Re: Errors

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I think I've seen that article before.

CAUSE
This issue may occur if one or more of the following conditions are true:
1) Only one other domain controller is available in the domain, and that
domain controller is starting up, but is not completely started.
2) This is the only domain controller in the domain. The error events that
are described in the "Symptoms" section of this article are logged while the
domain controller is starting up.
3) A program sends a request that requires a domain controller role, and the
domain controller is still starting up.
4) The Net Logon service on a domain controller is set to Manual and is not
started.

my answer:
1) I have 2 DCs and Server1 (DC1) is running while Server2 (DC2) starts up.
I haven't restarted Server2 for months.
2) No. I have 2 DCs
3) Not sure I understand this part
4) No, Netlogon service on both machines (Server1 and Server2) are set to
Automatic and runs properly.

There are no other repeating errors. The 2 errors only shows up after
restarts. If I don't restart it, no more errors. How do I make sure the 2
DCs are "talking" to each other properly?

Thanks for your quick reply.


"mtstream" <mtstream@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7352976A-F2DC-4C68-A0C5-BAF981FA663B@xxxxxxxxxxxxxxxx
Check this:
http://support.microsoft.com/kb/832215/en-us

Any other errors or errors repeating every 15min?

"John Doe" wrote:

Server1
Windows Server 2003 AD
DNS

I just installed another server for redundancy. Ran DCPROMO on server2.
Server2 now acts as another DC for the same domain. DNS is not installed
on
server2 yet. When server2 starts up, I get 2 errors:

Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1030
Date: 2/9/2007
Time: 1:00:41 PM
User: NT AUTHORITY\SYSTEM
Computer: WIN2003SRV02
Description:
Windows cannot query for the list of Group Policy objects. Check the
event
log for possible
messages previously logged by the policy engine that describes the reason
for this.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1097
Date: 2/9/2007
Time: 1:00:41 PM
User: NT AUTHORITY\SYSTEM
Computer: WIN2003SRV02
Description:
Windows cannot find the machine account, The Local Security Authority
cannot
be contacted .
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.


The above errors are always there whenever Server2 gets restarted. The
only
non-default setting in my domain is following:

Domain Controller Security Policy - Local Policies - Security Options -
Microsoft Network Server: Digitally sign communications (always)

Default setting is ENABLED. I changed it to DISABLED so old OS versions
can
authenticate to the network. I still have Windows 98 and NT4 servers in
the
domain.

My questions:
- Could that cause the error? Should I change it back to ENABLED?
- Is that a serious error?
- Last questions are, how can I make sure that the 2 DCs are
communicating
properly. Should I run DCDIAG or NETDIAG? Any switch to use when running
dcdiag or netdiag? What do I look for in the result? Warnings/Errors?

Btw, I ran DCDIAG without switch. The result doesn't even show Server2.
It
looks as if server2 doesn't exist. Is that normal? Thanks in advance.





.



Relevant Pages

  • Re: Errors (Correction)
    ... I haven't restarted Server2 for months. ... AD controller + DNS ... domain controller is starting up, ...
    (microsoft.public.windows.server.general)
  • Re: Errors (Correction)
    ... I haven't restarted Server2 for months. ... AD controller + DNS ... domain controller is starting up, ...
    (microsoft.public.windows.server.general)
  • Re: missing netlogon & Sysvol Share
    ... Troubleshooting File Replication Service ... problem is server2 is missing the Sysvol and Netlogon Shares. ... This event log message will appear once per connection, ... No Windows NT or Windows 2000 Domain Controller is available for domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help! Need to know how to set DC as default for logon...
    ... Currently, I added Server2 ... as a domain controller and AD was copied over, but if I pull down Server1, ... none of the computers are logging onto the domain. ... If your clients are configured statically you can do this either manually or use a GPO, if they get the config of a DHCP-Server you can just change this in the Options on the DHCP-Scope. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD sites and services
    ... A search for "Active Directory Sites" yeilds the following: ... After an Unsuccessful Domain Controller Demotion" ... http://support.microsoft.com?kbid=220140 "FRS Replication Protocol and Topology ... Windows 2000 Domain Controllers" ...
    (microsoft.public.win2000.active_directory)