0
dwTombstoneLifeTimeDays=180
dwForestBehaviorVersion=2
HomeServer=0, DC1
SERVER: pServer[0].pszName=DC1
pServer[0].pszGuidDNSName=6d452aba-3a2b-4ba0-bb53-dd5c0d4d3513._msdcs.corp.mydomain.com
pServer[0].pszDNSName=dc1.corp.mydomain.com
pServer[0].pszDn=CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
pServer[0].pszComputerAccountDn=CN=DC1,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com
pServer[0].uuidObjectGuid=6d452aba-3a2b-4ba0-bb53-dd5c0d4d3513
pServer[0].uuidInvocationId=f87d1090-e0c9-4cde-a8e0-eb4d3b7caedc
pServer[0].iSite=0 (Default-First-Site-Name)
pServer[0].iOptions=1
pServer[0].ftLocalAcquireTime=e40983a0 01d0dc44
pServer[0].ftRemoteConnectTime=e3b63380 01d0dc44
pServer[0].ppszMasterNCs:
ppszMasterNCs[0]=DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[1]=DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[2]=CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[3]=CN=Configuration,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[4]=DC=corp,DC=mydomain,DC=com
SERVER: pServer[1].pszName=DC2
pServer[1].pszGuidDNSName=1854b5ee-430a-4176-b18a-aaf114663fb1._msdcs.corp.mydomain.com
pServer[1].pszDNSName=dc2.corp.mydomain.com
pServer[1].pszDn=CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
pServer[1].pszComputerAccountDn=CN=DC2,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com
pServer[1].uuidObjectGuid=1854b5ee-430a-4176-b18a-aaf114663fb1
pServer[1].uuidInvocationId=120d219e-8603-4242-b142-344757a34d8d
pServer[1].iSite=0 (Default-First-Site-Name)
pServer[1].iOptions=1
pServer[1].ftLocalAcquireTime=00000000 00000000
pServer[1].ftRemoteConnectTime=00000000 00000000
pServer[1].ppszMasterNCs:
ppszMasterNCs[0]=DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[1]=DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[2]=CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[3]=CN=Configuration,DC=corp,DC=mydomain,DC=com
ppszMasterNCs[4]=DC=corp,DC=mydomain,DC=com
SITES: pSites[0].pszName=Default-First-Site-Name
pSites[0].pszSiteSettings=CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
pSites[0].pszISTG=CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
pSites[0].iSiteOption=0
pSites[0].cServers=2
NC: pNCs[0].pszName=ForestDnsZones
pNCs[0].pszDn=DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
pNCs[0].aCrInfo[0].dwFlags=0x00000201
pNCs[0].aCrInfo[0].pszDn=CN=e4678419-5061-4c34-b7d8-45ebcb7253a4,CN=Partitions,CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[0].aCrInfo[0].pszDnsRoot=ForestDnsZones.corp.mydomain.com
pNCs[0].aCrInfo[0].iSourceServer=0
pNCs[0].aCrInfo[0].pszSourceServer=(null)
pNCs[0].aCrInfo[0].ulSystemFlags=0x00000005
pNCs[0].aCrInfo[0].bEnabled=TRUE
pNCs[0].aCrInfo[0].ftWhenCreated=00000000 00000000
pNCs[0].aCrInfo[0].pszSDReferenceDomain=(null)
pNCs[0].aCrInfo[0].pszNetBiosName=(null)
pNCs[0].aCrInfo[0].aszReplicas=
NC: pNCs[1].pszName=DomainDnsZones
pNCs[1].pszDn=DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
pNCs[1].aCrInfo[0].dwFlags=0x00000201
pNCs[1].aCrInfo[0].pszDn=CN=0a70f765-7a8b-4413-a600-f97ccf16085a,CN=Partitions,CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[1].aCrInfo[0].pszDnsRoot=DomainDnsZones.corp.mydomain.com
pNCs[1].aCrInfo[0].iSourceServer=0
pNCs[1].aCrInfo[0].pszSourceServer=(null)
pNCs[1].aCrInfo[0].ulSystemFlags=0x00000005
pNCs[1].aCrInfo[0].bEnabled=TRUE
pNCs[1].aCrInfo[0].ftWhenCreated=00000000 00000000
pNCs[1].aCrInfo[0].pszSDReferenceDomain=(null)
pNCs[1].aCrInfo[0].pszNetBiosName=(null)
pNCs[1].aCrInfo[0].aszReplicas=
NC: pNCs[2].pszName=Schema
pNCs[2].pszDn=CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[2].aCrInfo[0].dwFlags=0x00000201
pNCs[2].aCrInfo[0].pszDn=CN=Enterprise Schema,CN=Partitions,CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[2].aCrInfo[0].pszDnsRoot=corp.mydomain.com
pNCs[2].aCrInfo[0].iSourceServer=0
pNCs[2].aCrInfo[0].pszSourceServer=(null)
pNCs[2].aCrInfo[0].ulSystemFlags=0x00000001
pNCs[2].aCrInfo[0].bEnabled=TRUE
pNCs[2].aCrInfo[0].ftWhenCreated=00000000 00000000
pNCs[2].aCrInfo[0].pszSDReferenceDomain=(null)
pNCs[2].aCrInfo[0].pszNetBiosName=(null)
pNCs[2].aCrInfo[0].aszReplicas=
NC: pNCs[3].pszName=Configuration
pNCs[3].pszDn=CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[3].aCrInfo[0].dwFlags=0x00000201
pNCs[3].aCrInfo[0].pszDn=CN=Enterprise Configuration,CN=Partitions,CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[3].aCrInfo[0].pszDnsRoot=corp.mydomain.com
pNCs[3].aCrInfo[0].iSourceServer=0
pNCs[3].aCrInfo[0].pszSourceServer=(null)
pNCs[3].aCrInfo[0].ulSystemFlags=0x00000001
pNCs[3].aCrInfo[0].bEnabled=TRUE
pNCs[3].aCrInfo[0].ftWhenCreated=00000000 00000000
pNCs[3].aCrInfo[0].pszSDReferenceDomain=(null)
pNCs[3].aCrInfo[0].pszNetBiosName=(null)
pNCs[3].aCrInfo[0].aszReplicas=
NC: pNCs[4].pszName=corp
pNCs[4].pszDn=DC=corp,DC=mydomain,DC=com
pNCs[4].aCrInfo[0].dwFlags=0x00000201
pNCs[4].aCrInfo[0].pszDn=CN=MYDOMAIN,CN=Partitions,CN=Configuration,DC=corp,DC=mydomain,DC=com
pNCs[4].aCrInfo[0].pszDnsRoot=corp.mydomain.com
pNCs[4].aCrInfo[0].iSourceServer=0
pNCs[4].aCrInfo[0].pszSourceServer=(null)
pNCs[4].aCrInfo[0].ulSystemFlags=0x00000003
pNCs[4].aCrInfo[0].bEnabled=TRUE
pNCs[4].aCrInfo[0].ftWhenCreated=00000000 00000000
pNCs[4].aCrInfo[0].pszSDReferenceDomain=(null)
pNCs[4].aCrInfo[0].pszNetBiosName=(null)
pNCs[4].aCrInfo[0].aszReplicas=
5 NC TARGETS: ForestDnsZones, DomainDnsZones, Schema, Configuration, corp,
2 TARGETS: DC1, DC2,
=============================================Done Printing pDsInfo
Doing initial required tests
Testing server: Default-First-Site-Name\DC1
Starting test: Connectivity
* Active Directory LDAP Services Check
Failure Analysis: DC1 ... OK.
* Active Directory RPC Services Check
......................... DC1 passed test Connectivity
Testing server: Default-First-Site-Name\DC2
Starting test: Connectivity
* Active Directory LDAP Services Check
DC2.currentTime = 20150821190923.0Z
DC2.highestCommittedUSN = 22328275
DC2.isSynchronized = 1
DC2.isGlobalCatalogReady = 1
Failure Analysis: DC2 ... OK.
* Active Directory RPC Services Check
......................... DC2 passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\DC1
Starting test: Replications
* Replications Check
DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com has 4 cursors.
DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com has 4 cursors.
CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com has 4 cursors.
CN=Configuration,DC=corp,DC=mydomain,DC=com has 4 cursors.
DC=corp,DC=mydomain,DC=com has 4 cursors.
* Replication Latency Check
DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Configuration,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
......................... DC1 passed test Replications
Starting test: Topology
* Configuration Topology Integrity Check
* Analyzing the connection topology for DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... DC1 passed test Topology
Starting test: CutoffServers
* Configuration Topology Aliveness Check
* Analyzing the alive system replication topology for DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... DC1 passed test CutoffServers
Starting test: NCSecDesc
* Security Permissions Check for
DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
(NDNC,Version 2)
* Security Permissions Check for
DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
(NDNC,Version 2)
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
(Schema,Version 2)
* Security Permissions Check for
CN=Configuration,DC=corp,DC=mydomain,DC=com
(Configuration,Version 2)
* Security Permissions Check for
DC=corp,DC=mydomain,DC=com
(Domain,Version 2)
......................... DC1 passed test NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
......................... DC1 passed test NetLogons
Starting test: Advertising
The DC DC1 is advertising itself as a DC and having a DS.
The DC DC1 is advertising as an LDAP server
The DC DC1 is advertising as having a writeable directory
The DC DC1 is advertising as a Key Distribution Center
The DC DC1 is advertising as a time server
The DS DC1 is advertising as a GC.
......................... DC1 passed test Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role Domain Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role PDC Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role Rid Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role Infrastructure Update Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
......................... DC1 passed test KnowsOfRoleHolders
Starting test: RidManager
ridManagerReference = CN=RID Manager$,CN=System,DC=corp,DC=mydomain,DC=com
* Available RID Pool for the Domain is 6103 to 1073741823
fSMORoleOwner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
* dc1.corp.mydomain.com is the RID Master
* DsBind with RID Master was successful
rIDSetReferences = CN=RID Set,CN=DC1,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com
* rIDAllocationPool is 5603 to 6102
* rIDPreviousAllocationPool is 5603 to 6102
* rIDNextRID: 5604
......................... DC1 passed test RidManager
Starting test: MachineAccount
* SPN found :LDAP/dc1.corp.mydomain.com/corp.mydomain.com
* SPN found :LDAP/dc1.corp.mydomain.com
* SPN found :LDAP/DC1
* SPN found :LDAP/dc1.corp.mydomain.com/MYDOMAIN
* SPN found :LDAP/6d452aba-3a2b-4ba0-bb53-dd5c0d4d3513._msdcs.corp.mydomain.com
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/6d452aba-3a2b-4ba0-bb53-dd5c0d4d3513/corp.mydomain.com
* SPN found :HOST/dc1.corp.mydomain.com/corp.mydomain.com
* SPN found :HOST/dc1.corp.mydomain.com
* SPN found :HOST/DC1
* SPN found :HOST/dc1.corp.mydomain.com/MYDOMAIN
* SPN found :GC/dc1.corp.mydomain.com/corp.mydomain.com
......................... DC1 passed test MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: w32time
* Checking Service: NETLOGON
......................... DC1 passed test Services
Starting test: OutboundSecureChannels
* The Outbound Secure Channels test
** Did not run Outbound Secure Channels test
because /testdomain: was not entered
......................... DC1 passed test OutboundSecureChannels
Starting test: ObjectsReplicated
DC1 is in domain DC=corp,DC=mydomain,DC=com
Checking for CN=DC1,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com in domain DC=corp,DC=mydomain,DC=com on 2 servers
Object is up-to-date on all servers.
Checking for CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com in domain CN=Configuration,DC=corp,DC=mydomain,DC=com on 2 servers
Object is up-to-date on all servers.
......................... DC1 passed test ObjectsReplicated
Starting test: frssysvol
* The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... DC1 passed test frssysvol
Starting test: frsevent
* The File Replication Service Event log test
There are warning or error events within the last 24 hours after the
SYSVOL has been shared. Failing SYSVOL replication problems may cause
Group Policy problems.
An Warning Event occured. EventID: 0x800034C4
Time Generated: 08/21/2015 11:33:12
(Event String could not be retrieved)
An Warning Event occured. EventID: 0x800034C5
Time Generated: 08/21/2015 12:15:16
(Event String could not be retrieved)
......................... DC1 failed test frsevent
Starting test: kccevent
* The KCC Event log test
Found no KCC errors in Directory Service Event log in the last 15 minutes.
......................... DC1 passed test kccevent
Starting test: systemlog
* The System Event log test
An Error Event occured. EventID: 0x825A0011
Time Generated: 08/21/2015 15:06:52
(Event String could not be retrieved)
An Error Event occured. EventID: 0x825A0011
Time Generated: 08/21/2015 15:07:04
(Event String could not be retrieved)
......................... DC1 failed test systemlog
Starting test: VerifyReplicas
......................... DC1 passed test VerifyReplicas
Starting test: VerifyReferences
The system object reference (serverReference)
CN=DC1,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com and backlink
on
CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
are correct.
The system object reference (frsComputerReferenceBL)
CN=DC1,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=corp,DC=mydomain,DC=com
and backlink on
CN=DC1,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com are correct.
The system object reference (serverReferenceBL)
CN=DC1,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=corp,DC=mydomain,DC=com
and backlink on
CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
are correct.
......................... DC1 passed test VerifyReferences
Starting test: VerifyEnterpriseReferences
......................... DC1 passed test VerifyEnterpriseReferences
Testing server: Default-First-Site-Name\DC2
Starting test: Replications
* Replications Check
DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com has 4 cursors.
DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com has 4 cursors.
CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com has 4 cursors.
CN=Configuration,DC=corp,DC=mydomain,DC=com has 4 cursors.
DC=corp,DC=mydomain,DC=com has 4 cursors.
* Replication Latency Check
DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
CN=Configuration,DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
DC=corp,DC=mydomain,DC=com
Latency information for 2 entries in the vector were ignored.
2 were retired Invocations. 0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc. 0 had no latency information (Win2K DC).
......................... DC2 passed test Replications
Starting test: Topology
* Configuration Topology Integrity Check
* Analyzing the connection topology for DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the connection topology for DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... DC2 passed test Topology
Starting test: CutoffServers
* Configuration Topology Aliveness Check
* Analyzing the alive system replication topology for DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for CN=Configuration,DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
* Analyzing the alive system replication topology for DC=corp,DC=mydomain,DC=com.
* Performing upstream (of target) analysis.
* Performing downstream (of target) analysis.
......................... DC2 passed test CutoffServers
Starting test: NCSecDesc
* Security Permissions Check for
DC=ForestDnsZones,DC=corp,DC=mydomain,DC=com
(NDNC,Version 2)
* Security Permissions Check for
DC=DomainDnsZones,DC=corp,DC=mydomain,DC=com
(NDNC,Version 2)
* Security Permissions Check for
CN=Schema,CN=Configuration,DC=corp,DC=mydomain,DC=com
(Schema,Version 2)
* Security Permissions Check for
CN=Configuration,DC=corp,DC=mydomain,DC=com
(Configuration,Version 2)
* Security Permissions Check for
DC=corp,DC=mydomain,DC=com
(Domain,Version 2)
......................... DC2 passed test NCSecDesc
Starting test: NetLogons
* Network Logons Privileges Check
......................... DC2 passed test NetLogons
Starting test: Advertising
The DC DC2 is advertising itself as a DC and having a DS.
The DC DC2 is advertising as an LDAP server
The DC DC2 is advertising as having a writeable directory
The DC DC2 is advertising as a Key Distribution Center
The DC DC2 is advertising as a time server
The DS DC2 is advertising as a GC.
......................... DC2 passed test Advertising
Starting test: KnowsOfRoleHolders
Role Schema Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role Domain Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role PDC Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role Rid Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
Role Infrastructure Update Owner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
......................... DC2 passed test KnowsOfRoleHolders
Starting test: RidManager
ridManagerReference = CN=RID Manager$,CN=System,DC=corp,DC=mydomain,DC=com
* Available RID Pool for the Domain is 6103 to 1073741823
fSMORoleOwner = CN=NTDS Settings,CN=DC1,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
* dc1.corp.mydomain.com is the RID Master
* DsBind with RID Master was successful
rIDSetReferences = CN=RID Set,CN=DC2,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com
* rIDAllocationPool is 5103 to 5602
* rIDPreviousAllocationPool is 5103 to 5602
* rIDNextRID: 5104
......................... DC2 passed test RidManager
Starting test: MachineAccount
* SPN found :LDAP/dc2.corp.mydomain.com/corp.mydomain.com
* SPN found :LDAP/dc2.corp.mydomain.com
* SPN found :LDAP/DC2
* SPN found :LDAP/dc2.corp.mydomain.com/MYDOMAIN
* SPN found :LDAP/1854b5ee-430a-4176-b18a-aaf114663fb1._msdcs.corp.mydomain.com
* SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/1854b5ee-430a-4176-b18a-aaf114663fb1/corp.mydomain.com
* SPN found :HOST/dc2.corp.mydomain.com/corp.mydomain.com
* SPN found :HOST/dc2.corp.mydomain.com
* SPN found :HOST/DC2
* SPN found :HOST/dc2.corp.mydomain.com/MYDOMAIN
* SPN found :GC/dc2.corp.mydomain.com/corp.mydomain.com
......................... DC2 passed test MachineAccount
Starting test: Services
* Checking Service: Dnscache
* Checking Service: NtFrs
* Checking Service: IsmServ
* Checking Service: kdc
* Checking Service: SamSs
* Checking Service: LanmanServer
* Checking Service: LanmanWorkstation
* Checking Service: RpcSs
* Checking Service: w32time
* Checking Service: NETLOGON
......................... DC2 passed test Services
Starting test: OutboundSecureChannels
* The Outbound Secure Channels test
** Did not run Outbound Secure Channels test
because /testdomain: was not entered
......................... DC2 passed test OutboundSecureChannels
Starting test: ObjectsReplicated
DC2 is in domain DC=corp,DC=mydomain,DC=com
Checking for CN=DC2,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com in domain DC=corp,DC=mydomain,DC=com on 2 servers
Object is up-to-date on all servers.
Checking for CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com in domain CN=Configuration,DC=corp,DC=mydomain,DC=com on 2 servers
Object is up-to-date on all servers.
......................... DC2 passed test ObjectsReplicated
Starting test: frssysvol
* The File Replication Service SYSVOL ready test
File Replication Service's SYSVOL is ready
......................... DC2 passed test frssysvol
Starting test: frsevent
* The File Replication Service Event log test
......................... DC2 passed test frsevent
Starting test: kccevent
* The KCC Event log test
Found no KCC errors in Directory Service Event log in the last 15 minutes.
......................... DC2 passed test kccevent
Starting test: systemlog
* The System Event log test
Found no errors in System Event log in the last 60 minutes.
......................... DC2 passed test systemlog
Starting test: VerifyReplicas
......................... DC2 passed test VerifyReplicas
Starting test: VerifyReferences
The system object reference (serverReference)
CN=DC2,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com and backlink
on
CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
are correct.
The system object reference (frsComputerReferenceBL)
CN=DC2,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=corp,DC=mydomain,DC=com
and backlink on
CN=DC2,OU=Domain Controllers,DC=corp,DC=mydomain,DC=com are correct.
The system object reference (serverReferenceBL)
CN=DC2,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=corp,DC=mydomain,DC=com
and backlink on
CN=NTDS Settings,CN=DC2,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=mydomain,DC=com
are correct.
......................... DC2 passed test VerifyReferences
Starting test: VerifyEnterpriseReferences
......................... DC2 passed test VerifyEnterpriseReferences
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : corp
Starting test: CrossRefValidation
......................... corp passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... corp passed test CheckSDRefDom
Running enterprise tests on : corp.mydomain.com
Starting test: Intersite
Skipping site Default-First-Site-Name, this site is outside the scope
provided by the command line arguments provided.
......................... corp.mydomain.com passed test Intersite
Starting test: FsmoCheck
GC Name: \\dc1.corp.mydomain.com
Locator Flags: 0xe00003fd
PDC Name: \\dc1.corp.mydomain.com
Locator Flags: 0xe00003fd
Time Server Name: \\dc1.corp.mydomain.com
Locator Flags: 0xe00003fd
Preferred Time Server Name: \\dc1.corp.mydomain.com
Locator Flags: 0xe00003fd
KDC Name: \\dc1.corp.mydomain.com
Locator Flags: 0xe00003fd
......................... corp.mydomain.com passed test FsmoCheck