|
Article ID: 950805 - View products that this article applies to. INTRODUCTIONThis article describes how to recover a deleted computer object that supports a Network Name resource in a Windows Server 2008 or Windows Server 2008 R2 failover cluster. MORE INFORMATIONBy default, the new security model in Windows Server 2008 or Windows Server 2008 R2 failover clustering includes Kerberos authentication. To create this security model, every Client Access Point (CAP) that is created in a Windows Server 2008 or Windows Server 2008 R2 failover cluster contains a Network Name resource. The Network Name resource has a corresponding Computer Account that is created in the Active Directory directory service when the resource is online for the first time. By default, the Computer Account is created in the Computers container. However, the Computer Account can be relocated to another organizational unit (OU). The Computer Account can also be pre-staged in an OU before the CAP is created. If these Computer Accounts are deleted from Active Directory, availability of the Network Name resource will be reduced. The computer accounts that are created in Active Directory represent the Network Name resources in a failover cluster. These accounts have the following distinct types:
Event ID: 1207
Event Level: Error Event Source: FailoverClustering Event ID: 1207 Description: Cluster network name resource ResourceName cannot be brought online. The computer object associated with the resource could not be updated in domain DomainName for the following reason: The text for the associated error code is: There is no such object on the server. The cluster identity CNO$Name may lack permissions required to update the object. Please work with your domain administrator to ensure the cluster identity can update computer objects in the domain. and the following messages are logged in the cluster log: WARN [RES] Network Name <FSCAP01>: Trying to remove credentials for LocalSystem returned status C0000225, STATUS_NOT_FOUND is a non-critical failure for a remove operation INFO [RES] Network Name <FSCAP01>: Initiating the Network Name operation : 'Verifying computer object associated with network name resource FSCAP01' INFO [RES] Network Name <FSCAP01>: Trying to find computer account FSCAP01 object GUID(d66e09dd8857e84da1f3a26fb1903e38) on any available domain controller. WARN [RES] Network Name <FSCAP01>: Search for existing computer account failed. status 80072030 WARN [RES] Network Name <FSCAP01>: Search for existing computer account failed. status 80072030 INFO [RES] Network Name <FSCAP01>: Trying to find object d66e09dd8857e84da1f3a26fb1903e38 on a PDC. WARN [RES] Network Name <FSCAP01>: Search for existing computer account failed. status 80072030 INFO [RES] Network Name <FSCAP01>: Unable to find object d66e09dd8857e84da1f3a26fb1903e38 on a PDC. INFO [RES] Network Name <FSCAP01>: GetComputerObjectViaGUIDEx() failed, Status 80072030. WARN [RES] Network Name <FSCAP01>: Trying to remove credentials for LocalSystem returned status C0000225, STATUS_NOT_FOUND is a non-critical failure for a remove operation WARN [RHS] Resource FSCAP01 has indicated that it cannot come online on this node. WARN [RCM] HandleMonitorReply: ONLINERESOURCE for 'FSCAP01', gen(8) result 5015. Note: status 80072030 = There is no such object on the server However, problems will occur even before the Network Name resource is cycled offline and online. For example, a user or a highly available application may be unable to access resources when a security token that represents the cluster computer object in Active Directory cannot be obtained. To recover from the deletion of a Computer Object that is associated with a cluster Network Name resource is different for a CNO than recovering from the deletion of a Computer Object for a VCO. To recover a deleted computer object that corresponds to the CNO, follow these steps:
To recover a deleted computer object that corresponds to a VCO, follow these steps:
REFERENCES947049 For more information, visit the following Microsoft Web sites:
(http://support.microsoft.com/kb/947049/
)
Description of the failover cluster security model in Windows Server 2008
Recovering a Deleted Cluster Name Object (CNO) in a Windows Server 2008 Failover Cluster - http://blogs.technet.com/b/askcore/archive/2009/04/27/recovering-a-deleted-cluster-name-object-cno-in-a-windows-server-2008-failover-cluster.aspx
(http://blogs.technet.com/b/askcore/archive/2009/04/27/recovering-a-deleted-cluster-name-object-cno-in-a-windows-server-2008-failover-cluster.aspx)
Event ID 1207 — Active Directory permissions for cluster accounts http://technet2.microsoft.com/windowsserver2008/en/library/4dbabb5d-24f7-445f-b57e-1bb3b4a6d1831033.mspx
(http://technet2.microsoft.com/windowsserver2008/en/library/4dbabb5d-24f7-445f-b57e-1bb3b4a6d1831033.mspx)
Active Directory backup and restore http://technet.microsoft.com/en-us/library/bb727048.aspx
(http://technet.microsoft.com/en-us/library/bb727048.aspx)
PropertiesArticle ID: 950805 - Last Review: 10 September 2011 - Revision: 5.0 APPLIES TO
|
Contact us for more help |
