RE: Network printing mystery



hi,
on print server check on local policies or on GPO that apply to that printer
server the security settings - allow access this computer from network (it
have to be xyz.com domain users) and deny access this computer from network
if the proper groups are there.
--
Dragos CAMARA
MCSA Windows 2003 server


"Tom wilson" wrote:

Hi! We run a Windows enterprise with W2003 servers and 2 domains. One
of the domain controllers is the print server. We have a giant Xerox
printer that everyone in both domains print to. They've been doing
this no problem until this week.

Half the people in the building can't print to this printer. Their end
says the document failed to print and has been deleted. It simply
disappears like it never existed. In the event logs of the print
server I keep seeing this:

"The document Microsoft Word - MyDoc.doc owned by someuser failed to
print on printer Xerox WorkCentre Pro 255 PS. Data type: NT EMF 1.008.
Size of the spool file in bytes: 65536. Number of bytes printed: 0.
Total number of pages in the document: 1. Number of pages printed: 0.
Client machine: \\SOMECLIENT. Win32 error code returned by the print
processor: 0. The operation completed successfully."

This only started last week. Since then I've checked all permissions
on that printer. Everyone has full control. I even added "Domain
Users" from both domains into security. If I log on to any of these
workstations as the domain administrator, it prints fine. Log in as a
user and it fails every time.

Domain abc.com hosts the print server. Domain users in abc.com can
print fine. Domain xyz.com cannot print at all, unless it's the domain
administrator. The following are in security with full control for
said printer:

abc.com Administrators
Authenticated users
Creator owner
abc.com domain users
xyz.com domain users
Everyone
Print Operators, abc.com
server operators, abd.com
xyz.com's active directory master (machine, not user)

Once in a while I see this in event viewer:

"The kerberos client received a KRB_AP_ERR_MODIFIED error from the
server FRANCESCALP$. The target name used was cifs/FRANCESCALP. This
indicates that the password used to encrypt the kerberos service
ticket is different than that on the target server. Commonly, this is
due to identically named machine accounts in the target realm
(XYZ.COM), and the client realm. Please contact your system
administrator."

The server has had all Windows updates and has been restarted from
power down.

I'm 100% stumped. There's no indication at all as to where the problem
is, printed documents simply disappear without reason.

Any help much appreciated, thanks!


.



Relevant Pages

  • RE: Cant set Local Security policies. They fail to save
    ... I followed your instructions on applying the predefined security templates. ... I still can’t set any of the local security policies on the server box. ... > using local Administrator account to test, ... >>> member of either the Remote Operators group or the Domain Power Users ...
    (microsoft.public.windows.server.sbs)
  • Re: FOR A SKILLED IT EXPERT - WIN2K SERVER - DOMAIN CONTROLLER
    ... After installing a parallel copy of WIN2K SERVER, ... Administrator access in Directory Services Restore Safe Mode. ... This reset the local policy back to ... manual security reset. ...
    (microsoft.public.win2000.security)
  • Help: ISAPI DLL cannot reach DCOM appserver (access denied)
    ... IIS (5.0 on W2K server machine, not PDC, joined to the main domain) is ... These users are all domain users (not local users of the IIS server). ... user" option which is an administrator) and in launch/access permission ...
    (microsoft.public.inetserver.iis.security)
  • Re: Queries regarding DCOM Security Enhancements in Windows XP Service Pack 2
    ... administrator, while server security lies with the developer. ... not be adequate for the client-server application, ...
    (microsoft.public.win32.programmer.ole)
  • Re: Unable to login to SBS Server
    ... Les Connor [SBS MVP] ... We were asked to look at a SBS 2003 server & found that the group policy has somehow been altered & we decided to do a complete re-install of the system. ... I guess this is because the administrator cannot log on so I then checked the local policy by running secpol.msc and then checked Security ...
    (microsoft.public.windows.server.sbs)