Enormous security problem

From: wosully (wosully_at_discussions.microsoft.com)
Date: 01/23/05


Date: Sun, 23 Jan 2005 13:53:01 -0800

Hi all,

I have one 2003 DC without any service pack, and one 2003 file server with
SP1 RC1, and I have run netdiag from the command line on the file server and
the LDAP tests have continually failed; no other tests fail. Any account
(even domain admin) that I log onto the file server with and use computer mgt
snap in to manage the DC, shows up in the DC's security log as a failed
authentication (680 and 529 errors). Eventually the accounts are locked out
every time. I had to disable account lock out in the defualt domain policy.
I have tried changing the accounts passwords. I have even taken the file
server out of the domain and renamed it prior to inserting it back into the
domain, but the problem persists. I have tested this with other domain admin
accounts and the result is the same.

When I open up comp mgt from the file server pointed at the DC and scroll to
the security log, all I have to do is select the security log and hit refresh
and a new pair of failure audits pop up until the account is locked again.

What would cause this problem and who do I need to pay off to fix it?

-- 
MCSE: Security, CCNA, A+, Network +, Security+


Relevant Pages

  • Re: Manage 30 XP, 2000, 98 without Domain Controller
    ... account on 98 machines) ... folders on the File Server, setup NTFS permission on each folder. ... How to prevent them from share out local folders, ... So is it possible to make the workgroup change ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Enormous security problem
    ... What is the LDAP failure return code in Netdiag? ... Are there errors on the file server perhaps kerberos errors in the system ... I had to disable account lock out in the defualt domain> policy. ... > the security log, all I have to do is select the security log and hit> refresh ...
    (microsoft.public.windows.server.general)
  • Re: Enormous security problem
    ... > Windows cannot query for the list of Group Policy objects. ... >> Are there errors on the file server perhaps kerberos errors in the system ... >>> snap in to manage the DC, shows up in the DC's security log as a failed ... I had to disable account lock out in the defualt domain ...
    (microsoft.public.windows.server.general)
  • old user account preventing networking
    ... Our office just got a new file server, ... network printer. ... everyone has a user account on ...
    (microsoft.public.windowsxp.network_web)
  • RE: A share located on another computer
    ... The connect as account need to have access this computer from network ... i.e. your file server here assuming a member or stand-alone ... Microsoft Product Service Packs ... Microsoft IIS Bookstore ...
    (microsoft.public.inetserver.iis.security)