Quantcast
Channel: Group Policy forum
Viewing all articles
Browse latest Browse all 19997

Group Policy processing failure on 2008 when MIX Domain 2003 with DC 2008

$
0
0
Dear I try to add additional Windows 2008 Domain to My Domain controller 2003  and I ma Receiving Group policy error in DC 2008  With Event ID 1055

The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 
a) Name Resolution failure on the current domain controller. 
b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-GroupPolicy" Guid="{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}" /> 
  <EventID>1055</EventID> 
  <Version>0</Version> 
  <Level>2</Level> 
  <Task>0</Task> 
  <Opcode>1</Opcode> 
  <Keywords>0x8000000000000000</Keywords> 
  <TimeCreated SystemTime="2014-03-06T14:36:44.411955300Z" /> 
  <EventRecordID>3859</EventRecordID> 
  <Correlation ActivityID="{28DAD258-26D0-4C1E-A4B7-F37DEE04C8F1}" /> 
  <Execution ProcessID="952" ThreadID="3276" /> 
  <Channel>System</Channel> 
  <Computer>PRIMARYDC.Qtit.com</Computer> 
  <Security UserID="S-1-5-18" /> 
  </System>
- <EventData>
  <Data Name="SupportInfo1">1</Data> 
  <Data Name="SupportInfo2">1632</Data> 
  <Data Name="ProcessingMode">0</Data> 
  <Data Name="ProcessingTimeInMilliseconds">1578</Data> 
  <Data Name="ErrorCode">5</Data> 
  <Data Name="ErrorDescription">Access is denied.</Data> 
  </EventData>
  </Event>

I install See KB939820 for a hotfix applicable to Microsoft DC 2003 regrading to he KRBTGT account 

Refer Url : http://support.microsoft.com/kb/939820 

I run dcdiag /v on  and repadmin /showrepl at DC 2008

the dcdiag /v result

               *****************************            
Directory Server Diagnosis


Performing initial setup:

   Trying to find home server...

   * Verifying that the local machine PRIMARYDC, is a Directory Server. 
   Home Server = PRIMARYDC

   * Connecting to directory service on server PRIMARYDC.

   * Identified AD Forest. 
   Collecting AD specific global data 
   * Collecting site info.

   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=Qtit,DC=com,LDAP_SCOPE_SUBTREE,(objectCategory=ntDSSiteSettings),.......
   The previous call succeeded 
   Iterating through the sites 
   Looking at base site object: CN=NTDS Site Settings,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com
   Getting ISTG and options for the site
   * Identifying all servers.

   Calling ldap_search_init_page(hld,CN=Sites,CN=Configuration,DC=Qtit,DC=com,LDAP_SCOPE_SUBTREE,(objectClass=ntDSDsa),.......
   The previous call succeeded....
   The previous call succeeded
   Iterating through the list of servers 
   Getting information for the server CN=NTDS Settings,CN=SECONDAD,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com 
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   Getting information for the server CN=NTDS Settings,CN=PRIMARYDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com 
   objectGuid obtained
   InvocationID obtained
   dnsHostname obtained
   site info obtained
   All the info for the server collected
   * Identifying all NC cross-refs.

   * Found 2 DC(s). Testing 1 of them.

   Done gathering initial info.


Doing initial required tests


   Testing server: Default-First-Site-Name\PRIMARYDC

      Starting test: Connectivity

         * Active Directory LDAP Services Check
         Determining IP4 connectivity 
         * Active Directory RPC Services Check
         ......................... PRIMARYDC passed test Connectivity



Doing primary tests


   Testing server: Default-First-Site-Name\PRIMARYDC

      Starting test: Advertising

         The DC PRIMARYDC is advertising itself as a DC and having a DS.
         The DC PRIMARYDC is advertising as an LDAP server
         The DC PRIMARYDC is advertising as having a writeable directory
         The DC PRIMARYDC is advertising as a Key Distribution Center
         The DC PRIMARYDC is advertising as a time server
         The DS PRIMARYDC is advertising as a GC.
         ......................... PRIMARYDC passed test Advertising

      Test omitted by user request: CheckSecurityError

      Test omitted by user request: CutoffServers

      Starting test: FrsEvent

         * The File Replication Service Event log test 
         There are warning or error events within the last 24 hours after the

         SYSVOL has been shared.  Failing SYSVOL replication problems may cause

         Group Policy problems. 
         A warning event occurred.  EventID: 0x800034C8

            Time Generated: 03/06/2014   10:18:56

            Event String:

            The File Replication Service has detected an enabled disk write cache on the drive containing the directory c:\windows\ntfrs\jet on the computer PRIMARYDC. The File Replication Service might not recover when power to the drive is interrupted and critical updates are lost.

         A warning event occurred.  EventID: 0x800034C8

            Time Generated: 03/06/2014   10:53:21

            Event String:

            The File Replication Service has detected an enabled disk write cache on the drive containing the directory c:\windows\ntfrs\jet on the computer PRIMARYDC. The File Replication Service might not recover when power to the drive is interrupted and critical updates are lost.

         ......................... PRIMARYDC passed test FrsEvent

      Starting test: DFSREvent

         The DFS Replication Event Log. 
         Skip the test because the server is running FRS.

         ......................... PRIMARYDC passed test DFSREvent

      Starting test: SysVolCheck

         * The File Replication Service SYSVOL ready test 
         File Replication Service's SYSVOL is ready 
         ......................... PRIMARYDC passed test SysVolCheck

      Starting test: KccEvent

         * The KCC Event log test
         Found no KCC errors in "Directory Service" Event log in the last 15 minutes.
         ......................... PRIMARYDC passed test KccEvent

      Starting test: KnowsOfRoleHolders

         Role Schema Owner = CN=NTDS Settings,CN=SECONDAD,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com
         Role Domain Owner = CN=NTDS Settings,CN=SECONDAD,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com
         Role PDC Owner = CN=NTDS Settings,CN=SECONDAD,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com
         Role Rid Owner = CN=NTDS Settings,CN=SECONDAD,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com
         Role Infrastructure Update Owner = CN=NTDS Settings,CN=SECONDAD,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com
         ......................... PRIMARYDC passed test KnowsOfRoleHolders

      Starting test: MachineAccount

         Checking machine account for DC PRIMARYDC on DC PRIMARYDC.
         * SPN found :LDAP/PRIMARYDC.Qtit.com/Qtit.com
         * SPN found :LDAP/PRIMARYDC.Qtit.com
         * SPN found :LDAP/PRIMARYDC
         * SPN found :LDAP/PRIMARYDC.Qtit.com/QTIT
         * SPN found :LDAP/e3d8c76c-1b59-4de6-9f7f-c438df9a2863._msdcs.Qtit.com
         * SPN found :E3514235-4B06-11D1-AB04-00C04FC2DCD2/e3d8c76c-1b59-4de6-9f7f-c438df9a2863/Qtit.com
         * SPN found :HOST/PRIMARYDC.Qtit.com/Qtit.com
         * SPN found :HOST/PRIMARYDC.Qtit.com
         * SPN found :HOST/PRIMARYDC
         * SPN found :HOST/PRIMARYDC.Qtit.com/QTIT
         * SPN found :GC/PRIMARYDC.Qtit.com/Qtit.com
         ......................... PRIMARYDC passed test MachineAccount

      Starting test: NCSecDesc

         * Security Permissions check for all NC's on DC PRIMARYDC.
         The forest is not ready for RODC. Will skip checking ERODC ACEs.
         * Security Permissions Check for

           DC=ForestDnsZones,DC=Qtit,DC=com
            (NDNC,Version 3)
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have 

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=ForestDnsZones,DC=Qtit,DC=com
         * Security Permissions Check for

           DC=DomainDnsZones,DC=Qtit,DC=com
            (NDNC,Version 3)
         Error NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS doesn't have 

            Replicating Directory Changes In Filtered Set
         access rights for the naming context:

         DC=DomainDnsZones,DC=Qtit,DC=com
         * Security Permissions Check for

           CN=Schema,CN=Configuration,DC=Qtit,DC=com
            (Schema,Version 3)
         * Security Permissions Check for

           CN=Configuration,DC=Qtit,DC=com
            (Configuration,Version 3)
         * Security Permissions Check for

           DC=Qtit,DC=com
            (Domain,Version 3)
         ......................... PRIMARYDC failed test NCSecDesc

      Starting test: NetLogons

         * Network Logons Privileges Check
         Verified share \\PRIMARYDC\netlogon
         Verified share \\PRIMARYDC\sysvol
         ......................... PRIMARYDC passed test NetLogons

      Starting test: ObjectsReplicated

         PRIMARYDC is in domain DC=Qtit,DC=com
         Checking for CN=PRIMARYDC,OU=Domain Controllers,DC=Qtit,DC=com in domain DC=Qtit,DC=com on 1 servers
            Object is up-to-date on all servers.
         Checking for CN=NTDS Settings,CN=PRIMARYDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com in domain CN=Configuration,DC=Qtit,DC=com on 1 servers
            Object is up-to-date on all servers.
         ......................... PRIMARYDC passed test ObjectsReplicated

      Test omitted by user request: OutboundSecureChannels

      Starting test: Replications

         * Replications Check
         * Replication Latency Check
            DC=ForestDnsZones,DC=Qtit,DC=com
               Latency information for 18 entries in the vector were ignored.
                  18 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            DC=DomainDnsZones,DC=Qtit,DC=com
               Latency information for 18 entries in the vector were ignored.
                  18 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            CN=Schema,CN=Configuration,DC=Qtit,DC=com
               Latency information for 20 entries in the vector were ignored.
                  20 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            CN=Configuration,DC=Qtit,DC=com
               Latency information for 20 entries in the vector were ignored.
                  20 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
            DC=Qtit,DC=com
               Latency information for 20 entries in the vector were ignored.
                  20 were retired Invocations.  0 were either: read-only replicas and are not verifiably latent, or dc's no longer replicating this nc.  0 had no latency information (Win2K DC).  
         * Replication Site Latency Check 
         ......................... PRIMARYDC passed test Replications

      Starting test: RidManager

         * Available RID Pool for the Domain is 14607 to 1073741823
         * SecondAD.Qtit.com is the RID Master
         * DsBind with RID Master was successful
         * rIDAllocationPool is 14107 to 14606
         * rIDPreviousAllocationPool is 14107 to 14606
         * rIDNextRID: 14124
         ......................... PRIMARYDC passed test RidManager

      Starting test: Services

         * Checking Service: EventSystem
         * Checking Service: RpcSs
         * Checking Service: NTDS
         * Checking Service: DnsCache
         * Checking Service: NtFrs
         * Checking Service: IsmServ
         * Checking Service: kdc
         * Checking Service: SamSs
         * Checking Service: LanmanServer
         * Checking Service: LanmanWorkstation
         * Checking Service: w32time
         * Checking Service: NETLOGON
         ......................... PRIMARYDC passed test Services

      Starting test: SystemLog

         * The System Event log test
         A warning event occurred.  EventID: 0x0000A001

            Time Generated: 03/06/2014   16:04:05

            Event String:

            The Security System could not establish a secured connection with the server ldap/PRIMARYDC.Qtit.com/Qtit.com@QTIT.COM. No authentication protocol was available.

         An error event occurred.  EventID: 0x0000041F

            Time Generated: 03/06/2014   16:06:35

            Event String:

            The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 

            a) Name Resolution failure on the current domain controller. 

            b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

         An error event occurred.  EventID: 0x0000041F

            Time Generated: 03/06/2014   16:11:36

            Event String:

            The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 

            a) Name Resolution failure on the current domain controller. 

            b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

         An error event occurred.  EventID: 0x0000041F

            Time Generated: 03/06/2014   16:16:38

            Event String:

            The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 

            a) Name Resolution failure on the current domain controller. 

            b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

         An error event occurred.  EventID: 0x0000041F

            Time Generated: 03/06/2014   16:21:39

            Event String:

            The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 

            a) Name Resolution failure on the current domain controller. 

            b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

         An error event occurred.  EventID: 0x0000041F

            Time Generated: 03/06/2014   16:26:41

            Event String:

            The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 

            a) Name Resolution failure on the current domain controller. 

            b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

         An error event occurred.  EventID: 0x00000457

            Time Generated: 03/06/2014   16:30:46

            Event String:

            Driver TOSHIBA e-STUDIO16/20/25 PCL 6 required for printer TOSHIBA e-STUDIO16/20/25 PCL 6 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 03/06/2014   16:30:48

            Event String:

            Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 03/06/2014   16:30:49

            Event String:

            Driver Send to Microsoft OneNote 15 Driver required for printer Send To OneNote 2013 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 03/06/2014   16:31:14

            Event String:

            Driver Send to Microsoft OneNote 15 Driver required for printer Send To OneNote 2013 is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 03/06/2014   16:31:16

            Event String:

            Driver Microsoft XPS Document Writer v4 required for printer Microsoft XPS Document Writer is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x00000457

            Time Generated: 03/06/2014   16:31:16

            Event String:

            Driver WebEx Document Loader required for printer WebEx Document Loader is unknown. Contact the administrator to install the driver before you log in again.

         An error event occurred.  EventID: 0x0000041F

            Time Generated: 03/06/2014   16:31:42

            Event String:

            The processing of Group Policy failed. Windows could not resolve the computer name. This could be caused by one of more of the following: 

            a) Name Resolution failure on the current domain controller. 

            b) Active Directory Replication Latency (an account created on another domain controller has not replicated to the current domain controller).

         ......................... PRIMARYDC failed test SystemLog

      Test omitted by user request: Topology

      Test omitted by user request: VerifyEnterpriseReferences

      Starting test: VerifyReferences

         The system object reference (serverReference)

         CN=PRIMARYDC,OU=Domain Controllers,DC=Qtit,DC=com and backlink on

         CN=PRIMARYDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com

         are correct. 
         The system object reference (serverReferenceBL)

         CN=PRIMARYDC,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=Qtit,DC=com

         and backlink on

         CN=NTDS Settings,CN=PRIMARYDC,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=Qtit,DC=com

         are correct. 
         The system object reference (frsComputerReferenceBL)

         CN=PRIMARYDC,CN=Domain System Volume (SYSVOL share),CN=File Replication Service,CN=System,DC=Qtit,DC=com

         and backlink on CN=PRIMARYDC,OU=Domain Controllers,DC=Qtit,DC=com are

         correct. 
         ......................... PRIMARYDC passed test VerifyReferences

      Test omitted by user request: VerifyReplicas


      Test omitted by user request: DNS

      Test omitted by user request: DNS


   Running partition tests on : ForestDnsZones

      Starting test: CheckSDRefDom

         ......................... ForestDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... ForestDnsZones passed test

         CrossRefValidation


   Running partition tests on : DomainDnsZones

      Starting test: CheckSDRefDom

         ......................... DomainDnsZones passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... DomainDnsZones passed test

         CrossRefValidation


   Running partition tests on : Schema

      Starting test: CheckSDRefDom

         ......................... Schema passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Schema passed test CrossRefValidation


   Running partition tests on : Configuration

      Starting test: CheckSDRefDom

         ......................... Configuration passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Configuration passed test CrossRefValidation


   Running partition tests on : Qtit

      Starting test: CheckSDRefDom

         ......................... Qtit passed test CheckSDRefDom

      Starting test: CrossRefValidation

         ......................... Qtit passed test CrossRefValidation


   Running enterprise tests on : Qtit.com

      Test omitted by user request: DNS

      Test omitted by user request: DNS

      Starting test: LocatorCheck

         GC Name: \\PRIMARYDC.Qtit.com

         Locator Flags: 0xe00031fc
         PDC Name: \\SecondAD.Qtit.com
         Locator Flags: 0xe00001bd
         Time Server Name: \\PRIMARYDC.Qtit.com
         Locator Flags: 0xe00031fc
         Preferred Time Server Name: \\PRIMARYDC.Qtit.com
         Locator Flags: 0xe00031fc
         KDC Name: \\PRIMARYDC.Qtit.com
         Locator Flags: 0xe00031fc
         ......................... Qtit.com passed test LocatorCheck

      Starting test: Intersite

         Skipping site Default-First-Site-Name, this site is outside the scope

         provided by the command line arguments provided. 
         ......................... Qtit.com passed test Intersite

***********************************************************

repadmin /showrepl Result




******************************8

==== INBOUND NEIGHBORS ===================================

DC=Qtit,DC=com
    Default-First-Site-Name\SECONDAD via RPC
        DSA object GUID: c5ef6e17-77f0-43f6-8d39-5497c563f
        Last attempt @ 2014-03-06 16:41:04 was successful.

CN=Configuration,DC=Qtit,DC=com
    Default-First-Site-Name\SECONDAD via RPC
        DSA object GUID: c5ef6e17-77f0-43f6-8d39-5497c563f
        Last attempt @ 2014-03-06 16:41:39 was successful.

CN=Schema,CN=Configuration,DC=Qtit,DC=com
    Default-First-Site-Name\SECONDAD via RPC
        DSA object GUID: c5ef6e17-77f0-43f6-8d39-5497c563f
        Last attempt @ 2014-03-06 15:53:01 was successful.

DC=DomainDnsZones,DC=Qtit,DC=com
    Default-First-Site-Name\SECONDAD via RPC
        DSA object GUID: c5ef6e17-77f0-43f6-8d39-5497c563f
        Last attempt @ 2014-03-06 16:27:31 was successful.

DC=ForestDnsZones,DC=Qtit,DC=com
    Default-First-Site-Name\SECONDAD via RPC
        DSA object GUID: c5ef6e17-77f0-43f6-8d39-5497c563f
        Last attempt @ 2014-03-06 15:53:01 was successful.
*******************************

I try to down the DC 2003 and access \\Qtit.com it success open the syslog on DC 2008

Any help or advice 












Viewing all articles
Browse latest Browse all 19997

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>