Re: Autoenrollment errors in Event Viewer...

From: Ken Gardner (KenGardner_at_discussions.microsoft.com)
Date: 02/04/05


Date: Fri, 4 Feb 2005 05:57:03 -0800

I agree with you on the DHCP part for the clients. I inherited this network
and the reason why they do not use DHCP is due an AutoCAD application
licensing issue. I alos know that we can veer around that with reservations
too, but it is what it is right now. I have proposals into upper mgmt. for a
network overhaul anyway. Besides I have to work with and deal with what I
have right now.

As for XP SP2, we're not finished testing it with our AutoCAD applications
and one of our backup programs too (ARCServe Mgmt. Interface for Novell).

Each computer logins into the domain, not the local computer. The domain
has not been broken down yet (thats included in my proposals to mgmt too.)
either.

Anyway, I managed to figure out what the issue was too. It was the NIC
driver on the server. I updated the driver from the vendor only and
everything is ok now. Funny, I never woulda guessed a NIC driver at all. My
first thoughts were domain GP, Kerberos or the workstation authentication
certificate.

As all ways thanks for the replies and I'm open to suggestions for the
domain reorganization as well if anyone has some. We're running a single
domain, single subnet, SBS 2003 Prem. Ed. server acting as the DC, DNS,
housing Exchange, SQL, antivirus, metering software...and a Novell 5
file/app. server. The Novell server will be on its way out sometime this
year, so it should morph into a Win2k3 file/app server and backup DC too. No
computers or users have been broken down into seperate OU's yet either (in
the works). Clients use the Novell Client login to authenticate to both
servers and login directly into the local domain (domainname.local).

Thanks,

Ken

"Marina Roos [SBS-MVP]" wrote:

> Hi Ken,
>
> Why aren't you using DHCP? Your clients are missing the WINS now. DHCP would
> provide that automagically. Why aren't the XP's on SP2? Are those XP's
> really login into the domain instead of the local computerdomain?
>
> --
> Regards,
>
> Marina
> Microsoft SBS-MVP
> One of the Magical M&M's
>
> "Ken Gardner" <KenGardner@discussions.microsoft.com> schreef in bericht
> news:37464699-C7E2-4C52-891F-EB125EFC9841@microsoft.com...
> > I'm not too sure I'm getting these errors on my clients when they login
> (see
> > below). I'm also running an SBS 2003 Prem. Ed. server and all clients are
> XP
> > SP1, no SP2 installed. All clients have static IP's and are all pointing
> > correctly to the server.
> > Thanks in advance.
> >
> > Event Viewer error reports and ipconfig /all snip-its:
> >
> > Event Type: Error
> > Event Source: Userenv
> > Event Category: None
> > Event ID: 1053
> > Date: 2/3/2005
> > Time: 12:37:43 PM
> > User: NT AUTHORITY\SYSTEM
> > Computer: KGG01A
> > Description:
> > Windows cannot determine the user or computer name. (Access is denied. ).
> > Group Policy processing aborted.
> >
> > For more information, see Help and Support Center at
> > http://go.microsoft.com/fwlink/events.asp.
> >
> >
> > Event Type: Error
> > Event Source: AutoEnrollment
> > Event Category: None
> > Event ID: 15
> > Date: 2/3/2005
> > Time: 12:38:43 PM
> > User: N/A
> > Computer: KGG01A
> > Description:
> > Automatic certificate enrollment for local system failed to contact the
> > active directory (0x8007052b). Unable to update the password. The value
> > provided as the current password is incorrect.
> > Enrollment will not be performed.
> >
> > For more information, see Help and Support Center at
> > http://go.microsoft.com/fwlink/events.asp.
> >
> > Microsoft Windows XP [Version 5.1.2600]
> > (C) Copyright 1985-2001 Microsoft Corp.
> >
> > C:\>ipconfig /all
> >
> > Windows IP Configuration
> >
> > Host Name . . . . . . . . . . . . : kgg01a
> > Primary Dns Suffix . . . . . . . : ssastructural.local
> > Node Type . . . . . . . . . . . . : Unknown
> > IP Routing Enabled. . . . . . . . : No
> > WINS Proxy Enabled. . . . . . . . : No
> > DNS Suffix Search List. . . . . . : ssastructural.local
> >
> > Ethernet adapter Local Area Connection:
> >
> > Connection-specific DNS Suffix . :
> > Description . . . . . . . . . . . : VIA Networking Velocity Family
> > Giga-
> > bit Ethernet Adapter
> > Physical Address. . . . . . . . . : 00-50-8D-64-46-5F
> > Dhcp Enabled. . . . . . . . . . . : No
> > IP Address. . . . . . . . . . . . : 10.0.0.55
> > Subnet Mask . . . . . . . . . . . : 255.255.255.0
> > Default Gateway . . . . . . . . . : 10.0.0.1
> > DNS Servers . . . . . . . . . . . : 10.0.0.101
> >
> > C:\>
> >
> >
> > Microsoft Windows XP [Version 5.1.2600]
> > (C) Copyright 1985-2001 Microsoft Corp.
> >
> > C:\>ipconfig /all
> >
> > Windows IP Configuration
> >
> > Host Name . . . . . . . . . . . . : SSASBS2K3
> > Primary Dns Suffix . . . . . . . : ssastructural.local
> > Node Type . . . . . . . . . . . . : Unknown
> > IP Routing Enabled. . . . . . . . : YES
> > WINS Proxy Enabled. . . . . . . . : YES
> > DNS Suffix Search List. . . . . . : ssastructural.local
> >
> > Ethernet adapter Local Area Connection:
> >
> > Connection-specific DNS Suffix . :
> > Description . . . . . . . . . . . : VIA Networking Velocity Family
> > Giga-
> > bit Ethernet Adapter
> > Physical Address. . . . . . . . . : 00-0E-A6-01-EA-51
> > Dhcp Enabled. . . . . . . . . . . : No
> > IP Address. . . . . . . . . . . . : 10.0.0.101
> > Subnet Mask . . . . . . . . . . . : 255.255.255.0
> > Default Gateway . . . . . . . . . : 10.0.0.1
> > DNS Servers . . . . . . . . . . . : 10.0.0.101
> > Primary WINS Server . . . . . . . : 10.0.0.101
> >
> > C:\>
> >
> >
>
>
>



Relevant Pages

  • RE: VPN, RRAS & DHCP
    ... Open DHCP console. ... Check the status of the local server. ... <VPN connections subsequently fail again. ... <I say fail but in practice both the server and clients are assigned IP ...
    (microsoft.public.windows.server.sbs)
  • RE: DHCP: not reached by clients
    ... This newsgroup only focuses on SBS technical issues. ... | Thread-Topic: DHCP: not reached by clients ... | thereafter re-enabling dhcp server it worked perfectly. ...
    (microsoft.public.windows.server.sbs)
  • Re: IIS 6.0 FTP
    ... Server port: 21. ... I doubt IIS FTP has such feature. ... next, general 530 error indicating login failed, that could due to ... clients are using an order entry program created in Microsoft access. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: How to setup effective school network
    ... > I have a very nice quality server ... ... > Network card all hubs and switches to my server and serve dhcp. ... the listing it appears you are running samba/windows clients. ... Do SSO for just a few hosts initially to get some experience. ...
    (comp.os.linux.networking)
  • Re: Taking Domain Controller Offline
    ... Depends of the DHCP clients lease, if you think that the amount of time that ... additional DHCP server, of course if you've one in place you should use it ... sure that the clients are able to use the additional DNS server. ... "Jorge Silva" wrote: ...
    (microsoft.public.windows.server.active_directory)

Loading