pritchardavid Posted May 21, 2010 Posted May 21, 2010 (edited) Seem our domain has gone wrong Got problems with all the shares not working (so no start menus or desktops shortcuts eithier) time problems (seem to stop start menus and desktop shoructs on some computers) students account not getting policys & scripts (policys looks like it is working now through) All I can think is that is changed is, is one of our staff, tried to get a mac osx server using active directory Some errors were getting, of you care to take a look (errors are from a from a few different servers, dcs and one citrix server) Event Type: Error Event Source: Kerberos Event Category: None Event ID: 4 Date: 21/05/2010 Time: 20:47:07 User: N/A Computer: CITRIX01 Description: The kerberos client received a KRB_AP_ERR_MODIFIED error from the server server-7$. The target name used was cifs/SERVER-7. This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly, this is due to identically named machine accounts in the target realm (OCKENDON.THURROCK.SCH.UK), and the client realm. Please contact your system administrator. For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Log Name: System Source: Microsoft-Windows-Security-Kerberos Date: 21/05/2010 19:34:48 Event ID: 4 Task Category: None Level: Error Keywords: Classic User: N/A Computer: SERVER-6.ockendon.thurrock.sch.uk Description: The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server server-7$. The target name used was cifs/SERVER-7.ockendon.thurrock.sch.uk. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Please ensure that the target SPN is registered on, and only registered on, the account used by the server. This error can also happen when the target service is using a different password for the target service account than what the Kerberos Key Distribution Center (KDC) has for the target service account. Please ensure that the service on the server and the KDC are both updated to use the current password. If the server name is not fully qualified, and the target domain (OCKENDON.THURROCK.SCH.UK) is different from the client domain (OCKENDON.THURROCK.SCH.UK), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server. Event Xml: 4 0 2 0 0 0x80000000000000 4961 System SERVER-6.ockendon.thurrock.sch.uk server-7$ OCKENDON.THURROCK.SCH.UK cifs/SERVER-7.ockendon.thurrock.sch.uk OCKENDON.THURROCK.SCH.UK Log Name: Application Source: Microsoft-Windows-Folder Redirection Date: 21/05/2010 19:34:50 Event ID: 502 Task Category: None Level: Error Keywords: User: OCKENDON\username Computer: SERVER-6.ockendon.thurrock.sch.uk Description: Failed to apply policy and redirect folder "Music" to "%HOMESHARE%\Users\username\My Music". Redirection options=0x9210. The following error occurred: "". Error details: "The specified path is invalid. ". Event Xml: 502 0 2 0 0 0x8000000000000000 2677 Application SERVER-6.ockendon.thurrock.sch.uk Music %HOMESHARE%\Users\username\My Music 0x9210 The specified path is invalid. Log Name: System Source: Microsoft-Windows-GroupPolicy Date: 21/05/2010 20:38:57 Event ID: 1055 Task Category: None Level: Error Keywords: User: SYSTEM Computer: SERVER-7.ockendon.thurrock.sch.uk Description: The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: a) Name Resolution failure on the current domain controller. b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller). Event Xml: 1055 0 2 0 1 0x8000000000000000 3174 System SERVER-7.ockendon.thurrock.sch.uk 1 1632 0 3244 5 Access is denied. Log Name: System Source: NETLOGON Date: 21/05/2010 20:27:31 Event ID: 5774 Task Category: None Level: Error Keywords: Classic User: N/A Computer: SERVER-7.ockendon.thurrock.sch.uk Description: The dynamic registration of the DNS record '843b0a26-cf81-48cd-8314-2b05e15c0d16._msdcs.ockendon.thurrock.sch.uk. 600 IN CNAME SERVER-7.ockendon.thurrock.sch.uk.' failed on the following DNS server: DNS server IP address: 10.146.67.151 Returned Response Code (RCODE): 5 Returned Status Code: 9017 For computers and users to locate this domain controller, this record must be registered in DNS. USER ACTION Determine what might have caused this failure, resolve the problem, and initiate registration of the DNS records by the domain controller. To determine what might have caused this failure, run DCDiag.exe. To learn more about DCDiag.exe, see Help and Support Center. To initiate registration of the DNS records by this domain controller, run 'nltest.exe /dsregdns' from the command prompt on the domain controller or restart Net Logon service. Or, you can manually add this record to DNS, but it is not recommended. ADDITIONAL DATA Error Value: DNS bad key. Event Xml: 5774 2 0 0x80000000000000 3171 System SERVER-7.ockendon.thurrock.sch.uk 843b0a26-cf81-48cd-8314-2b05e15c0d16._msdcs.ockendon.thurrock.sch.uk. 600 IN CNAME SERVER-7.ockendon.thurrock.sch.uk. %%9017 10.146.67.151 5 9017 0500 Log Name: Directory Service Source: Microsoft-Windows-ActiveDirectory_DomainService Date: 21/05/2010 20:36:43 Event ID: 1925 Task Category: Knowledge Consistency Checker Level: Warning Keywords: Classic User: ANONYMOUS LOGON Computer: SERVER-7.ockendon.thurrock.sch.uk Description: The attempt to establish a replication link for the following writable directory partition failed. Directory partition: DC=DomainDnsZones,DC=ockendon,DC=thurrock,DC=sch,DC=uk Source directory service: CN=NTDS Settings,CN=SERVER-4,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ockendon,DC=thurrock,DC=sch,DC=uk Source directory service address: b6a597b5-9076-423c-a04b-976d3f9bd3af._msdcs.ockendon.thurrock.sch.uk Intersite transport (if any): This directory service will be unable to replicate with the source directory service until this problem is corrected. User Action Verify if the source directory service is accessible or network connectivity is available. Additional Data Error value: 5 Access is denied. Event Xml: 1925 0 3 1 0 0x8080000000000000 312 Directory Service SERVER-7.ockendon.thurrock.sch.uk DC=DomainDnsZones,DC=ockendon,DC=thurrock,DC=sch,DC=uk b6a597b5-9076-423c-a04b-976d3f9bd3af._msdcs.ockendon.thurrock.sch.uk Access is denied. CN=NTDS Settings,CN=SERVER-4,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=ockendon,DC=thurrock,DC=sch,DC=uk 5 Log Name: DNS Server Source: Microsoft-Windows-DNS-Server-Service Date: 21/05/2010 20:43:03 Event ID: 4000 Task Category: None Level: Error Keywords: Classic User: N/A Computer: SERVER-7.ockendon.thurrock.sch.uk Description: The DNS server was unable to open Active Directory. This DNS server is configured to obtain and use information from the directory for this zone and is unable to load the zone without it. Check that the Active Directory is functioning properly and reload the zone. The event data is the error code. Event Xml: 4000 0 2 0 0 0x80000000000000 115 DNS Server SERVER-7.ockendon.thurrock.sch.uk 2D230000 Edited May 21, 2010 by pritchardavid
pritchardavid Posted May 21, 2010 Author Posted May 21, 2010 Log Name: DNS Server Source: Microsoft-Windows-DNS-Server-Service Date: 21/05/2010 16:24:39 Event ID: 4521 Task Category: None Level: Warning Keywords: Classic User: N/A Computer: SERVER-7.ockendon.thurrock.sch.uk Description: The DNS server encountered error 13 attempting to load zone ockendon.thurrock.sch.uk from Active Directory. The DNS server will attempt to load this zone again on the next timeout cycle. This can be caused by high Active Directory load and may be a transient condition. Event Xml: 4521 0 3 0 0 0x80000000000000 88 DNS Server SERVER-7.ockendon.thurrock.sch.uk 13 ockendon.thurrock.sch.uk Log Name: DFS Replication Source: DFSR Date: 21/05/2010 17:30:19 Event ID: 1202 Task Category: None Level: Error Keywords: Classic User: N/A Computer: SERVER-7.ockendon.thurrock.sch.uk Description: The DFS Replication service failed to contact domain controller to access configuration information. Replication is stopped. The service will try again during the next configuration polling cycle, which will occur in 60 minutes. This event can be caused by TCP/IP connectivity, firewall, Active Directory Domain Services, or DNS issues. Additional Information: Error: 160 (One or more arguments are not correct.) Event Xml: 1202 2 0 0x80000000000000 49 DFS Replication SERVER-7.ockendon.thurrock.sch.uk 60 160 One or more arguments are not correct. Log Name: File Replication Service Source: NtFrs Date: 21/05/2010 16:12:39 Event ID: 13562 Task Category: None Level: Warning Keywords: Classic User: N/A Computer: SERVER-7.ockendon.thurrock.sch.uk Description: Following is the summary of warnings and errors encountered by File Replication Service while polling the Domain Controller SERVER-7.ockendon.thurrock.sch.uk for FRS replica set configuration information. Could not bind to a Domain Controller. Will try again at next polling cycle. Event Xml: 13562 3 0 0x80000000000000 26 File Replication Service SERVER-7.ockendon.thurrock.sch.uk SERVER-7.ockendon.thurrock.sch.uk Could not bind to a Domain Controller. Will try again at next polling cycle. Log Name: System Source: Microsoft-Windows-DfsSvc Date: 21/05/2010 16:09:07 Event ID: 14534 Task Category: None Level: Warning Keywords: Classic User: N/A Computer: SERVER-7.ockendon.thurrock.sch.uk Description: DFS Root Year9 failed during initialization. The root will not be available. Event Xml: 14534 0 3 0 0 0x80000000000000 3018 System SERVER-7.ockendon.thurrock.sch.uk Year9 4B050000 Event Type: Warning Event Source: MSDTC Event Category: MSDTC Proxy Event ID: 53258 Date: 21/05/2010 Time: 16:08:19 User: N/A Computer: SERVER-4 Description: MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: d:\nt\com\complus\dtc\dtc\adme\uiname.cpp:9351, Pid: 1252 No Callstack, CmdLine: C:\WINDOWS\system32\msdtc.exe For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Data: 0000: 05 00 07 80 ...? Event Type: Warning Event Source: MSDTC Event Category: SVC Event ID: 53258 Date: 21/05/2010 Time: 16:08:19 User: N/A Computer: SERVER-4 Description: MS DTC could not correctly process a DC Promotion/Demotion event. MS DTC will continue to function and will use the existing security settings. Error Specifics: %1 For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Event Type: Error Event Source: KDC Event Category: None Event ID: 26 Date: 21/05/2010 Time: 20:57:37 User: N/A Computer: SERVER-4 Description: While processing an AS request for target service krbtgt, the account SERVER-7$ did not have a suitable key for generating a Kerberos ticket (the missing key has an ID of 2). The requested etypes were 18. The accounts available etypes were 23 -133 -128 3 -140. For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Event Type: Warning Event Source: NETLOGON Event Category: None Event ID: 5781 Date: 21/05/2010 Time: 16:19:41 User: N/A Computer: SERVER-4 Description: Dynamic registration or deletion of one or more DNS records associated with DNS domain 'DomainDnsZones.ockendon.thurrock.sch.uk.' failed. These records are used by other computers to locate this server as a domain controller (if the specified domain is an Active Directory domain) or as an LDAP server (if the specified domain is an application partition). Possible causes of failure include: - TCP/IP properties of the network connections of this computer contain wrong IP address(es) of the preferred and alternate DNS servers - Specified preferred and alternate DNS servers are not running - DNS server(s) primary for the records to be registered is not running - Preferred or alternate DNS servers are configured with wrong root hints - Parent DNS zone contains incorrect delegation to the child zone authoritative for the DNS records that failed registration USER ACTION Fix possible misconfiguration(s) specified above and initiate registration or deletion of the DNS records by running 'nltest.exe /dsregdns' from the command prompt or by restarting Net Logon service. Nltest.exe is available in the Microsoft Windows Server Resource Kit CD. For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Data: 0000: b4 05 00 00 ´... Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40960 Date: 21/05/2010 Time: 16:08:35 User: N/A Computer: SERVER-4 Description: The Security System detected an authentication error for the server ldap/SERVER-4.ockendon.thurrock.sch.uk. The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request. (0xc000005e)". For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Data: 0000: 5e 00 00 c0 ^..À Event Type: Error Event Source: W32Time Event Category: None Event ID: 29 Date: 21/05/2010 Time: 16:08:32 User: N/A Computer: SERVER-4 Description: The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Event Type: Error Event Source: NETLOGON Event Category: None Event ID: 5719 Date: 21/05/2010 Time: 15:50:34 User: N/A Computer: SERVER-4 Description: This computer was not able to set up a secure session with a domain controller in domain OCKENDON due to the following: There are currently no logon servers available to service the logon request. This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator. ADDITIONAL INFO If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain. For more information, see Help and Support Center at Events and Errors Message Center: Basic Search. Data: 0000: 5e 00 00 c0 ^..À
kmount Posted May 21, 2010 Posted May 21, 2010 Is DNS working on the DNS servers? (DCs probably) Is the server/workstation service running on the servers? Can you access the sysvol share on each domain controller from the other domain controllers? Do you have the FSMO roles on a single server or spread out? EDIT: Firewalls enabled on the servers?
pritchardavid Posted May 21, 2010 Author Posted May 21, 2010 (edited) How extually can you tell if dns is working? believe they are, not sure All firewalls are turned off on each server fsmo roles are on one server (server-6) will check the other two questions out, just need to logon and check through citrix edit: ok cant check, citrix will not let me in, I can get onto the normal ctrl alt delete logon box, its starts complaining about the time different in the server, so will not let me logon. I dont know what the local admin password of that server is, we didnt set that server up Edited May 21, 2010 by pritchardavid
featured_spectre Posted May 21, 2010 Posted May 21, 2010 (edited) go to CMD and then type NSLOOKUP. Do nslookup on a random batch of machines should be able to tell you if your DNS is working properly. It will give you your server name and IP address. If it does that, then your DNS is working. Edited May 21, 2010 by featured_spectre
leco Posted May 21, 2010 Posted May 21, 2010 Do you have the local credentials for the time-server server? Would running dcdiag with the /e switch help with diagnostics?
digital Posted May 22, 2010 Posted May 22, 2010 i have never used citrix so not sure but looks like you have some serious problems their can you even open AD can clients login OK ? what i would check for is to make sure that my group policy is all correct you should really only have the minimal applied e.g password policy etc but i would also make sure that their is no firewalls turn on you shouldn't have them on any way all servers are static ip address which I'm guessing they are also you want to make sure that in your root dns servers that you have the correct srv and pointer records and also that the ldap.TCP is correct the zone transfers are correct your scavaging scale are setup properly and i would also check the last time the system replicated to and from other servers also think back to the last thing that happen before all this went wrong try and trace your steps did you applied any service packs or anything like that or did any one change any passwords that used to authenticate anything also ask your team
pritchardavid Posted May 23, 2010 Author Posted May 23, 2010 Do you have the local credentials for the time-server server? Would running dcdiag with the /e switch help with diagnostics? Not acutally sure what server is the time server, we have had the time wrong for the past two years I believe, never had this sort of problem before All I know is hat server 6 is the master server for all the fmos roles Well were getting our support company in for tomorrow to sort out another problem, looks like they will have to fix this major problem first (haha)
pritchardavid Posted May 23, 2010 Author Posted May 23, 2010 i would also make sure that their is no firewalls turn on you shouldn't have them on Yep checked all firewalls before I left work, all off any way all servers are static ip address which I'm guessing they are All are static and checked also you want to make sure that in your root dns servers that you have the correct srv and pointer records and also that the ldap. Think this is correct, what the difference between srv and pointer records (hard to think what it is, has im not looking at the server and dont know much about dns) TCP is correct the zone transfers are correct your scavaging scale are setup properly No idea, how do you check this? and i would also check the last time the system replicated to and from other servers No idea last time this was done also think back to the last thing that happen before all this went wrong try and trace your steps did you applied any service packs or anything like that or did any one change any passwords that used to authenticate anything also ask your team No passwords have been changed. All I can thiunk of its someone trying to setup a mac server to the active directory, thats about time it all happended. Later when this happended, i did find that the server 7 ip address in dns what now the mac server ip address, so changed this back, has I know he was trying to connect it through server 7
localzuk Posted May 23, 2010 Posted May 23, 2010 When you say someone tried to get an OSX server to work via AD, what method of doing this did they try? Did they update the AD Schema or did they go with the safer route of simply joining the box to the domain? Is the OD server still connected and on?
pritchardavid Posted May 23, 2010 Author Posted May 23, 2010 not sure extually was done on the mac server, but got him to undo all the things he done to it, after that I dont him i'll sort the server out for him, just in case he is doing something wrong (believe he used to work in ict, now one of our music teachers, it actually his server he brought with his department money) Also turned the server off until this problem is sorted, has this may be the problem. dont think any ad schema was done, I know ours is at 2008r2 level does the mac server have its on ad schema then?
SYNACK Posted May 23, 2010 Posted May 23, 2010 The Mac schema implementation that localzuk is talking about is probably the one where to get macs to authenticate directly with AD and get additional Mac specific configurations off it the AD LDAP database schema is modified to include some of the values that Macs expect of an Open Directory server as housed on OSX. This lets you use a bunch of the central managment functionality that you would otherwise need a Mac Server to implement. As the AD database is kind of the core of the network any changes that go wrong can trash everything, the LDAP spec that AD uses though does fully support this kind of modification and you can even modify it youself four your own ends. The general wisdom though is don't touch it unless you know what you are doing, have a backup and really need to do it as if it goes wrong it makes a mess. Looking at the errors above it looks like kerberos has lost sync between servers I'd restart all of the servers and look for failures in the event logs on each of them. If it has a DCpromo in a failed state it could be pointing some clients to the wrong places for kerberos.
Michael Posted May 24, 2010 Posted May 24, 2010 I have to agree with Synack, the AD database is essentially the core and it looks as though it's corrupted. Realistically I think you're looking at a non-authoritative restore of Active Directory on your PDC to get your network back up and running properly. If you still want to introduce the Mac Server, I suggest some extensive testing is required before adding it to a live network.
pritchardavid Posted May 24, 2010 Author Posted May 24, 2010 ok all sorted by our support company today He took the dcs of the domain. expect one and the readded them I was to do with the reliaction of the servers, it was all muddled up with with sever relicated what Also while he was there got him to back dhcp, adter I updated that server to 2008r2 and got him to restore the dhcp service on there. So were totally running a 2008r2 active directory now. Just need to update our two citrix servers and our exchange server, then all servers on the cirrculun our 2008r2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now