ÔÚWindowsµÄ»î¶¯Ä¿Â¼·þÎñÖУ¬Óò¿ØÖÆÆ÷µÄ»î¶¯Ä¿Â¼Êý¾Ý¿âÀï°üº¬×ÅËùÓÐĿ¼¶ÔÏ󣬱ÈÈçÓû§Õʺţ¬»úÆ÷ÕÊºÅºÍÆäËü¸÷ÖÖÀàÐ͵ĶÔÏó¡£¶ø¡°Ä¿Â¼¸´ÖÆ¡±×é¼þÔò¸ºÔð°Ñ·¢ÉúÔÚ¸ÃÓò¿ØÖÆÆ÷ÉϵÄĿ¼¶ÔÏó¸ü¸Ä¸´ÖƵ½ÆäËüÓò¿ØÖÆÆ÷ÉÏÈ¥£¬ÒÔ±£Ö¤ËùÓÐÓò¿ØÖÆÆ÷µÄÊý¾Ý¿âÄÚÈÝÏà¶ÔÒ»Ö¡£Èç¹ûÓò¿ØÖÆÖ®¼äµÄĿ¼¸´ÖÆ·¢ÉúÁËÎÊÌ⣬Ôò»áÒýÆð·Ç³£ÑÏÖØµÄÎÊÌâ¡£±ÈÈçÄãÔÚ±±¾©µÄÓò¿ØÖÆÆ÷ÉÏ´´½¨ÁËÒ»¸öÕʺţ¬Èç¹û±±¾©ºÍ¹ãÖݵÄÓò¿ØÖÆÆ÷¸´ÖÆ·¢ÉúÎÊÌ⣬µ¼Ö¹ãÖݵÄÓò¿ØÖÆÆ÷ÎÞ·¨µÃµ½Äã¸Õ²Å´´½¨µÄÓû§Õʺţ¬ÄÇôÄãÔÚ¹ãÖݵĿͻ§¾Í¿ÉÄÜÎÞ·¨Ê¹ÓøÃÕʺŽøÐÐÏà¹ØµÄ²Ù×÷ÁË¡£¿ÉÏë¶øÖª£¬»î¶¯Ä¿Â¼µÄ¸´ÖÆÔÚÆóÒµµÄÓ¦ÓÃÖÐÊǺεȵÄÖØÒª¡£
ÓÉÓڻĿ¼µÄ¸´ÖÆ·þÎñÊÇÒ»Ïî·Ç³£¸ß¶ËµÄÓ¦Óã¬ËüµÄÕý³£Ö´Ðзdz£ÒÀÀµÓÚÏà¶Ôµ×²ãµÄ·þÎñºÍ×é¼þµÄÖ´ÐÐ״̬¡£ÈÃÎÒÃÇÀ´»Ø¹ËÒ»ÏÂÕû¸ö¸´Öƹý³Ì£ºµ±Ò»Ì¨Óò¿ØÖÆÆ÷ÉÏij¸öĿ¼¶ÔÏó·¢ÉúÁ˵ıä¸üºó£¬¸ÃÓò¿ØÖÆÆ÷¶ÔÕâ¸öеıä¸Ä¸³ÓèÒ»¸öÖµ£¬ÎÒÃdzÆÖ®ÎªUSN£¨unique sequence number£©¡£È»ºó£¬¸ÃÓò¿ØÖÆÆ÷¼ì²âÄÄЩÓò¿ØÖÆÆ÷ÊÇÆä¸´ÖÆ»ï°é£¬²¢Í¨¹ýDNS·þÎñÆ÷À´µÃµ½ËûÃǵÄIPµØÖ·¡£Ëæºó£¬¸Ã·þÎñÆ÷ºÍËûµÄ¸´ÖÆ»ï°é½øÐлùÓÚkerberosÐÒéµÄË«ÏòÑéÖ¤¡£Í¨¹ýÑéÖ¤ºó£¬¸ÃÁ½¸öÓò¿ØÖÆÆ÷½¨Á¢ÁËRPC£¨Remote Procedure Call£©Á¬½Ó¡£»ùÓÚRPCÁ¬½Ó£¬£¬Ä¿±êÓò¿ØÖÆÆ÷ÏòÔ´Óò¿ØÖÆÆ÷·¢³ö»ñÈ¡×îеĸüеÄÇëÇ󣬵±Ä¿±ê·þÎñÆ÷µÃµ½À´×ÔÔ´Óò¿ØÖÆÆ÷µÄ±ä¸üºó£¬Í¨¹ýESENT£¨Extensible Storage Engine£©µÄÒýÇæ°ÑÕâЩÄÚÈÝдµ½ADµÄÊý¾Ý¿âÀ¸´ÖƵ½´Ë½áÊø¡£´ÓÕâÒ»¶Î¹ý³ÌÖпÉÒÔ¿´³ö£¬Ä¿Â¼¸´ÖƵijɹ¦Ö´ÐÐÓë¸´ÖÆµÄÍØÆË½á¹¹£¬ÍøÂçÃû×Ö½âÎö£¨DNS£©£¬°²È«£¨Kerberos£©£¬RPCÒÔ¼°ADµÄÊý¾Ý¿âÓÐ׎ôÃܵÄÁªÏµ¡£ÓÉÓÚĿ¼¸´ÖÆÎÊÌâµÄ²î´í¸²¸ÇÃæ·Ç³£¹ã·º£¬ÎÒÃÇÕâÀï¾ÍÆäÏàÒÀÀµµÄ×é¼þÕâÒ»²¿·Ö×öÒ»ÏÂÌÖÂÛ£¬Ã¶¾ÙһЩ·½·¨À´¼ì²âÕâЩÄÚÈÝÊÇ·ñÕýÈ·Ö´ÐС£
Ŀ¼¸´ÖƵÄÍØÆË½á¹¹ºÍ¸´ÖÆ×´Ì¬£º
ͨ³££¬Äã¿ÉÒÔʹÓá°repadmin.exe¡±Õâ¸ö¹¤¾ß¿ÉÒÔÓÃÀ´¼ì²â¸Ã·þÎñÆ÷´ÓÄÄЩԴÓò¿ØÖÆÆ÷¸´ÖÆADµÄÄÚÈÝ£¬Í¬Ê±¼ì²â¸ÃÏî¸´ÖÆÊÇ·ñÕýÈ·¡£±ÈÈ磺
C:>repadmin /showreps
Default-First-Site-NameDC01
DSA Options : (none)
objectGuid : a0d6dbaf-4297-47b3-92b8-2d604d290bb5
invocationID: e805158b-f7e1-4d23-a797-5121262c0fa2
==== INBOUND NEIGHBORS ======================================
CN=Schema,CN=Configuration,DC=domain,DC=com
Default-First-Site-NameDC02 via RPC
objectGuid: 035046f0-5de5-4adb-b1fc-259614a8de64
Last attempt @ 2007-01-01 05:58.19 failed, result 8453:
Replication access was denied.
Last success @ 2007-01-01 04:12.01. 14 consecutive failure(s).
CN=Configuration,DC=Domain,DC=com
Default-First-Site-NameDC02 via RPC
objectGuid: 035046f0-5de5-4adb-b1fc-259614a8de64
Last attempt @ 2007-01-01 05:58.19 failed, result 8453:
Replication access was denied.
Last success @ 2007-01-01 12:12.01. 14 consecutive failure(s).
DC=RESKIT,DC=com
Default-First-Site-NameDC02 via RPC
objectGuid: 035046f0-5de5-4adb-b1fc-259614a8de64
Last attempt @ 2007-01-01 05:58.19 failed, result 8453:
Replication access was denied.
Last success @ 2007-01-01 12:12.01. 14 consecutive failure(s).
ÒÔÉÏÁбí±íÃ÷DC01³¢ÊÔ´ÓDC02¸´ÖÆADÄÚÈÝ£¬µ«ÊÇÓÉÓÚ¡°Access is denied¡±µÄ´íÎ󣬸´ÖÆÊ§°ÜÔÚ3¸öÇøÓòÈ«²¿Ê§°Ü¡£Äã´Ó¸ÃÁбíÀïµÃµ½´íÎóµÄÔÒòÊÇ¡°Access is denied¡±£¬ÄÇôÄãµÄÏÂÒ»²½·½Ïò¾ÍÊÇ´Ó°²È«·½ÃæÈëÊֲ鿴Ϊʲô»áÓС°Access Denied¡±´íÎó¡£Í¬Ê±Ä㻹¿ÉÒԴӸղŵı¨¸æÖеõ½¸½¼ÓµÄÐÅÏ¢£¬±ÈÈç·þÎñÆ÷µÄGUID¡£DC02 µÄIDÊÇ035046f0-5de5-4adb-b1fc-259614a8de64¡£ Õâ¸öID·Ç³£ÖØÒª£¬ËüÊÇDC01ÓÃÀ´Ñ°ÕÒDC02IPµØÖ·µÄΨһÒÀ¾Ý¡£
ÍøÂçÃû×Ö½âÎö£º
ÓÉÓÚ¸´ÖƵĻúÖÆÊǽ¨Á¢ÔÚTCP/IPͨѶÐÒ飬ÄÇôÓò¿ØÖÆÆ÷ÊÇʹÓÃDNSÀ´Íê³ÉѰÕÒ¶Ô·½µÄÈÎÎñµÄ¡£Í¨³££¬Äã¿ÉÒÔʹÓÃnslookup.exeÀ´ÑéÖ¤µ±Ç°DNS·þÎñÆ÷ÊÇ·ñÄÜÌṩÕýÈ·µÄÃû×Ö½âÎö¡£ÔÚ¸´ÖÆÖУ¬Óò·þÎñÆ÷ÐèÒªÌṩ¸´ÖÆ»ï°éµÄGUID¡£±ÈÈç˵£¬Èç¹û¶Ô·½µÄGUIDÊÇ035046f0-5de5-4adb-b1fc-259614a8de64£¬ÄÇôÓò¿ØÖÆÆ÷¾ÍÐèÒªÏòDNS²éѯ£º035046f0-5de5-4adb-b1fc-259614a8de64._msdcs.domain.com Ëù¶ÔÓ¦µÄIPµØÖ·¡£Äã¿ÉÒÔͨ¹ýÏÂÁв½ÖèÀ´¼ì²âDNSÊÇ·ñ¹¤×÷Õý³££º
µÚÒ»²½£ºÊ¹Óà ipconfig °Ñµ±Ç°ÔÚDNS»º´æÀïµÄÄÚÈÝö¾Ù³öÀ´
C:>ipconfig /displaydns
Windows IP Configuration
1.0.0.127.in-addr.arpa
----------------------------------------
Record Name . . . . . : 1.0.0.127.in-addr.arpa.
Record Type . . . . . : 12
Time To Live . . . . : 0
Data Length . . . . . : 4 Section . . . . . . . :
Answer PTR Record . . . . . : localhost
RESKIT-DC2
----------------------------------------
Record Name . . . . . : RESKIT-DC2.reskit.com
Record Type . . . . . : 1
Time To Live . . . . : 1506
Data Length . . . . . : 4
Section . . . . . . . :
Answer A (Host) Record . . . : 54.34.192.30
µÚ¶þ²½£º³¢ÊÔÓÃnslookupÀ´½âÎöÖ÷»úÃû³Æ¡£NslookupÖ±½Ó²éѯDNS·þÎñÆ÷µÄÄÚÈÝ£¬²»»áʹÓÃ×Ô¼ºDNS»º´æÀïµÄÄÚÈÝ£¬ÕâÑù£¬Äã¾Í¿ÉÒԱȽÏnslookupºÍDNS»º´æµÄ½á¹ûÀ´ÑéÖ¤ÄÚÈÝÊÇ·ñÒ»Ö¡£
C:>nslookup reskit-dc2.reskit.com
Server: ns.reskit.com
Address: 61.53.4.32
Name: reskit-dc2.reskit.com
Address: 54.34.192.30
µÚÈý²½£ºÈç¹ûÉÏÊöÁ½²½¶¼ÎÞ·¨µÃµ½ÕýÈ·½á¹û£¬ÄÇôÎÊÌâ¿ÉÄÜ»áÊÇ
1£® ·þÎñÆ÷Ãû×Ö²»¶Ô
2£® Óòºó׺Ãû²»¶Ô
3£® DNS·þÎñʧЧ
4£® ¶ą̀DNS·þÎñÆ÷µÄÄÚÈݲ»Ò»ÖÂ
5£® ÍøÂçÔÒòµ¼ÖÂÎÞ·¨ºÍDNS·þÎñÆ÷ͨѶ
µÚËIJ½£º¼ì²â¸Õ²Ådns»º´æ»ònslookupÀïµÃµ½IPÊÇ·ñΪ¸´ÖÆ»ï°éµÄIP
µÚÎå²½£ºÈç¹ûdns»º´æÀïµÄipÓÐÎó£¬Ê¹ÓÃipconfig°Ñ»º´æÇå¿Õ
C:>ipconfig /flushdns
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
µÚÁù²½£º³¢ÊÔÓÃnslookupÀ´½âÎöÓÉGUID×é³ÉµÄ¸´ÖÆ»ï°éµÄDNSÃû×Ö¡£Õâ¸öÃû×ֵĽṹÊÇ
C:>NSLOOKUP 035046f0-5de5-4adb-b1fc-259614a8de64._msdcs.reskit.com
Server: ns.reskit.com
Address: 65.53.4.32
Name: RESKIT-DC2.reskit.com
Address: 54.34.192.30
Aliases: 035046f0-5de5-4adb-b1fc-259614a8de64._msdcs.reskit.com
µÚÆß²½£ºÈç¹ûnslookupÄܹ»³É¹¦°ÑÒÔÉÏÃû×Öת»»³ÉIPµØÖ·£¬ÄÇôÕâ¾ÍÖ¤Ã÷DNSµÄ·þÎñ¹¤×÷ÊÇÕý³£µÄ£¬Èç¹û²»Äܵõ½ÕýÈ·IP£¬ÔòÓпÉÄÜÊǿͻ§¶ËÁªÏµÁËһ̨´íÎóµÄDNS·þÎñÆ÷£¬»òÕ߸÷þÎñÆ÷Êý¾Ý¿âûÓеõ½¼°Ê±¸üС£
RPCÁ¬½Ó£º
ÔÚRPCͨѶÖУ¬Endpoint Mapper ÊÇÒ»¸öÓÃÀ´´æ´¢RPC·þÎñÐÅÏ¢µÄÊý¾Ý¿â¡£RPC·þÎñÕìÌýTCP135¶Ë¿ÚÀ´»ñÖªÄĸö¿Í»§¶Ë³¢ÊÔµ÷ÓÃÏà¹ØµÄRPCÇëÇó¡£µ±µÃµ½Ïà¹ØµÄ¿Í»§ÇëÇó£¬RPC·þÎñÔò¶¯Ì¬·ÖÅäÒ»¸ö¶Ë¿Ú¹©¿Í»§¶ËµÄ·þÎñÆ÷ͨѶʹÓá£Óɴ˿ɼûÔÚ¼ì²âRPCÁ¬½ÓʱÎÒÃÇÐèÒª¼ì²âÒ»ÏÂһЩÄÚÈÝ£º
1. ¼ì²âÓò¿ØÖÆÆ÷µÄTCP 135¶Ë¿ÚûÓб»·â±Õ¡£
2. ¼ì²âĿ¼·þÎñÔÚÕìÌý¸Ã¶Ë¿Ú¡£
3. ¼ì²â±»·ÖÅäµÄ¶¯Ì¬¶Ë¿ÚûÓб»·â±Õ¡£
ΪÁ˽øÐÐÉÏÊö¼ì²â£¬Äã¿ÉÒÔʹÓÃportqry.exe ºÍrpcdump.exeÁ½¸ö¹¤¾ß¡£±ÈÈçÏÂÃæÕâ¸ö°¸ÀýÊÇÓÃÀ´¼ì²âTCP¶Ë¿Ú135ÊÇ·ñ´ò¿ª£¬²¢ÇÒDRS RPC endpointµÄͨѶÊÇ·ñÕý³££º
1. ÓÃrpcdumpÀ´²éѯDRS endpoint ÊÇ·ñÒѾÔÚRPCµÄendpoint mapper Êý¾Ý¿âÀï½øÐÐÁË×¢²á
C:>Rpcdump /s
2. ´ò¿ªendpoint.txt Îļþ£¬²é¿´ncacn_ip_tcp Ò»¶ÎÀïÊÇ·ñÓÐe3514235-4b06-11d1-ab04-00c04fc2dcd2 µÄUUID¡£±ÈÈ磺
ProtSeq:ncacn_ip_tcp
Endpoint:1025
NetOpt:
Annotation:MS NT Directory DRS Interface
IsListening:YES
StringBinding:ncacn_ip_tcp:65.53.63.15[1025]
UUID:e3514235-4b06-11d1-ab04-00c04fc2dcd2
ComTimeOutValue:RPC_C_BINDING_DEFAULT_TIMEOUT
VersMajor 4 VersMinor 0
3. Èç¹ûIsListeningÀ¸ÀïÏÔʾµÄÊÇ¡°YES¡±£¬ÔòTCP 135¶Ë¿ÚºÍDRS½Ó¿ÚµÄͨѶÊdz©Í¨ÎÞ×èµÄ¡£´ÓÉÏÃæµÄ±¨¸æ£¬Ä㻹¿ÉÒÔÖªµÀDRS½Ó¿ÚʹÓÃ1025¶¯Ì¬¶Ë¿Ú¡£
4. Èç¹ûIsListeningÀ¸ÀïÏÔʾ¡°NO¡±£¬»òÕß±¨¸æµÚÒ»ÐоÍÏÔʾ²éѰ´íÎ󣬻òÕßûÓÐÈκÎ×¢²áµÄendpoint£¬ÄÇôÔòÎÊÌâ¿ÉÄܺͶ˿ڱ»·âÓйأ¬ÄãÐèÒªºÍÄúµÄÍøÂ繩ӦÉÌÁªÏµ²ì¿´Ò»ÏÂÄĸöÍøÂçÉ豸×è¶ÏÁ˸ö˿ڡ£±ÈÈ磺
Querying Endpoint Mapper Database...
137 registered endpoints found.
°²È«£º
»î¶¯Ä¿Â¼¸´ÖÆÊ¹ÓÃKerberosÀ´½øÐÐË«·½µÄÉí·ÝÑéÖ¤£¬Í¬Ê±·þÎñÆ÷Éϵݲȫ²ßÂÔÅäÖÃÒ²Ö±½ÓÓ°ÏìĿ¼¸´ÖƵÄÕý³£½øÐС£ÔÚÄú½øÐа²È«·½ÃæµÄ¼ì²âʱ£¬ÄãÐèÒª²ì¿´ÊÇ·ñË«·½µÄ·þÎñÆ÷ʱ¼äÏàÒ»Ö£¬·ñÔòkerberosÈÏÖ¤»á·µ»ØÏà¹Ø´íÎó¡£²¢ÇÒ£¬ÄúÐèÒª¼ì²â·þÎñÆ÷ÊÇ·ñ×¢²áÏàÓ¦µÄSPN Ãû×Ö £¨e3514235-4b06-11d1-ab04-00c04fc2dcd2/ntdsa_objectGUID/domainname£©£¬±£Ö¤Ë«·½µÄ¼ÆËã»úÃÜÂëÔÚË«·½µÄÊý¾Ý¿âÀïÊÇͬ²½µÄ¡£ÕâÀïö¾ÙÁËһЩÄãÔÚ°²È«·½Ãæ±ØÐëÒª½øÐмì²éµÄÄÚÈݺͲ½Ö裺
¼ì²â¡°Access this computer from network user right¡±
ÔÚMPS±¨¸æÀÕÒµ½¡¡£¼computername£¾_userrights.txt Îļþ£¬È·ÈÏeveryone£¬authenticated users£¬ÒÔ¼°enterprise domain controllers ×éÓµÓиÃȨÏÞ¡£
¼ì²âÓò¿ØÖÆÆ÷ʱ¼äÊÇ·ñͬ²½£º
Äã¿ÉÒÔʹÓá°net time PDC /set /y¡±À´Í¬²½¸Ą̃Óò¿ØÖÆÆ÷ºÍPDCµÄʱ¼ä¡£
¼ì²âÓò¿ØÖÆÆ÷userAccountControlÊôÐÔÒÔ¼°KerberosÐÅÈΣº
1£® È·ÈÏË«·½µÄKDC·þÎñ¶¼ÊÇÔÚÆô¶¯µÄ״̬¡£
2£® È·ÈϸüÆËã»úÕʺŵġ°Trust computer for delegation¡±µÄÑ¡ÏîÒѾ¼¤»î¡£
3£® Èç¹ûÓÃadsiedit»òldp¹¤¾ß²ì¿´¸Ã¼ÆËã»úµÄuserAccountControlÊôÐÔ£¬ËüµÄֵΪ532480 £¨0x82000£©
4£® Èç¹ûÁ½Ì¨Óò¿ØÖÆÆ÷ÔÚ²»Í¬µÄÓòÀÄÇôʹÓá°Active Directory Domains and Trusts À´ÑéÖ¤Á½¸öÓòµÄÐÅÈÎÁ¬½ÓÊÇ·ñÕý³£¡£
¸ü¸ÄKDCÏà¹ØµÄÉèÖãº
µ±Ä¿Â¼¸´ÖÆ·þÎñÒѾÓÉÓÚ°²È«¼ì²âûÓÐͨ¹ý¶øÖжϣ¬ÄãÐèÒª¸ü¸ÄKDCµÄÏà¹ØÅäÖÃÀ´Ê¹Á½Ì¨»úÆ÷µÄÑéÖ¤µÃÒÔͨ¹ý¡£
1£® Èç¹û¼ÆËã»úÔÚ²»Í¬µÄÓò£¬ÄãÔÚÔ´Óò¿ØÖÆÆ÷ÉÏÌí¼ÓÈçÏÂ×¢²á±í¼üÖµ£º
HKEY_LOCAL_MACHINESystemCurrentControlSetServicesNTDSParameters
Value name: Replicator Allow SPN Fallback
Value type: REG_DWORD
Value data: 1
2. ÔÚÔ´¿ØÖÆÆ÷ÉÏÔËÐУº
C:>repadmin /add cn=configuration,dc=
3. µ±ÄãÍê³ÉÉÏÊöÖ¸Áîºó£¬É¾³ý¡°Replicator Allow SPN FallBack¡±¼üÖµ¡£
ÖØÐÂÉèÖüÆËã»úÃÜÂëºÍ¸üÐÂkerberosµÄ»º´æÄÚÈÝ£º
Ôڵõ½¡°Access is denied¡±´íÎóʱ£¬Äú¿ÉÄÜÐèÒªÖØÉè¼ÆËã»úÃÜÂ룺
1£® Í£Ö¹µ±Ç°KDC·þÎñ¡£¡°C:>net stop kdc¡±
2£® Çå³ýÓû§µÄkerberos»º´æÄÚÈÝ¡£¡°c:>Klist purgeall¡±
3£® ͨ¹ý¼Æ»®ÈÎÎñ·þÎñÆô¶¯Ò»¸öÓÉLocalSystemÕÊºÅÆô¶¯µÄCMD´°¿Ú
C:>at system_time /interactive cmd.exe
4. µ±ÏµÍ³µ¯³öCMD´°¿Úºó£¬Ôڸô°¿ÚÀïÔËÐС°c:>klist purgeall¡±.ÕâÑùϵͳµÄkerberos»º´æÄÚÈÝÒ²±»Çå¿ÕÁË¡£
5. ÔÚCMD´°¿ÚÀïÖ´ÐÐÒÔÏÂÖ¸ÁîÀ´ÖØÉè¼ÆËã»úÃÜÂ룺
C:>netdom resetpwd /server:PDC /userD:domainadmin_account /PasswordD:*
ÄúÐèÒªÔÚ°´»Ø³µ·ûºóÌṩ¸ÃÕʺŵÄÃÜÂë¡£µ±ÄúÊÕµ½³É¹¦µÄÏûÏ¢ºó£¬³¢ÊÔͨ¹ý·ÃÎÊPDCµÄFQDNÃû×ÖÀ´Ê¹×Ô¼ºµÄ¸üÐÂkerberos Ʊ֤¡£
C:>net use PDC.domain.comIPC$
6. ÓÃAD Site and Service À´ÖØÐ¼ì²â¸´ÖƵÄÍØÆËÂß¼£¬»òÕßÓÃÃüÁîÐз½Ê½¼ì²âKCC¡£ ¡°C:>repadmin /KCC¡±
7. ËæºóÓÃrepadmin /syncall /d /e
¼ì²âSPNµÄ×¢²áÇé¿ö£º
1£® Ê×ÏÈ£¬ÔËÐС°SETSPN DC1¡±£¬Äú»áµÃµ½ÈçÏÂÀàËÆÊä³ö£º
Registered ServicePrincipalNames for CN=dc1,OU=Domain
Controllers,DC=mydomain,DC=com:
HOST/dc1
HOST/dc1.mydomain.com
HOST/dc1.mydomain.com/mydomain.com
GC/dc1.mydomain.com/mydomain.com
LDAP/3cb25b0f-3809-48fb-8571-59f4a2253846._msdcs.mydomain.com
LDAP/dc1.mydomain.com/mydomain
LDAP/dc1
LDAP/dc1.mydomain.com
LDAP/dc1.mydomain.com/mydomain.com
HOST/dc1.mydomain.com/mydomain
E3514235-4B06-11D1-AB04-00C04FC2DCD2/3cb25b0f-3809-48fb-8571-59f4a2253846/mydomain.com
×îºóÒ»ÏîÃû×ÖÊÇĿ¼¸´ÖÆ×¢²áËùÓõÄSPNÃû×Ö£¬Èç¹ûÄãûÓÐÕҵĸÃÃû×Ö£¬ÔòĿ¼¸´ÖÆÎÞ·¨Õý³£½øÐУ¬Äã±ØÐëΪ¸Ã·þÎñÆ÷ÖØÐÂ×¢²á¸ÃÃû×Ö¡°setspn -a E3514235-4B06-11D1-AB04-00C04FC2DCD2/3cb25b0f-3809-48fb-8571-59f4a2253846/mydomain.com¡±
ÐèҪעÒâµÄÊÇ¡°E3514235-4B06-11D1-AB04-00C04FC2DCD2¡±ÊÇÒ»¸ö¹Ì¶¨Öµ£¬Äã²»ÐèÒª¸ü¸ÄËû¡£¶øºóÃæÒ»¸öÖµ¡°3cb25b0f-3809-48fb-8571-59f4a2253846¡±ÊǸ÷þÎñÆ÷µÄGUID£¬Äã¿ÉÒÔͨ¹ýDNSµÄ_msdcs ÇøÓòµÃµ½¸Ã·þÎñÆ÷µÄÖµ¡£
2£® ÓÃÈçÏÂÃüÁîÀ´¼ì²â¸ÃÓò¿ØÖÆÆ÷ÊÇ·ñÓµÓÐÁ½¸ö»òÁ½¸öÒÔÉÏÏàͬµÄSPN¡£ÀíÂÛÉÏÀ´½²£¬Ò»¸öÓò¿ØÖÆÆ÷Ö»ÄÜÓÐÒ»¸ö¶ÔÓ¦µÄDRS SPN¡£
¡°LDIFDE ¨Cf output.txt ¨Cd dc=domain,dc=com ¨Cr ¡°(&(objectclass=user)(serviceprincipalname= E3514235-4B06-11D1-AB04-00C04FC2DCD2/3cb25b0f-3809-48fb-8571-59f4a2253846/mydomain.com))¡± ¨Cl ¡°dn,ServicePrincipalName,ObjectClass,saMAccountName¡±¡±
¼ì²â¸´ÖÆÇøÓòµÄȨÏÞ£º
Óò¿ØÖÆÆ÷±ØÐë¶ÔÐèÒª¸´ÖƵÄÇøÓòÓС°¸´ÖÆ¡±µÄȨÏÞ¡£Èç¹û¸ÃÓò¿ØÖÆÆ÷ÓÐ3¸ö¸´ÖÆÇøÓò£¬domain£¬configurationºÍschema¡£ÄÇô±ØÐë¼ì²âÓò¿ØÖÆÆ÷µÄ»úÆ÷ÕʺÅÓжԸÃ3¸öÇøÓòµÄ¸´ÖÆÈ¨ÏÞ¡£
i. ÔËÐÐadsiedit
ii. ÓÒ¼üµã»÷ÿһ¸öÇøÓòµÄ¸ù½áµã£¬Ñ¡Ôñ¡°ÄÚÈÝ¡±
iii. ÔÚ°²È«Ò³ÀïµÄÃû×ÖÀ¸Àïµã»÷¡°Enterprise Domain Controllers¡±£¬È·ÈϸÃ×éÓÐ ¡°manage replication topology¡±¡°Replication Directory Changes¡±¡°Replication Synchronization¡±È¨ÏÞ£¬Í¬Ê±±ØÐëÈ·ÈϸüÆËã»úÕʺÅÔÚ¡°Enterprise domain controller¡±×éÀï¡£
°²È«²ßÂÔ¼ì²â£º
ʹÓá°secedit /export /mergedpolicy /cfg sec.txt¡±µ¼³öË«·½·þÎñÆ÷µÄ°²È«²ßÂÔÅäÖ㬼ì²âË«·½µÄSMBÐÒéÅäÖÃÊÇ·ñÇ¡µ±£¬Õâ°üÀ¨ÈçÏÂÄÚÈÝ£º
Digitally Sign Client Communication (Always).
Digitally Sign Client Communication (When Possible).
Digitally Sign Server Communication (Always).
Digitally Sign Server Communication (When Possible).
LAN Manager Authentication Level.
Crash on Audit Fail.
ADÊý¾Ý¿â£º
³£¼ûµÄµ¼ÖÂĿ¼¸´ÖÆÊ§°ÜµÄÊý¾Ý¿â·½ÃæÔÒòÓÐÈý¸ö£º
1£® Êý¾Ý¿âµÄÊý¾ÝËð»µ
2£® ´ÅÅ̿ռ䲻¹»£¬µ¼ÖÂÊý¾ÝÎÞ·¨¸üе½Êý¾Ý¿âÈÕÖ¾ÎļþÀï¡£
3£® ·À²¡¶¾Èí¼þËø×¡ÁËÊý¾Ý¿âÈÕÖ¾Îļþ£¬µ¼ÖÂADÎÞ·¨Õý³£´ò¿ªÈÕÖ¾Îļþ¡£
ͨ³£Èç¹ûÊÇÊý¾Ý¿â·¢ÉúÎÊÌ⣬ÄãÄÜÔÚĿ¼Ê¼þÈÕÖ¾ÀïÊÕµ½Ïà¹ØµÄ´íÎóÌáʾ¡£ÕâÑùÄúÐèÒª°Ñ·þÎñÆ÷ÖØÐÂÆô¶¯ÖÁĿ¼·þÎñ»Ö¸´Ä£Ê½£¬È»ºóÓÃntdsutil.exeÀ´ÐÞ¸´Ë𻵵ÄÊý¾Ý¿â¡£ÐèҪעÒâµÄÊÇÈç¹ûÄúʹÓõÄÊÇWIndows2000Óò¿ØÖÆÆ÷£¬Ç§Íò²»ÒªÊ¹Óá°repair¡±Ä£Ê½½øÐÐÐÞ¸´¡£ÒòΪÈç¹ûʹÓÃÁËrepairģʽÀ´½øÐÐÐÞ¸´µÄ»°£¬ADµÄÊý¾Ý¿â²¿·ÖÄÚÈݻᶪʧ£¬Èç¹û¶ªÊ§µÄÄÚÈÝÉæ¼°µ½schema,Ôòºó¹û²»¿°ÉèÏ룬ºÜÓпÉÄÜ»¹»áµ¼ÖÂÆäËûÓò¿ØÖÆÆ÷µÄÊý¾Ý¿âË𻵡£
×ܽ᣺
×îºó£¬ÎÒÃÇÀ´Ì¸Ò»ÏÂÒ»ÖֱȽÏÌØÊâµÄÇé¿ö¡£ºÜ¶àʱºòµ±Ç°Óò¿ØÖÆÆ÷ÎÞ·¨¼°Ê±µÃµ½·¢ÉúÔÚÁíһ̨·þÎñÆ÷µÄ¶ÔÏó±ä¸ü¡£Èç¹ûÄãÔÚAD Site and ServiceÇ¿ÖÆ½øÐи´ÖÆ£¬Ôò¸Ã´°¿Ú»áÍ£Ö¹ÏìÓ¦¡£Èç¹ûÄúÔËÐС°repadmin /showreps¡±£¬Äã»á·¢ÏÖÔÚ³¢ÊÔ¸´ÖÆÏà¹ØÇøÓòµÄʱºò£¬¸Ã·þÎñÆ÷µÃµ½ÈçÏ·µ»ØÐÅÏ¢¡°The replication job is preemptied¡±¡£
ÆäʵÕâ¸öÏÖÏó²¢²»ÊÇÒ»¸ö´íÎó£¬ËûÖ»ÊÇÌáʾµ±Ç°µÄ¸´ÖÆÈÎÎñ±»ÆäËûÈÎÎñ¸øÇÀÕ¼ÁË£¬ÐèÒªÑÓºóÖ´ÐС£Õâ¸öÏÖÏóµÄÔÒòÖ÷ÒªÊÇÒòΪĿ¼·þÎñµÄÒýÇæÊÇÒ»¸öµ¥Ïß³ÌÈÎÎñ£¬Ã¿Ò»¸öºÍĿ¼¸´ÖÆÏà¹ØµÄÈÎÎñ¶¼ÓÐËû¹Ì¶¨µÄÓÅÏȼ¶¡£±ÈÈçKCC¼ì²âÍØÆËÂß¼µÄÓÅÏȼ¶½Ï¸ß£¬Õ¾Ì¨ÄÚ²¿¸´ÖƵÄÈÎÎñ±È¿çվ̨¸´ÖƵÄÓÅÏȼ¶¸ß£¬ÓòÄڵĸ´ÖƱÈÈ«¾Ö±àÂ¼ÇøÓòµÄ¸´ÖÆÓÅÏȼ¶¸ß£¬Í¬²½¸´ÖƱÈÒì²½¸´ÖƵÄÓÅÏȼ¶¸ß¡£µ±Óи´ÖÆÏà¹ØÈÎÎñ²úÉúʱ£¬ÏµÍ³°Ñ¸ÃÈÎÎñ·ÅÈëÒ»¸ö¶ÓÁÐÀȻºó°´ÕÕÆäÓÅÏȼ¶´Ó¸ßµ½µÍÒÀ´ÎÖ´ÐÐÔڸöÓÁÐÀïµÄËùÓÐÈÎÎñ£¬Èç¹ûϵͳÔÚÖ´ÐÐÒ»¸öÈÎÎñʱÓÐÒ»¸ö½Ï¸ßÓÅÏȼ¶µÄÈÎÎñ½øÈë¶ÓÁÐÀÔòϵͳÖжϵ±Ç°ÈÎÎñ£¬¶øÈ¥Ö´ÐиսøÈë¶ÓÁеĸßÓÅÏȼ¶ÈÎÎñ¡£¶ÔÓÚÕâ¸ö±»ÖжϵÄÈÎÎñ£¬ÏµÍ³Ìáʾ¡°The replication job is preemptied¡±¡£ËùÒÔÓöµ½ÕâÖÖÇé¿ö£¬Äú²»±Ø×ż±£¬Ö»ÒªµÈ´ýÒ»»á¶ù£¬ÎÊÌâ¾Í×ÔÈ»¶øÈ»µÄÏûʧÁË¡£
×îºó£¬Äã¿ÉÒԲο¼¡°Troubleshooting Active Directory Replication Problems¡±Îĵµ£¬¸ÃÎĵµÀïÁоÙÁ˳£¼ûµÄÎÊÌâºÍÏàÓ¦µÄ½â¾ö·Å°¸£¬¼ÈʵÓÃÓÖ±ã½Ý£¬·Ç³£ÖµµÃ²Î¿¼¡£
http://www.microsoft.com/technet/prodtechnol/windows2000serv/technologies/-
activedirectory/ maintain/opsguide/part1/adogd12.mspx
²Î¿¼ÐÅÏ¢£º
RPCÏà¹ØÖªÊ¶£ºhttp://msdn2.microsoft.com/en-us/library/aa374172.aspx
| ×ÔÓÉ¹ã¸æÇø |
| ¡¡ |