{"id":1400,"date":"2011-08-05T16:37:35","date_gmt":"2011-08-05T19:37:35","guid":{"rendered":"http:\/\/www.radians.com.ar\/blog\/?p=1400"},"modified":"2011-08-05T16:41:55","modified_gmt":"2011-08-05T19:41:55","slug":"ad-troubleshooting-restaurando-la-db-ntds-dit-de-active-directory-event-id-454-1003-1168-howto","status":"publish","type":"post","link":"https:\/\/www.radians.com.ar\/blog\/?p=1400","title":{"rendered":"AD Troubleshooting: Restaurando la DB (ntds.dit) de Active Directory&hellip; Event Id: 454, 1003, 1168 {HowTo}"},"content":{"rendered":"<p align=\"justify\"><font size=\"2\">Hola, hoy vamos a ver como recuperar un dominio cuando nuestro Active Directory esta roto y no inicia correctamente mostr\u00e1ndonos el siguiente error:<\/font><\/p>\n<blockquote>\n<p align=\"justify\"><font color=\"#ff0000\" size=\"2\" face=\"OCR A Extended\">Security Accounts Manager initialization failed because of the following error: Directory Service cannot start. Error Status: 0xc00002e1. Please click OK to shutdown this system and reboot into Directory Services Restore Mode, check the event log for more detailed information.<\/font><\/p>\n<\/blockquote>\n<p align=\"justify\"><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/e01.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-right-width: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px; padding-top: 0px\" title=\"e01\" border=\"0\" alt=\"e01\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/e01_thumb.png\" width=\"540\" height=\"200\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Este inconveniente puede producirse si se marcan objetos de Active Directory como autoritativo con la herramienta Ntdsutil y, luego restauramos Active Directory desde un backup. Como toda base de datos podr\u00eda corromperse por varias causas, pero en nuestro caso ocurri\u00f3 despu\u00e9s que el servidor se reinicio inesperadamente 2 veces.<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/01.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"01\" border=\"0\" alt=\"01\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/01_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Para resolver este inconveniente vamos a tener que iniciar nuestro equipo en modo <font color=\"#ff0000\" face=\"OCR A Extended\">Directory Services Restore Mode<\/font>, y luego vamos a realizar varias comprobaciones sobre la base de datos de Active Directory.<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/02.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"02\" border=\"0\" alt=\"02\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/02_thumb.png\" width=\"544\" height=\"342\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Al iniciar en este modo podremos logearnos y ver los siguientes eventos: <font color=\"#ff0000\" face=\"OCR A Extended\">454 NTD ISAM<\/font>,<\/font><\/p>\n<p align=\"justify\"><font size=\"2\"><font color=\"#ff0000\" face=\"OCR A Extended\">1003 NTDS General<\/font> y <font color=\"#ff0000\" face=\"OCR A Extended\">1168 NTDS General<\/font>:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/Evento454.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"Evento454\" border=\"0\" alt=\"Evento454\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/Evento454_thumb.png\" width=\"540\" height=\"597\" \/><\/a><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/Evento1003.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"Evento1003\" border=\"0\" alt=\"Evento1003\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/Evento1003_thumb.png\" width=\"540\" height=\"597\" \/><\/a><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/Evento1168.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"Evento1168\" border=\"0\" alt=\"Evento1168\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/Evento1168_thumb.png\" width=\"540\" height=\"597\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Entonces lo que hacemos una vez que nos logeamos en este modo, abrimos una consola de comando y ejecutamos el comando <font color=\"#ff0000\" face=\"OCR A Extended\">ntdsutil file info<\/font>, esto nos mostrara la ubicaci\u00f3n de nuestra DB de AD. Si queremos podemos verificar en la carpeta y veremos los archivos. Si la ubicaci\u00f3n esta mal debemos esto no fuera as\u00ed, debemos configurar la ubicaci\u00f3n correcta mediante el comando <font color=\"#ff0000\" face=\"OCR A Extended\">ntdsutil file set path Ubicacion<\/font><\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/03.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"03\" border=\"0\" alt=\"03\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/03_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">En nuestro caso coinciden. Tambi\u00e9n lo podemos verificar en la registry por medio de <font color=\"#ff0000\" face=\"OCR A Extended\">RegEdit<\/font>, en el siguiente screenshoot pueden ver los campos a verificar y la ubicaci\u00f3n dentro del registro:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/04.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"04\" border=\"0\" alt=\"04\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/04_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Ahora lo que vamos a hacer es verificar la integridad de nuestra base NTDIS.DIT, con el comando <font color=\"#ff0000\" face=\"OCR A Extended\">NTDSUTIL FILES INTEGRITY<\/font>.<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/05.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"05\" border=\"0\" alt=\"05\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/05_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Si intentamos hacer un recovery con el <font color=\"#ff0000\" face=\"OCR A Extended\">ntdsutil<\/font>, veremos que nos da un error en la DB: <font color=\"#ff0000\" face=\"OCR A Extended\">Jet_errLogFileCorrupt, Log file is corrupt<\/font>.<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/06.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"06\" border=\"0\" alt=\"06\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/06_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Volvemos a verificar la integridad:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/07.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"07\" border=\"0\" alt=\"07\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/07_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Vamos a realizar una reparaci\u00f3n de la misma por medio del comando: <font color=\"#ff0000\" face=\"OCR A Extended\">esentutl \/p &quot;C:\\WINDOWS\\NTDS\\ntds.dit&quot;<\/font><\/font><\/p>\n<p align=\"justify\"><font size=\"2\">El sistema nos mostrara un mensaje de Warning:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/08.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"08\" border=\"0\" alt=\"08\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/08_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Comienza el proceso de reparaci\u00f3n:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/10.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"10\" border=\"0\" alt=\"10\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/10_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Una vez que termino el proceso debemos eliminar los dos archivos de logs del directorio.<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/11.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"11\" border=\"0\" alt=\"11\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/11_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Verificamos nuevamente la integridad de las bases, y podemos ver que termina correctamente.<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/14.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"14\" border=\"0\" alt=\"14\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/14_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Como vemos en la pantalla se nos recomienda verificar sem\u00e1nticamente la base de datos, para asegurarnos de la consistencia de ella:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/15.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"15\" border=\"0\" alt=\"15\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/15_thumb.png\" width=\"540\" height=\"322\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Comienza el procedimiento de verificaci\u00f3n y termina correctamente:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/16.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"16\" border=\"0\" alt=\"16\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/16_thumb.png\" width=\"540\" height=\"206\" \/><\/a><\/p>\n<p align=\"justify\"><font size=\"2\">Reiniciamos nuestro equipo:<\/font><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/17.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"17\" border=\"0\" alt=\"17\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/17_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p align=\"justify\">Mientras reinicia el equipo, podemos ver que no nos da mas el error y que el equipo reinicia normalmente. Nos podemos logear al equipo y si abrimos la consola de <font color=\"#ff0000\" face=\"OCR A Extended\">Active Directory Users and Computers<\/font> y vemos todos los usuarios y el servidor inicio correctamente.<\/p>\n<p align=\"justify\">Espero que les sea de utilidad este troubleshooting. Saludos, Roberto Di Lello.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/18.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"18\" border=\"0\" alt=\"18\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/18_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/19.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"19\" border=\"0\" alt=\"19\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/19_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/20.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"20\" border=\"0\" alt=\"20\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/20_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/22.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; border-bottom: 0px; border-left: 0px; margin: 5px; padding-left: 0px; padding-right: 0px; display: inline; border-top: 0px; border-right: 0px; padding-top: 0px\" title=\"22\" border=\"0\" alt=\"22\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/08cf221a6e81_97FA\/22_thumb.png\" width=\"544\" height=\"409\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hola, hoy vamos a ver como recuperar un dominio cuando nuestro Active Directory esta roto&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4291,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12,11],"tags":[],"class_list":["post-1400","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-2003-r2","category-2008-r2"],"_links":{"self":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1400"}],"version-history":[{"count":1,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1400\/revisions"}],"predecessor-version":[{"id":1401,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/1400\/revisions\/1401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/media\/4291"}],"wp:attachment":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}