Jump to content

Recommended Posts

Posted (edited)

Seem our domain has gone wrong

 

Got problems with all the shares not working (so no start menus or desktops shortcuts eithier)

time problems (seem to stop start menus and desktop shoructs on some computers)

students account not getting policys & scripts (policys looks like it is working now through)

 

All I can think is that is changed is, is one of our staff, tried to get a mac osx server using active directory

 

Some errors were getting, of you care to take a look (errors are from a from a few different servers, dcs and one citrix server)

 

Event Type: Error

Event Source: Kerberos

Event Category: None

Event ID: 4

Date: 21/05/2010

Time: 20:47:07

User: N/A

Computer: CITRIX01

Description:

The kerberos client received a KRB_AP_ERR_MODIFIED error from the server server-7$. The target name used was cifs/SERVER-7. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (OCKENDON.THURROCK.SCH.UK), and the client realm. Please contact your system administrator.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

 

 

 

 

 

Log Name: System

Source: Microsoft-Windows-Security-Kerberos

Date: 21/05/2010 19:34:48

Event ID: 4

Task Category: None

Level: Error

Keywords: Classic

User: N/A

Computer: SERVER-6.ockendon.thurrock.sch.uk

Description:

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server server-7$. The target name used was cifs/SERVER-7.ockendon.thurrock.sch.uk. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (OCKENDON.THURROCK.SCH.UK) is different from the client domain (OCKENDON.THURROCK.SCH.UK), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

Event Xml:

4

0

2

0

0

0x80000000000000

4961

System

SERVER-6.ockendon.thurrock.sch.uk

server-7$

OCKENDON.THURROCK.SCH.UK

cifs/SERVER-7.ockendon.thurrock.sch.uk

OCKENDON.THURROCK.SCH.UK

 

 

 

 

 

 

Log Name: Application

Source: Microsoft-Windows-Folder Redirection

Date: 21/05/2010 19:34:50

Event ID: 502

Task Category: None

Level: Error

Keywords:

User: OCKENDON\username

Computer: SERVER-6.ockendon.thurrock.sch.uk

Description:

Failed to apply policy and redirect folder "Music" to "%HOMESHARE%\Users\username\My Music".

Redirection options=0x9210.

The following error occurred: "".

Error details: "The specified path is invalid.

".

Event Xml:

502

0

2

0

0

0x8000000000000000

2677

Application

SERVER-6.ockendon.thurrock.sch.uk

Music

%HOMESHARE%\Users\username\My Music

0x9210

The specified path is invalid.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: System

Source: Microsoft-Windows-GroupPolicy

Date: 21/05/2010 20:38:57

Event ID: 1055

Task Category: None

Level: Error

Keywords:

User: SYSTEM

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following:

a) Name Resolution failure on the current domain controller.

b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

Event Xml:

1055

0

2

0

1

0x8000000000000000

3174

System

SERVER-7.ockendon.thurrock.sch.uk

1

1632

0

3244

5

Access is denied.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: System

Source: NETLOGON

Date: 21/05/2010 20:27:31

Event ID: 5774

Task Category: None

Level: Error

Keywords: Classic

User: N/A

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

The dynamic registration of the DNS record '843b0a26-cf81-48cd-8314-2b05e15c0d16._msdcs.ockendon.thurrock.sch.uk. 600 IN CNAME SERVER-7.ockendon.thurrock.sch.uk.' failed on the following DNS server:

DNS server IP address: 10.146.67.151

Returned Response Code (RCODE): 5

Returned Status Code: 9017

For computers and users to locate this domain controller, this record must be registered in DNS.

USER ACTION

Determine what might have caused this failure, resolve the problem, and initiate registration of the DNS records by the domain controller. To determine what might have caused this failure, run DCDiag.exe. To learn more about DCDiag.exe, see Help and Support Center. To initiate registration of the DNS records by this domain controller, run 'nltest.exe /dsregdns' from the command prompt on the domain controller or restart Net Logon service.

Or, you can manually add this record to DNS, but it is not recommended.

ADDITIONAL DATA

Error Value: DNS bad key.

Event Xml:

5774

2

0

0x80000000000000

3171

System

SERVER-7.ockendon.thurrock.sch.uk

843b0a26-cf81-48cd-8314-2b05e15c0d16._msdcs.ockendon.thurrock.sch.uk. 600 IN CNAME SERVER-7.ockendon.thurrock.sch.uk.

%%9017

10.146.67.151

5

9017

0500

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: Directory Service

Source: Microsoft-Windows-ActiveDirectory_DomainService

Date: 21/05/2010 20:36:43

Event ID: 1925

Task Category: Knowledge Consistency Checker

Level: Warning

Keywords: Classic

User: ANONYMOUS LOGON

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

The attempt to establish a replication link for the following writable directory partition failed.

 

Directory partition:

DC=DomainDnsZones,DC=ockendon,DC=thurrock,DC=sch,DC=uk

Source directory service:

CN=NTDS Settings,CN=SERVER-4,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ockendon,DC=thurrock,DC=sch,DC=uk

Source directory service address:

b6a597b5-9076-423c-a04b-976d3f9bd3af._msdcs.ockendon.thurrock.sch.uk

Intersite transport (if any):

 

 

This directory service will be unable to replicate with the source directory service until this problem is corrected.

 

User Action

Verify if the source directory service is accessible or network connectivity is available.

 

Additional Data

Error value:

5 Access is denied.

Event Xml:

1925

0

3

1

0

0x8080000000000000

312

Directory Service

SERVER-7.ockendon.thurrock.sch.uk

DC=DomainDnsZones,DC=ockendon,DC=thurrock,DC=sch,DC=uk

b6a597b5-9076-423c-a04b-976d3f9bd3af._msdcs.ockendon.thurrock.sch.uk

Access is denied.

CN=NTDS Settings,CN=SERVER-4,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ockendon,DC=thurrock,DC=sch,DC=uk

5

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: DNS Server

Source: Microsoft-Windows-DNS-Server-Service

Date: 21/05/2010 20:43:03

Event ID: 4000

Task Category: None

Level: Error

Keywords: Classic

User: N/A

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

The DNS server was unable to open Active Directory. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code.

Event Xml:

4000

0

2

0

0

0x80000000000000

115

DNS Server

SERVER-7.ockendon.thurrock.sch.uk

2D230000

Edited by pritchardavid
Posted

Log Name: DNS Server

Source: Microsoft-Windows-DNS-Server-Service

Date: 21/05/2010 16:24:39

Event ID: 4521

Task Category: None

Level: Warning

Keywords: Classic

User: N/A

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

The DNS server encountered error 13 attempting to load zone ockendon.thurrock.sch.uk from Active Directory. The DNS server will attempt to load this zone again on the next timeout cycle. This can be caused by high Active Directory load and may be a transient condition.

Event Xml:

4521

0

3

0

0

0x80000000000000

88

DNS Server

SERVER-7.ockendon.thurrock.sch.uk

13

ockendon.thurrock.sch.uk

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: DFS Replication

Source: DFSR

Date: 21/05/2010 17:30:19

Event ID: 1202

Task Category: None

Level: Error

Keywords: Classic

User: N/A

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

The DFS Replication service failed to contact domain controller to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues.

 

Additional Information:

Error: 160 (One or more arguments are not correct.)

Event Xml:

1202

2

0

0x80000000000000

49

DFS Replication

SERVER-7.ockendon.thurrock.sch.uk

60

160

One or more arguments are not correct.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: File Replication Service

Source: NtFrs

Date: 21/05/2010 16:12:39

Event ID: 13562

Task Category: None

Level: Warning

Keywords: Classic

User: N/A

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

Following is the summary of warnings and errors encountered by File Replication Service while polling the Domain Controller SERVER-7.ockendon.thurrock.sch.uk for FRS replica set configuration information.

 

Could not bind to a Domain Controller. Will try again at next polling cycle.

 

Event Xml:

13562

3

0

0x80000000000000

26

File Replication Service

SERVER-7.ockendon.thurrock.sch.uk

SERVER-7.ockendon.thurrock.sch.uk

Could not bind to a Domain Controller. Will try again at next polling cycle.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Log Name: System

Source: Microsoft-Windows-DfsSvc

Date: 21/05/2010 16:09:07

Event ID: 14534

Task Category: None

Level: Warning

Keywords: Classic

User: N/A

Computer: SERVER-7.ockendon.thurrock.sch.uk

Description:

DFS Root Year9 failed during initialization. The root will not be available.

Event Xml:

14534

0

3

0

0

0x80000000000000

3018

System

SERVER-7.ockendon.thurrock.sch.uk

Year9

4B050000

 

 

 

 

 

 

 

 

 

 

 

 

Event Type: Warning

Event Source: MSDTC

Event Category: MSDTC Proxy

Event ID: 53258

Date: 21/05/2010

Time: 16:08:19

User: N/A

Computer: SERVER-4

Description:

MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: d:\nt\com\complus\dtc\dtc\adme\uiname.cpp:9351, Pid: 1252

No Callstack,

CmdLine: C:\WINDOWS\system32\msdtc.exe

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

Data:

0000: 05 00 07 80 ...?

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Event Type: Warning

Event Source: MSDTC

Event Category: SVC

Event ID: 53258

Date: 21/05/2010

Time: 16:08:19

User: N/A

Computer: SERVER-4

Description:

MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: %1

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Event Type: Error

Event Source: KDC

Event Category: None

Event ID: 26

Date: 21/05/2010

Time: 20:57:37

User: N/A

Computer: SERVER-4

Description:

While processing an AS request for target service krbtgt, the account SERVER-7$ did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 2). The requested etypes were 18. The accounts available etypes were 23 -133 -128 3 -140.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

 

 

 

 

 

 

 

 

 

 

 

Event Type: Warning

Event Source: NETLOGON

Event Category: None

Event ID: 5781

Date: 21/05/2010

Time: 16:19:41

User: N/A

Computer: SERVER-4

Description:

Dynamic registration or deletion of one or more DNS records associated with DNS domain 'DomainDnsZones.ockendon.thurrock.sch.uk.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition).

Possible causes of failure include:

- TCP/IP properties of the network connections of this computer contain wrong IP address(es) of the preferred and alternate DNS servers

- Specified preferred and alternate DNS servers are not running

- DNS server(s) primary for the records to be registered is not running

- Preferred or alternate DNS servers are configured with wrong root hints

- Parent DNS zone contains incorrect delegation to the child zone authoritative for the DNS records that failed registration

USER ACTION

Fix possible misconfiguration(s) specified above and initiate registration or deletion of the DNS records by running 'nltest.exe /dsregdns' from the command prompt or by restarting Net Logon service. Nltest.exe is available in the Microsoft Windows Server Resource Kit CD.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

Data:

0000: b4 05 00 00 ´...

 

 

 

 

 

 

 

 

 

 

 

 

 

Event Type: Warning

Event Source: LSASRV

Event Category: SPNEGO (Negotiator)

Event ID: 40960

Date: 21/05/2010

Time: 16:08:35

User: N/A

Computer: SERVER-4

Description:

The Security System detected an authentication error for the server ldap/SERVER-4.ockendon.thurrock.sch.uk. The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request.

(0xc000005e)".

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

Data:

0000: 5e 00 00 c0 ^..À

 

 

 

 

 

 

 

 

 

 

 

 

 

Event Type: Error

Event Source: W32Time

Event Category: None

Event ID: 29

Date: 21/05/2010

Time: 16:08:32

User: N/A

Computer: SERVER-4

Description:

The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

 

 

 

 

 

 

 

 

 

 

 

 

 

Event Type: Error

Event Source: NETLOGON

Event Category: None

Event ID: 5719

Date: 21/05/2010

Time: 15:50:34

User: N/A

Computer: SERVER-4

Description:

This computer was not able to set up a secure session with a domain controller in domain OCKENDON due to the following:

There are currently no logon servers available to service the logon request.

This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator.

ADDITIONAL INFO

If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.

For more information, see Help and Support Center at Events and Errors Message Center: Basic Search.

Data:

0000: 5e 00 00 c0 ^..À

Posted

Is DNS working on the DNS servers? (DCs probably)

 

Is the server/workstation service running on the servers?

 

Can you access the sysvol share on each domain controller from the other domain controllers?

 

Do you have the FSMO roles on a single server or spread out?

 

EDIT: Firewalls enabled on the servers?

Posted (edited)

How extually can you tell if dns is working? believe they are, not sure

 

All firewalls are turned off on each server

 

fsmo roles are on one server (server-6)

 

 

will check the other two questions out, just need to logon and check through citrix

 

 

edit: ok cant check, citrix will not let me in, I can get onto the normal ctrl alt delete logon box, its starts complaining about the time different in the server, so will not let me logon. I dont know what the local admin password of that server is, we didnt set that server up

Edited by pritchardavid
Posted (edited)

go to CMD and then type NSLOOKUP. Do nslookup on a random batch of machines should be able to tell you if your DNS is working properly. It will give you your server name and IP address.

 

If it does that, then your DNS is working.

Edited by featured_spectre
Posted
Do you have the local credentials for the time-server server? Would running dcdiag with the /e switch help with diagnostics?
Posted
i have never used citrix so not sure but looks like you have some serious problems their can you even open AD can clients login OK ? what i would check for is to make sure that my group policy is all correct you should really only have the minimal applied e.g password policy etc but i would also make sure that their is no firewalls turn on you shouldn't have them on any way all servers are static ip address which I'm guessing they are also you want to make sure that in your root dns servers that you have the correct srv and pointer records and also that the ldap.TCP is correct the zone transfers are correct your scavaging scale are setup properly and i would also check the last time the system replicated to and from other servers also think back to the last thing that happen before all this went wrong try and trace your steps did you applied any service packs or anything like that or did any one change any passwords that used to authenticate anything also ask your team
Posted
Do you have the local credentials for the time-server server? Would running dcdiag with the /e switch help with diagnostics?

 

Not acutally sure what server is the time server, we have had the time wrong for the past two years I believe, never had this sort of problem before

 

All I know is hat server 6 is the master server for all the fmos roles

 

Well were getting our support company in for tomorrow to sort out another problem, looks like they will have to fix this major problem first (haha)

Posted

i would also make sure that their is no firewalls turn on you shouldn't have them on

 

 

Yep checked all firewalls before I left work, all off

 

any way all servers are static ip address which I'm guessing they are

 

 

All are static and checked

 

also you want to make sure that in your root dns servers that you have the correct srv and pointer records and also that the ldap.

 

Think this is correct, what the difference between srv and pointer records (hard to think what it is, has im not looking at the server and dont know much about dns)

 

TCP is correct the zone transfers are correct your scavaging scale are setup properly

 

No idea, how do you check this?

 

and i would also check the last time the system replicated to and from other servers

 

No idea last time this was done

 

also think back to the last thing that happen before all this went wrong try and trace your steps did you applied any service packs or anything like that or did any one change any passwords that used to authenticate anything also ask your team

 

No passwords have been changed. All I can thiunk of its someone trying to setup a mac server to the active directory, thats about time it all happended. Later when this happended, i did find that the server 7 ip address in dns what now the mac server ip address, so changed this back, has I know he was trying to connect it through server 7

Posted

When you say someone tried to get an OSX server to work via AD, what method of doing this did they try? Did they update the AD Schema or did they go with the safer route of simply joining the box to the domain?

 

Is the OD server still connected and on?

Posted

not sure extually was done on the mac server, but got him to undo all the things he done to it, after that I dont him i'll sort the server out for him, just in case he is doing something wrong (believe he used to work in ict, now one of our music teachers, it actually his server he brought with his department money) Also turned the server off until this problem is sorted, has this may be the problem.

 

dont think any ad schema was done, I know ours is at 2008r2 level

 

does the mac server have its on ad schema then?

Posted

The Mac schema implementation that localzuk is talking about is probably the one where to get macs to authenticate directly with AD and get additional Mac specific configurations off it the AD LDAP database schema is modified to include some of the values that Macs expect of an Open Directory server as housed on OSX. This lets you use a bunch of the central managment functionality that you would otherwise need a Mac Server to implement.

 

As the AD database is kind of the core of the network any changes that go wrong can trash everything, the LDAP spec that AD uses though does fully support this kind of modification and you can even modify it youself four your own ends. The general wisdom though is don't touch it unless you know what you are doing, have a backup and really need to do it as if it goes wrong it makes a mess.

 

 

Looking at the errors above it looks like kerberos has lost sync between servers I'd restart all of the servers and look for failures in the event logs on each of them. If it has a DCpromo in a failed state it could be pointing some clients to the wrong places for kerberos.

Posted

I have to agree with Synack, the AD database is essentially the core and it looks as though it's corrupted.

 

Realistically I think you're looking at a non-authoritative restore of Active Directory on your PDC to get your network back up and running properly. If you still want to introduce the Mac Server, I suggest some extensive testing is required before adding it to a live network.

Posted

ok all sorted by our support company today

 

He took the dcs of the domain. expect one and the readded them

 

I was to do with the reliaction of the servers, it was all muddled up with with sever relicated what

 

 

Also while he was there got him to back dhcp, adter I updated that server to 2008r2 and got him to restore the dhcp service on there. So were totally running a 2008r2 active directory now. Just need to update our two citrix servers and our exchange server, then all servers on the cirrculun our 2008r2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...