Unlock a Domain
You can be locked out of a domain if you forget the administrator password, change authentication methods without adding an administrative account, or experience a problem with the external authentication system.
You can unlock the domain using the rxsconfig command line utility's recovery option.
To unlock a domain using rxsconfig
-
Log on the server on which the Domain Controller is installed as an administrator (Windows) or root (Linux).
-
Open a command window.
note
On Windows systems, you need to open the command window as an administrator. (In the Start menu, under Accessories, right-click Command Prompt and select Run As Administrator).
-
Enter the following command:
rxsconfig recover
-
Open the Administrative Console and log on to the domain with the following user name and password:
user name:
recovery
password:
recovery
note
Running the recover command allows access to the Administrative Console only once. After you log out, these login values for username and password won't work again. To log in again with these values you need to repeat steps 1 through 3.
-
Set Authentication system to the authentication system you want to use for the domain.
-
Click the plus sign () to add a new administrative user account.
-
Select the check box under Administrator for the new account.
-
Click Test Authentication then enter the name and password for this account and click Test to make sure that the account is valid.
caution
Don't close the Administrative Console without first redefining and testing an administrative account. Without a valid administrative account, you won't be able to log back into the Administrative Console and you'll need to repeat this procedure from the beginning.
More information