Re: Group policy Error; Event ID 1030 & 1058



Hello Meinwolf Weber,

Merry Xmas to you.

I totally agree with you. Please find my findings below:

Ipconfig /all:

Windows IP Configuration


Host Name . . . . . . . . . . . . : mudonmainsrvr

Primary Dns Suffix . . . . . . . : mudonsiteoff.local

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : mudonsiteoff.local



Ethernet adapter Local Area Connection 2:



Connection-specific DNS Suffix . : mudonsiteoff.local

Description . . . . . . . . . . . : HP NC373i Multifunction Gigabit
Server Adapter #2

Physical Address. . . . . . . . . : 00-1A-4B-E9-FD-4A

DHCP Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : 192.168.1.20

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.10

DNS Servers . . . . . . . . . . . : 192.168.1.20

213.42.20.20


dcdiag.exe:


Domain Controller Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial required tests

Testing server: Default-First-Site-Name\MUDONMAINSRVR
Starting test: Connectivity
......................... MUDONMAINSRVR passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\MUDONMAINSRVR
Starting test: Replications
......................... MUDONMAINSRVR passed test Replications
Starting test: NCSecDesc
......................... MUDONMAINSRVR passed test NCSecDesc
Starting test: NetLogons
......................... MUDONMAINSRVR passed test NetLogons
Starting test: Advertising
......................... MUDONMAINSRVR passed test Advertising
Starting test: KnowsOfRoleHolders
......................... MUDONMAINSRVR passed test
KnowsOfRoleHolders
Starting test: RidManager
......................... MUDONMAINSRVR passed test RidManager
Starting test: MachineAccount
......................... MUDONMAINSRVR passed test MachineAccount
Starting test: Services
......................... MUDONMAINSRVR passed test Services
Starting test: ObjectsReplicated
......................... MUDONMAINSRVR passed test ObjectsReplicated
Starting test: frssysvol
......................... MUDONMAINSRVR passed test frssysvol
Starting test: frsevent
......................... MUDONMAINSRVR passed test frsevent
Starting test: kccevent
......................... MUDONMAINSRVR passed test kccevent
Starting test: systemlog
......................... MUDONMAINSRVR passed test systemlog
Starting test: VerifyReferences
......................... MUDONMAINSRVR passed test VerifyReferences

Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom

Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom

Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom

Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test
CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom

Running partition tests on : mudonsiteoff
Starting test: CrossRefValidation
......................... mudonsiteoff passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... mudonsiteoff passed test CheckSDRefDom

Running enterprise tests on : mudonsiteoff.local
Starting test: Intersite
......................... mudonsiteoff.local passed test Intersite
Starting test: FsmoCheck
......................... mudonsiteoff.local passed test FsmoCheck


netdiag.exe:


......................................

Computer Name: MUDONMAINSRVR
DNS Host Name: mudonmainsrvr.mudonsiteoff.local
System info : Microsoft Windows Server 2003 R2 (Build 3790)
Processor : x86 Family 6 Model 15 Stepping 6, GenuineIntel
List of installed hotfixes :
KB921503
KB924667-v2
KB925398_WMP64
KB925876
KB925902
KB926122
KB927891
KB929123
KB930178
KB931784
KB932168
KB933360
KB933729
KB933854
KB935839
KB935840
KB935966
KB936021
KB936357
KB936782
KB937143
KB937143-IE7
KB938127
KB938127-IE7
KB939653-IE7
KB941202
KB941568
KB941569
KB941672
KB942615-IE7
KB942763
KB943460
KB944653
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : Local Area Connection 2

Netcard queries test . . . : Passed

Host Name. . . . . . . . . : mudonmainsrvr.mudonsiteoff.local
IP Address . . . . . . . . : 192.168.1.20
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.1.10
Dns Servers. . . . . . . . : 192.168.1.20
213.42.20.20


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
'Messenger Service', <20> 'WINS' names is missing.

WINS service test. . . . . : Skipped
There are no WINS servers configured for this interface.


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{90E36FA0-B07E-407E-A26A-6D966D565985}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation
Service', <03> 'Messenger Service', <20> 'WINS' names defined.


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server
'192.168.1.20'.
[WARNING] The DNS entries for this DC cannot be verified right now on
DNS server 213.42.20.20, ERROR_TIMEOUT.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{90E36FA0-B07E-407E-A26A-6D966D565985}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{90E36FA0-B07E-407E-A26A-6D966D565985}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Passed


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Skipped

Note: run "netsh ipsec dynamic show /?" for more detailed information


The command completed successfully


Please tell me what we need to resolve this.

Thank You & Merry Xmas again





"Meinolf Weber" wrote:

Hello sphilip,

Before looking around lets start with some basic trouble shooting. Please
do not try out additional things. Lets try to find a step by step solution.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm

Also, I ran gpotool /verbose & this is my log

Domain: mudonsiteoff.local
Validating DCs...
Available DCs:
mudonmainsrvr.mudonsiteoff.local
Searching for policies...
Found 2 policies
============================================================
Policy {31B2F340-016D-11D2-945F-00C04FB984F9}
Error: Cannot access
\\mudonmainsrvr.mudonsiteoff.local\sysvol\mudonsiteoff.local\policies\
{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini, error 2
Friendly name: Default Domain Policy
Details:
------------------------------------------------------------
DC: mudonmainsrvr.mudonsiteoff.local
Friendly name: Default Domain Policy
Created: 9/5/2007 2:01:02 PM
Changed: 12/23/2007 9:42:40 AM
DS version: 3(user) 49(machine)
Sysvol version: not found
Flags: 0 (user side enabled; machine side enabled)
User extensions:
[{3060E8D0-7020-11D2-842D-00C04FA372D4}{3060E8CE-7020-11D2-842D-00C04F
A372D4}]
Machine extensions:
[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{53D6AB1B-2488-11D1-A28C-00C04F
B94F17}][{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D
0-00A0C90F574B}][{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}{53D6AB1B-2488-
11D1-A28C-00C04FB94F17}]
Functionality version: 2
------------------------------------------------------------
============================================================
Policy {6AC1786C-016F-11D2-945F-00C04FB984F9}
Error: Cannot access
\\mudonmainsrvr.mudonsiteoff.local\sysvol\mudonsiteoff.local\policies\
{6AC1786C-016F-11D2-945F-00C04FB984F9}, error 2
Friendly name: Default Domain Controllers Policy
Details:
------------------------------------------------------------
DC: mudonmainsrvr.mudonsiteoff.local
Friendly name: Default Domain Controllers Policy
Created: 9/5/2007 2:01:02 PM
Changed: 12/24/2007 9:40:41 AM
DS version: 2(user) 22(machine)
Sysvol version: not found
Flags: 0 (user side enabled; machine side enabled)
User extensions: not found
Machine extensions:
[{827D319E-6EAC-11D2-A4EA-00C04F79F83A}{803E14A0-B4FB-11D0-A0D0-00A0C9
0F574B}]
Functionality version: 2
------------------------------------------------------------
============================================================
Errors found

Please let me know if you can find anything from this, I will post the
ipconfig /all + netdiag & dcdiag very soon.

Thank You & Merry Xmas

"sphilip" wrote:

Hello Meinolf Weber, Thank You for the response I will be posting
ipconfig /all + dcdiag & netdiag shortly.

However I want to tell you the root of this problem,

I am logging in as administrator of the domain controller but anytime
i try to edit any "Domain Controller Security Policy" & "Domain
Security Policy" & when I click "Apply" to save the changes I get
this error:

Access is Denied.

Failed to Save.

\\domain name\sysvol\domain

name\policies\{6AC1786C-016F-11D2-945F-00C04FB9-84F9}\Machine\Microso
ft\Windows NT\Sec Edit\GptTmpl.inf

Make sure you have the right permissions to this object.

After this i ran dcgpofix tool, running this tool failed with some
"cannot re-create the EFS certificate" error & from then on I am
having this problem.

Please advice me on how I can resolve this issue too.

Thank You & Merry Xmas

"Meinolf Weber" wrote:

Hello sphilip,

Start here, there can be a lot of problems for this event id
combination: http://support.microsoft.com/kb/842804

http://support.microsoft.com/kb/314494

Can you also post an ipconfig /all here and an unedited dcdiag and
netdiag.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm
major




.



Relevant Pages

  • Re: GPO Reinstall
    ... Ethernet adapter Local Area Connection 2: ... Running partition tests on: ForestDnsZones ... Starting test: CrossRefValidation ... Running partition tests on: Configuration ...
    (microsoft.public.windows.server.general)
  • Re: DNS CORRUPT AND ALL SYSTEMS DOWN
    ... > This error can occur because of a common DNS misconfiguration. ... Ethernet adapter Local Area Connection: ... Source domain controller address: ... Starting test: CrossRefValidation ...
    (microsoft.public.windows.server.dns)
  • RE: error found after dc demote
    ... The DNS on AD05 and AD06 is not the best solution. ... Windows 2000 IP Configuration ... Ethernet adapter Local Area Connection: ... Starting test: CrossRefValidation ...
    (microsoft.public.win2000.active_directory)
  • RE: error found after dc demote
    ... AD01 (is DC, DNS DHCP) ... Windows 2000 IP Configuration ... Ethernet adapter Local Area Connection: ... Starting test: CrossRefValidation ...
    (microsoft.public.win2000.active_directory)
  • Re: Unable to connect new vista terminal to SBS 2003 R2
    ... Windows IP Configuration ... Ethernet adapter Server Local Area Connection: ... Connection-specific DNS Suffix. ...
    (microsoft.public.windows.server.sbs)