Strange things with a domain user account/domain computer account

M

Micke Alvmarken

Hi,

I have a strange problem:

When I try to login to our domain with my domain user
account it takes forever to logon. When I finally get in
the following entries appears in the event log:
Source: LSASRV
Category: SPNEGO
Event-ID: 40961
Details:
The security system could not make a protected connection
to the server LDAP/servername.domain.
No authentication protocol was available.
(I have translated freely from swedish. Swedish original
follows)

Säkerhetssystemet kunde inte upprätta en skyddad
anslutning till servern LDAP/servernamn.domän.
Inget autentiseringsprotokoll var tillgängligt.

And the following entry:
Source: LSASRV
Category: SPNEGO
Event-ID: 40960
Details:
The security system discovered an attempt to a downgrade
attack for the server LDAP/servername.domain
The error code generated from the authentication protocol
Kerberos was "There are no login servers available that
could administer the login request.(0xc000005e)".

(Again freely translated from swedish. Swedish original
follows)
Säkerhetssystemet upptäckte ett försök till en
nedgraderingsattack för servern LDAP/servernamn.domän Den
felkod som erhölls från autentiseringsprotokollet
Kerberos var "Det finns för närvarande inte några
inloggningsservrar tillgängliga som kan hantera
inloggningsförfrågan.
(0xc000005e)".

I cannot use any resources from within the domain.
I do not receive any group policy settings.

If I logon with a different domain user account on my
computer everything works fine.

If I logon with the problem domain user account on any
other computer everything works fine.

I copied the problem domain user account to a new domain
user account (with all the group memberships and other
settings intact) and tried to logon and the same problems
occured.

I created a whole new domain user account and added the
same group memberships and other settings manually and
logged on and everything worked fine.

I deleted the domain user profile (on my computer) in
case the profile was corrupted and tried to logon, still
having the same problems.

We have a windows 2000 server SP4 as a domain controller.
I run windows XP Pro SP1 on my computer.

Does anyone have any clues to what's wrong?

I'm confused!
Thanks in advance

/Michael
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top