Re: Continual errors - Event ID 1030 and 1058 on DC



This article will help you check the security rights on the sysvol
http://support.microsoft.com/kb/290647/en-us

This article normally fixes the problem - start with the dfsutil
/purgemupcache
http://support.microsoft.com/kb/887303/en-us

"Saral6978" wrote:

Nevermind...I found the correct policy in my GP Mgmt mmc...

"Roger Abell [MVP]" wrote:

The Default Domain and the Default Domain Controllers group
policy objects are two different things. It sounds as though you
are being told to check that the second of these is being applied
to the DCs in the DCs OU, but you state you check in the security
settings for the first of these.


"Saral6978" <Saral6978@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7F44BCA0-DAF5-41E5-846A-2037EA5E6FA6@xxxxxxxxxxxxxxxx
Regarding this:
. Domain controllers have the read and apply rights to the Domain
Controllers Policy.
-I'm not sure where to check this? In the security tab of default domain
policy? And where would this setting be configured? I have my Domain
Controllers OU, but the default domain policy is applied here as is 2
other
policies that were created regarding Automatic updates.

I believe I found where this was - I right-clicked on the "default domain
policy" went to "properties". Clicked on the Security tab, and added the
group "Domain Controllers" which contain my 4 DCs and selected Read and
Apply
Group Policy rights for that group; Hopefully this is the policy they are
talking about.


"Saral6978" wrote:

I am continually getting the above 2 errors on my domain controller. KB
Article 842804 refers to a hotfix, but it also says to look at a few
other
possible causes to the error messages before applying the hotfix:

. Netlogon and DFS services are started.
-These services are started

. Domain controllers have the read and apply rights to the Domain
Controllers Policy.
-I'm not sure where to check this? In the security tab of default domain
policy? And where would this setting be configured? I have my Domain
Controllers OU, but the default domain policy is applied here as is 2
other
policies that were created regarding Automatic updates

. NTFS file system permissions and share permissions are set correctly on
the Sysvol share.
-What are the permissions supposed to be exactly?

. DNS entries are correct for the domain controllers.
-This looks to be correct

I'dl like to confirm I have the correct settings above before installing
the
hotfix. I would think that NTFS permissions for the Sysvol should be
fine,
if the default settings were kept, as well as the domain controllers'
read
and apply rights, but I just don't know for sure. I'm not sure if the
person
who worked here before me made any manual changes to this information.

I have a total of 4 domains controllers and the other 3 are not getting
these 2 errors. The particular DC having the issue is considered our
"Master" DC - it assumes all FSMO responsiblities.

Any help would be appreciated as I would love to stop these errors from
occuring all day long, almost every day. Anyone else ever have these 2
errors?



.



Relevant Pages

  • Re: Blocking port scans on local network
    ... You can implement enumeration of SAM accounts and shares with probably no ... on domain controllers via Domain Controller Security Policy depending of ... domain computer that has a "require" ipsec policy assigned to it. ... between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • Re: Blocking port scans on local network
    ... > additional restrictions for anonymous connections in this security guide. ... > do not recommend applying ipsec policy wide scale without some testing of ... > between domain computers and domain controllers as the domain controllers ...
    (microsoft.public.win2000.security)
  • Re: Security Treats
    ... -- No or poor password and account lockout policy. ... -- Misconfigured operating systems - particularly domain controllers and dns. ... -- Not using Group Policy to manage/enforce Internet Explorer security settings. ... -- Not physically securing sensitive computers, ...
    (microsoft.public.win2000.security)
  • Re: IPSEC Wrapper Policy
    ... to create the policy and view it in the first place. ... This posting is provided "AS IS" with no warranties, and confers no rights. ... When I right click on "IP Security ... > Administrators Log on as Service, Log on as batch, etc.... ...
    (microsoft.public.security)
  • Re: Secedit and Domain Controller Security Policy
    ... You configure the appropriate domain/OU Group Policy. ... security templates and the settings will apply to the computers in the OU ... domain controllers I suggest that instead of modifying the default Domain ...
    (microsoft.public.win2000.security)