I have security event log errors on my domain controllers ever since bringing Exchange
2000 into our enterprise. A little background - single domain, single site, win2k SP3,
native mode. Exchange 2k SP2 - moved mailboxes from an Exchange 5.5 box and followed
the steps to remove the first exchange server. Exchange 5.5 was uninstalled from the
old server, but the box itself remains as a DC on the network.
The errors occur every minute for 15 minutes, every 4 hours, exactly when one of the
RUS runs. When the RUS was "Always Run" so were the errors. There are 2 RUS entries,
one updates all the time and works fine (Recipient Update Service (Athena)). The other
runs every four hours and produces 15 errors per pop (Recipient Update Service
(Enterprise Configuration)). Do I really need two of these? Is there anyway to see
what exactly is in the individual RUS?
Thanks for your help.
Tim Hooks, MCSE
Columbus, OH
Here is the error message:
Event Type: Failure Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 565
Date: 11/12/2002
Time: 7:05:21 AM
User: ATHENA\ARIES$
Computer: HERMES
Description:
Object Open:
Object Server: DS
Object Type: configuration
Object Name: CN=Configuration,DC=inside,DC=kbhr,DC=com
New Handle ID: -
Operation ID: {0,1638256139}
Process ID: 296
Primary User Name: HERMES$
Primary Domain: ATHENA
Primary Logon ID: (0x0,0x3E7)
Client User Name: ARIES$
Client Domain: ATHENA
Client Logon ID: (0x0,0x61A5CDFF)
Accesses Control Access
Privileges -
Properties:
READ_CONTROL
Create Child
Delete Child
List Contents
Write Self
Delete Tree
Manage Replication Topology
_________________________________________________________________
List posting FAQ: http://www.swinc.com/resource/exch_faq.htm
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe: mailto:leave-exchange@;ls.swynk.com
Exchange List admin: [EMAIL PROTECTED]