DNS Error 4011 on Active Directory-Integrated DNS
- From: mjblay@xxxxxxxxx
- Date: Mon, 2 Jun 2008 23:24:40 -0700 (PDT)
Hello,
I have a Windows 2003 domain controller running an Active Directory-
Integrated DNS, and I've recently been getting the following error
message:
The DNS server was unable to add or write an update of domain name
dc02 in zone mydomain.com to the Active Directory. Check that the
Active Directory is functioning properly and add or update this domain
name using the DNS console. The extended error debug information
(which may be empty) is "00002098: SecErr: DSID-03150A45, problem 4003
(INSUFF_ACCESS_RIGHTS), data 0". The event data contains the error.
The Help and Support Center says to:
Check the permissions on the specified file:
1. In Windows Explorer, go to the Systemroot\System32\Dns folder.
2. Right-click the specified database file, and then click
Properties.
3. Click the Security tab, and then click Permissions.
4. Verify that you have the proper permissions to read, write, and run
the file.
I have three .dns files in this directory: cache.dns, 1.16.172.in-
addr.arpa.dns, and 3.16.172.in-addr.arpa.dns. I've never changed the
security settings on any of these files to start with, and I'm not
sure how or why they could have been altered. Since the error message
has started appearing, I've checked the security settings, and they
seem right to me:
DOMAIN\Administrators -- Full Control
Authenticated Users -- Read & Execute; Read
DOMAIN\Domain Admins -- Full Control
DOMAIN\Server Operators -- Modify; Read & Execute; Read; Write
SYSTEM -- Full Control
The DNS server seems to function properly, but I'd like to fix this
error to be sure that updates from other servers are being propagated
to this one. No similar errors are occurring on other servers. There
are no Active Directory errors in the Event Viewer and there are no
failed tests in DCDIAG. I'd really appreciate any suggestions about
solving this problem.
.
- Follow-Ups:
- Re: DNS Error 4011 on Active Directory-Integrated DNS
- From: Meinolf Weber
- Re: DNS Error 4011 on Active Directory-Integrated DNS
- Prev by Date: Re: DNS Cache corruption?
- Next by Date: Re: DNS Error 4011 on Active Directory-Integrated DNS
- Previous by thread: DNS Cache corruption?
- Next by thread: Re: DNS Error 4011 on Active Directory-Integrated DNS
- Index(es):
Relevant Pages
|