Re: event id 1030 and 1058

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Mark Renoden [MSFT] (markreno_at_online.microsoft.com)
Date: 02/16/05


Date: Thu, 17 Feb 2005 09:46:47 +1100

Hi Greg

Aside from the fix, I've seen this once or twice. There's a whole range of
things that may cause it ranging from DNS problems to dodgy NIC drivers.

Kind regards

-- 
Mark Renoden [MSFT]
Windows Platform Support Team
Email: markreno@online.microsoft.com
Please note you'll need to strip ".online" from my email address to email 
me; I'll post a response back to the group.
This posting is provided "AS IS" with no warranties, and confers no rights.
"Greg DeMaderios" <GregDeMaderios@discussions.microsoft.com> wrote in 
message news:A32701D6-4BA2-4DC3-B2DA-7A0459025C87@microsoft.com...
> Mark,
>
> I appreciate your response but I had already stepped through that (I
> searched and read some of your previous posts.)  I actually had to do the
> exact opposite of KB839499 regarding SMB signing and disabling it for
> Microsoft Network Server and Microsoft Network Client.
>
> "Greg DeMaderios" wrote:
>
>> Frustrating on two fronts.  The errors as mentioned in the subject field 
>> and
>> the fact that I type out a big long post and it doesn't seem to have made 
>> it
>> to technet.  Grrrrrrrrrrrrrrr.  I'll start again.
>>
>> We have 2 DC's, DC1 and DC2 we'll call them.  Around Feb 1, 2005 updated
>> both DC1 and DC2 with latest security patches from MS and started seeing 
>> this:
>>
>> Windows cannot query for the list of Group Policy objects. Check the 
>> event
>> log for possible messages previously logged by the policy engine that
>> describes the reason for this.
>>
>> and this:
>>
>> Windows cannot access the file gpt.ini for GPO
>> CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=domain,DC=com.
>> The file must be present at the location
>> <\\domain.com\sysvol\domain.com\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>.
>> (Access is denied. ). Group Policy processing aborted. (The domain has 
>> been
>> changed to domain.com to protect the innocent)
>>
>> I stepped through KB 839499 regarding SMB signing and that took care of 
>> the
>> issue until yesterday when I updated the servers again.  Stepped through 
>> the
>> aforementioned KB on DC1 and it worked fine (the errors went away in 
>> event
>> viewer) but on DC2, the errors are not going away.
>>
>> I cannot access \\domain.com\sysvol\domain.com from DC2 (it asks for
>> credentials) and tells me access denied.  I can access that same UNC path
>> from DC1 and it's fine, I can access that UNC path from my workstation 
>> and
>> get to it just fine.
>>
>> When I open Group Policy Management on DC1 or my workstation, I open it 
>> just
>> fine.  When I try to open Group Policy Management on DC2, I get "Access 
>> is
>> Denied".
>>
>> I've tried everything from eventid.net including the dfsutil 
>> /PurgeMupCache,
>> adding our DCs to each hosts file, DFS service is turned on.
>>
>> Everyone can access DC2 just fine as it's a file/print server so no 
>> problems
>> there.
>>
>> Any help is appreciated.  Thanks,
>> Greg 


Relevant Pages

  • event id 1030 and 1058
    ... both DC1 and DC2 with latest security patches from MS and started seeing this: ... Windows cannot query for the list of Group Policy objects. ... viewer) but on DC2, the errors are not going away. ... When I open Group Policy Management on DC1 or my workstation, ...
    (microsoft.public.windows.group_policy)
  • Re: event id 1030 and 1058
    ... Windows Platform Support Team ... > Windows cannot query for the list of Group Policy objects. ... > aforementioned KB on DC1 and it worked fine (the errors went away in event ... > viewer) but on DC2, the errors are not going away. ...
    (microsoft.public.windows.group_policy)
  • Re: AD replication
    ... Assuming DC1 for the Root Domain, and DC2 for the child domain: ... NtdsSettings -> all tasks and choose check replication topology, ...
    (microsoft.public.windows.server.active_directory)
  • Re: netlogon using wrong DC
    ... You can not remove DC1 from DC2, you can demote a DC from the domain, ... Authentication requires a configured DNS server that is known from all ... it will no longer replicate nor communicate wtih ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need DHCP Setup Clarification 2003 Std Svr
    ... I've discovered that DC1 has bindings to two connections!! ... I should then go into DC2 which lists it's proper static IP and activate it. ... That splits the DHCP assigning about 80/20. ...
    (microsoft.public.windows.server.general)