I have a friend who asked about this. They have some Servers where the Server Object was created prior to joining the Server to the Domain. Once it was joined it was promoted to a DC for its respective site. Below is what they have found which "may" be causing an replication issue that they are trying to nail down.
Edit: Added - YES this was found when running DCDIAG. I am finding several links on it now. Looking for best way to fix multiple DCs...
What is the effect if we don’t fix this:
Starting test: MachineAccount
Warning: Attribute userAccountControl of ServerA is:
0x82020 = ( PASSWD_NOTREQD | SERVER_TRUST_ACCOUNT | TRUSTED_FOR_DELEGATION )
Typical setting for a DC is
0x82000 = ( SERVER_TRUST_ACCOUNT | TRUSTED_FOR_DELEGATION )
This may be affecting replication?
The thought is that creating the Computer Object prior to joining the computer to the domain is creating issues once the server has been promoted to a DC...