RE: sbs2003 pdc and bdc no DNS name listed.



email sent..
DNS log is empty?


The problem is still:
New users created in sbs2003 still have no rights to the SQL server.
DPM can not even attach to SQL.
SQL has no DNS name.


"Steven Zhu [MSFT]" wrote:

Hi Brian,

Thank you for your prompt response.

From your active directory export file you mail to me, I don't find any
duplicate object name with CLISBS.CLILANG.LOCAL Windows SBS server. So I
believe duplicate server node shouldn't cause the Kerberos error, there
should be other reason to the problem.

Please refer to the following steps to narrow down this issue:

1. The SRV records are necessary for domain controller to be located,
please recreate it and let me know whether the issue disappears:

1) Run "net stop netlogon"
2) Run "ipconfig /flushdns"
4) Rename netlogon.dnb and netlogon.dns to oldnetlogon.dnb and
oldnetlogon.dns in the folder %systemroot%\system32\config\
5) Run "net start netlogon"
6) Run "ipconfig /registerdns"

2. Please send me the DNS database for further investigation. The
domain.com.dns file and domain.com.dns.log files are located at
%systemroot%\system32\dns.

If the zone is Active Directory integrated zone so the DNS records are
stored in AD instead of the folder on the server. In that case, we can use
dnscmd utility to export the zone file. Please refer to the following KB
for instruction:

304489 Extracting DNS Active Directory-Integrated Zone Files
http://support.microsoft.com/?id=304489

In additional, I find a similar problem about Kerberos Event ID 4, and this
issue may caused by same SPN in DNS. A service principal name (SPN) is the
name by which a client uniquely identifies an instance of a service. If you
install multiple instances of a service on computers throughout a forest,
each instance must have its own SPN. A given service instance can have
multiple SPNs if there are multiple names that clients might use for
authentication. For more information on SPN:

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ad/ad/servi
ce_principal_names.asp

http://www.microsoft.com/resources/documentation/Windows/2000/server/reskit/
en-us/Default.asp?url=/resources/documentation/Windows/2000/server/reskit/en
-us/distrib/dsbd_int_brkw.asp

Please let me know the result above and thanks for your time and patience.

Have a great day.

Best Regards,

Steven Zhu
MCSE
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
======================================================
PLEASE NOTE the newsgroup SECURE CODE and PASSWORD were
updated on February 14, 2006.? Please complete a re-registration process
by entering the secure code mmpng06 when prompted. Once you have
entered the secure code mmpng06, you will be able to update your profile
and access the partner newsgroups.
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
======================================================








.



Relevant Pages

  • Re: slow DNS caused extreme SQLS memory pressure+CPU?
    ... RAM in my 64-bit SQL Server box. ... The DNS problem occurring at almost the same time is simply ... The CPU on the SQLS ...
    (comp.databases.ms-sqlserver)
  • Re: Delegation problems
    ... There are no SPNs on the machine account. ... did you add an SPN to that service account in AD ... delegate from my web server to the SQL service on the DB server when I ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: SPN for SSL over common name
    ... you can't register those SPNs under the SQL Server's ... service account is the MSSQL SPN. ... That SPN should be registered under ... Lastly, since the SQL Server is not being used for delegation anywhere, ...
    (microsoft.public.inetserver.iis.security)
  • Re: SPN for SSL over common name
    ... you can't register those SPNs under the SQL Server's ... That SPN should be registered under the SQL ... Server's service account and *removed* from the SQL ... Lastly, since the SQL Server is not being used for delegation anywhere, ...
    (microsoft.public.inetserver.iis.security)
  • Re: NewBie ASP.NET on a PDC securiy sugestions
    ... are about 25, I am running SQL, and imail, and DNS on the server. ...
    (microsoft.public.dotnet.framework.aspnet.security)