This is a 5.5 to 2003 upgrade. All 5.5 servers and accounts are running in
the AD. I'm working through some issues with old accounts before I can get
connection agreements to install. In the meantime can I get the first
Exchange 2003 server up to serve as the replacement bridgehead? I've been
under the assumption the CA's needed to be in place prior to the first 2003
installation since the installation wizard steps you through that process.

Re: CA reqd for first 2003 server in 5.5 upgrade? by Steven

Steven
Tue Jun 01 15:11:36 CDT 2004

It is highly recommended that you get your user issues corrected before you
deploy an Exchange 2003.
The reason is what are preventable issues before a server is deployed become
difficult to track down and fix issues after a server is deployed.

That being said it is possible to deploy the first server, just you are
potentially "baking in" the issues with the old accounts, and they will
become more difficult to remove after you deploy the server.

--
Steven Halsey
Stevhal@online.microsoft.com
Microsoft Exchange

Please do not send email directly to this alias. This alias is for
newsgroup purposes only.

This posting is provided "AS IS" with no warranties, and confers no rights.



"JimG" <Jim.Geith@nospam.cccs.edu> wrote in message
news:OAbxl$$REHA.1936@TK2MSFTNGP10.phx.gbl...
> This is a 5.5 to 2003 upgrade. All 5.5 servers and accounts are running
> in
> the AD. I'm working through some issues with old accounts before I can
> get
> connection agreements to install. In the meantime can I get the first
> Exchange 2003 server up to serve as the replacement bridgehead? I've been
> under the assumption the CA's needed to be in place prior to the first
> 2003
> installation since the installation wizard steps you through that process.
>
>



Re: CA reqd for first 2003 server in 5.5 upgrade? by JimG

JimG
Tue Jun 01 16:49:28 CDT 2004

The issue I have is from some orphaned or maybe "zombie" accounts. I think
the root cause of the problem is where someone had a server that had either
crashed or was removed from service before they moved or deleted mailboxes.
The problem is in 3 sites out of about 14. I saw KB 812963. But it's a
catch-22 since I can't install my connection agreements with the error, and
I also then can't install my first 2003 server. This KB mentions adding a
key to an Exchange 2003 server. I tried running DS/IS consistency adjuster
for the unknown accounts (options 2 &4) but that didn't help. I tried
recreating a mailbox with the same name, deleted the next day but that
didn't help. Thanks for any ideas.


"Steven Halsey [MSFT]" <Stevhal@Online.Microsoft.com> wrote in message
news:OHK4kSBSEHA.1256@TK2MSFTNGP09.phx.gbl...
> It is highly recommended that you get your user issues corrected before
you
> deploy an Exchange 2003.
> The reason is what are preventable issues before a server is deployed
become
> difficult to track down and fix issues after a server is deployed.
>
> That being said it is possible to deploy the first server, just you are
> potentially "baking in" the issues with the old accounts, and they will
> become more difficult to remove after you deploy the server.
>
> --
> Steven Halsey
> Stevhal@online.microsoft.com
> Microsoft Exchange
>
> Please do not send email directly to this alias. This alias is for
> newsgroup purposes only.
>
> This posting is provided "AS IS" with no warranties, and confers no
rights.
>
>
>
> "JimG" <Jim.Geith@nospam.cccs.edu> wrote in message
> news:OAbxl$$REHA.1936@TK2MSFTNGP10.phx.gbl...
> > This is a 5.5 to 2003 upgrade. All 5.5 servers and accounts are running
> > in
> > the AD. I'm working through some issues with old accounts before I can
> > get
> > connection agreements to install. In the meantime can I get the first
> > Exchange 2003 server up to serve as the replacement bridgehead? I've
been
> > under the assumption the CA's needed to be in place prior to the first
> > 2003
> > installation since the installation wizard steps you through that
process.
> >
> >
>
>



Re: CA reqd for first 2003 server in 5.5 upgrade? by Steven

Steven
Tue Jun 01 17:25:48 CDT 2004

The KB 812963 only affects the way the Exchange Store deals with zombie
users in ACLs. Basically if you were to move forward this is one of the
baked in issues you would hit. So the KB will not help you get through the
ADC Tools setup. Trouble shooting the problem users in the best bet.

So I'm a little confused about these old mailboxes.

Do directory entries still exist for these mailboxes in the original sites?
If so you should be able to delete these directory entries and then wait for
them to replicate to the other 5.5 site directories.
If the directory entries are long since lost but the other exchange sites
still contain directory entries for them? Meaning if you use 5.5
Administrator and connect to the original site the account no longer exists,
but if you look at a replicated site you still see the directory object?
If this is the case what you need to do is create an object with the exact
same Directory Name as the ghost object in the original Site. Wait for it
to replicate into all of the other Exchange sites. Then delete the new
object from the original site, and wait for the delete to replicate out to
the other Exchange sites. This should cause the removal of the ghost
objects from the other Exchange directories and allow you to complete your
ADC tasks.

--
Steven Halsey
Stevhal@online.microsoft.com
Microsoft Exchange

Please do not send email directly to this alias. This alias is for
newsgroup purposes only.

This posting is provided "AS IS" with no warranties, and confers no rights.



"JimG" <Jim.Geith@nospam.cccs.edu> wrote in message
news:%23oeyPJCSEHA.3944@TK2MSFTNGP11.phx.gbl...
> The issue I have is from some orphaned or maybe "zombie" accounts. I
> think
> the root cause of the problem is where someone had a server that had
> either
> crashed or was removed from service before they moved or deleted
> mailboxes.
> The problem is in 3 sites out of about 14. I saw KB 812963. But it's a
> catch-22 since I can't install my connection agreements with the error,
> and
> I also then can't install my first 2003 server. This KB mentions adding a
> key to an Exchange 2003 server. I tried running DS/IS consistency
> adjuster
> for the unknown accounts (options 2 &4) but that didn't help. I tried
> recreating a mailbox with the same name, deleted the next day but that
> didn't help. Thanks for any ideas.
>
>
> "Steven Halsey [MSFT]" <Stevhal@Online.Microsoft.com> wrote in message
> news:OHK4kSBSEHA.1256@TK2MSFTNGP09.phx.gbl...
>> It is highly recommended that you get your user issues corrected before
> you
>> deploy an Exchange 2003.
>> The reason is what are preventable issues before a server is deployed
> become
>> difficult to track down and fix issues after a server is deployed.
>>
>> That being said it is possible to deploy the first server, just you are
>> potentially "baking in" the issues with the old accounts, and they will
>> become more difficult to remove after you deploy the server.
>>
>> --
>> Steven Halsey
>> Stevhal@online.microsoft.com
>> Microsoft Exchange
>>
>> Please do not send email directly to this alias. This alias is for
>> newsgroup purposes only.
>>
>> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>>
>>
>>
>> "JimG" <Jim.Geith@nospam.cccs.edu> wrote in message
>> news:OAbxl$$REHA.1936@TK2MSFTNGP10.phx.gbl...
>> > This is a 5.5 to 2003 upgrade. All 5.5 servers and accounts are
>> > running
>> > in
>> > the AD. I'm working through some issues with old accounts before I can
>> > get
>> > connection agreements to install. In the meantime can I get the first
>> > Exchange 2003 server up to serve as the replacement bridgehead? I've
> been
>> > under the assumption the CA's needed to be in place prior to the first
>> > 2003
>> > installation since the installation wizard steps you through that
> process.
>> >
>> >
>>
>>
>
>



Re: CA reqd for first 2003 server in 5.5 upgrade? by Jim

Jim
Tue Jun 01 21:22:51 CDT 2004

I didn't see these mailboxes in any directory. I first got the errors in
the ADC tools, then traced some of them back to their home server that was
taken out of service years ago. I worked on this last Friday and can't
remember exactly how we were able to determine the original home server.
Maybe with a directory export using Header and dumping the full directory
name. I tried recreating the mailbox, letting it replicate, deleting,
waiting for replication, but no dice. Maybe it didn't work since the
original 5.5 server and associated NT account are long gone?

In the meantime here is a sample that the ADC Mailbox Resource utility
produces. The names have been changed to protect the innocent.

Error: Security identifier (SID) for the associated Windows NT account
(Assoc-NT-Account) for the mailbox
'cn=MMike,cn=Recipients,ou=Louisville,o=MyORG' could not be resolved.