From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rimmerman, Russ
Sent: Thursday, October 14, 2004 11:47 AM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] Still troubleshooting, still no resolution
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mulnick, Al
Sent: Thursday, October 14, 2004 10:36 AM
To: [EMAIL PROTECTED]
Subject: RE: [ActiveDir] Still troubleshooting, still no resolution
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rimmerman, Russ
Sent: Thursday, October 14, 2004 11:20 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Still troubleshooting, still no resolution
10/4/2004 10:29:11 AM LSASRV Warning SPNEGO (Negotiator) 40960 N/A CESVPL50835 "The Security System detected an attempted downgrade attack for server ldap/ccc.ourdomain.com. The failure code from authentication protocol Kerberos was ""There are currently no logon servers available to service the logon request.
(0xc000005e)""."
The Directory Service consistency checker has noticed that 12 successive replication attempts with CN=NTDS Settings,CN=CAMDHQDC02,CN=Servers,CN=CAM-DHQ,CN=Sites,CN=Configuration,DC=ourdomain,DC=com have failed over a period of 132 minutes. The connection object for this server will be kept in place, and new temporary connections will established to ensure that replication continues. The Directory Service will continue to retry replication with CN=NTDS Settings,CN=CAMDHQDC02,CN=Servers,CN=CAM-DHQ,CN=Sites,CN=Configuration,DC=ourdomain,DC=com; once successful the temporary connection will be removed.
All servers in site CN=CAM-DHQ,CN=Sites,CN=Configuration,DC=ourdomain,DC=com that can replicate partition DC=ccc,DC=coopcam,DC=com over transport CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=ourdomain,DC=com are currently unavailable.
The Directory Service consistency checker has determined that either (a) there is not enough physical connectivity published via the Active Directory Sites and Services Manager to create a spanning tree connecting all the sites containing the Partition DC=ourdomain,DC=com, or (b) replication cannot be performed with one or more critical servers in order for changes to propagate across all sites (most often due to the servers being unreachable).
For (a), please use the Active Directory Sites and Services Manager to do one of the following:
1. Publish sufficient site connectivity information such that the system can infer a route by which this Partition can reach this site. This option is preferred.
2. Add an ntdsConnection object to a Domain Controller that contains the Partition DC=ourdomain,DC=com in this site from a Domain Controller that contains the same Partition in another site.
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This e-mail is confidential, may contain proprietary information of the Cooper Cameron Corporation and its operating Divisions and may be confidential or privileged. This e-mail should be read, copied, disseminated and/or used only by the addressee. If you have received this message in error please delete it, together with any attachments, from your system. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This e-mail is confidential, may contain proprietary information of the Cooper Cameron Corporation and its operating Divisions and may be confidential or privileged. This e-mail should be read, copied, disseminated and/or used only by the addressee. If you have received this message in error please delete it, together with any attachments, from your system. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
