Exchange System Attendant will not start

A

Andrew Fields

(I posted this to multiple NGs since I had errors in: ADS, DNS,
Exchange2000)

I have an SBS2000 Server (SP4) running ADS, with Exchange 2000 (SP3).
When I try to launch the Microsoft System Attendant, I get the errors in the
Application Log (attached below).

I have looked at DNS as well as ADS; DNS has an issue in that if I
stop/restart netlogon, the <GUID>._msdcs.chc.local entry is an alias to
"chc01." instead of "chc01.chc.local". I have tried numerous changes to the
TCP/IP configuration and *none* have caused it to behave as I would expect.

I'm hoping someone will see something I have missed. I attached as much
data as possible so you wouldn't have to waste time asking me to post more,
however, if I didn't post what you need, let me know and I will post it.

Thanks in advance.

Andrew D. Fields
(e-mail address removed)

<BEGIN APP LOG>
Source: MSExchangeDSAccess
Category: LDAP
EventID: 2110
Description:
Process INETINFO.EXE (PID=1236). Could not bind to DS server CHC01, error 52
at port 389.

For more information, click http://www.microsoft.com/contentredirect.asp.

Source: MSExchangeDSAccess
Category: Topology
EventID: 2102
Description:
Process INETINFO.EXE (PID=1236). All Domain Controller Servers in use are
not responding:
CHC01


Source: MSExchangeDSAccess
Category: Topology
EventID: 2080
Description:
Process INETINFO.EXE (PID=1236). DSAccess has discovered the following
servers with the following characteristics:
(Server name | Roles | Reachability | Synchronized | GC capable | PDC | SACL
right | Critical Data | Netlogon)
In-site:
CHC01 CDG 7 0 1 1 0 1 0
Out-of-site:
<END APP LOG>



**In Addition, when DNS launches, I get the following:
<BEGIN DNS LOG>
Source: DNS
Category: None
EventID: 414
Description:
The DNS server machine currently has no DNS domain name. Its DNS name is a
single label hostname with no domain (example: "host" rather than
"host.microsoft.com").

You might have forgotten to configure a primary DNS domain for the server
computer. For more information, see either "DNS server log reference" or "To
configure the primary DNS suffix for a client computer" in the online Help.

While the DNS server has only a single label name, all zones created will
have default records (SOA and NS) created using only this single label name
for the server's hostname. This can lead to incorrect and failed referrals
when clients and other DNS servers use these records to locate this server
by name.

To correct this problem:
1) open ControlPanel
2) open System applet
3) select NetworkIdentification tab
4) click the "Properties" button and enter a domain name or workgroup name;
this name will be used as your DNS domain name
5) reboot to initialize with new domain name

After reboot, the DNS server will attempt to fix up default records,
substituting new DNS name of this server, for old single label name.
However, you should review to make sure zone's SOA and NS records now
properly use correct domain name of this server.
<END DNS LOG>

In addition, I have the following entries in the ADS Log:
<BEGIN ADS Log>
Source: NTDS Replication
Category: Replication
Event ID: 1411
Description:
The Directory Service failed to construct a mutual authentication Service
Principal Name (SPN) for server CHC01. The call is denied. The error was:
A Service Principal Name (SPN) could not be constructed because the provided
hostname is not in the necessary format.

The record data is the status code.


Source: NTDS General
Category: Global Catalog
Event ID: 1655
Description:
The attempt to communicate with global catalog \\CHC01 failed with the
following status:

A Service Principal Name (SPN) could not be constructed because the provided
hostname is not in the necessary format.

The operation in progress might be unable to continue. The directory
service will use the locator to try find an available global catalog server
for the next operation that requires one.

The record data is the status code.


Source: NTDS General
Category: Global Catalog
Event ID: 1126
Description:
Unable to establish connection with global catalog.

<END ADS Log>

Following is an unedited ipconfig / all
<BEGIN ipconfig /all>
D:\SW\Apps\Utils>ipconfig /all

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : CHC01
Primary DNS Suffix . . . . . . . : CHC.Local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : CHC.Local

Ethernet adapter LAN - INT - Linksys:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Linksys LNE100TX(v5) Fast
Ethernet A
dapter
Physical Address. . . . . . . . . : 00-04-5A-82-AF-7E
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2

Ethernet adapter WAN - EXT - Onboard:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/100 VM Network
Connecti
on
Physical Address. . . . . . . . . : 00-03-47-CC-A7-B5
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 66.182.23.146
Subnet Mask . . . . . . . . . . . : 255.255.255.248
Default Gateway . . . . . . . . . : 66.182.23.145
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2
<END ipconfig /all>

Following is netdiag output:
<BEGIN netdiag>
D:\SW\Apps\Utils>netdiag

...........................................

Computer Name: CHC01
DNS Host Name: CHC01
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 1 Stepping 2, GenuineIntel
List of installed hotfixes :
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : LAN - INT - Linksys

Netcard queries test . . . : Passed

Host Name. . . . . . . . . :
IP Address . . . . . . . . : 10.0.0.2
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . :
Primary WINS Server. . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.2


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Passed

Adapter : WAN - EXT - Onboard

Netcard queries test . . . : Passed

Host Name. . . . . . . . . :
IP Address . . . . . . . . : 66.182.23.146
Subnet Mask. . . . . . . . : 255.255.255.248
Default Gateway. . . . . . : 66.182.23.145
Primary WINS Server. . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.2


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
'Messenge
r Service', <20> 'WINS' names is missing.
No remote names have been found.

WINS service test. . . . . : Passed


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the
name
'CHC01.CHC.Local.'. [RCODE_SERVER_FAILURE]
The name 'CHC01.CHC.Local.' may not be registered in DNS.
[WARNING] The DNS entries for this DC are not registered correctly on DNS
se
rver '10.0.0.2'. Please wait for 30 minutes for DNS server replication.
[FATAL] No DNS servers have the DNS records for this DC registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Failed
[WARNING] The default SPN registration for 'HOST/CHC01' is missing on DC
'CH
C01'.
[FATAL] The default SPNs are not properly registered on any DCs.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.


The command completed successfully
<END netdiag>

Following is my dcdiag output
<BEGIN dcdiag>
D:\SW\Apps\Utils>dcdiag

DC Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial non skippeable tests

Testing server: Default-First-Site-Name\CHC01
Starting test: Connectivity
*** Warning: could not confirm the identity of this server in
the directory versus the names returned by DNS servers.
If there are problems accessing this directory server then
you may need to check that this server is correctly registered
with DNS
......................... CHC01 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\CHC01
Starting test: Replications
......................... CHC01 passed test Replications
Starting test: NCSecDesc
......................... CHC01 passed test NCSecDesc
Starting test: NetLogons
......................... CHC01 passed test NetLogons
Starting test: Advertising
......................... CHC01 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... CHC01 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... CHC01 passed test RidManager
Starting test: MachineAccount
......................... CHC01 passed test MachineAccount
Starting test: Services
......................... CHC01 passed test Services
Starting test: ObjectsReplicated
......................... CHC01 passed test ObjectsReplicated
Starting test: frssysvol
......................... CHC01 passed test frssysvol
Starting test: kccevent
An Error Event occured. EventID: 0xC0000583
Time Generated: 09/26/2003 09:57:07
Event String: The Directory Service failed to construct a
An Warning Event occured. EventID: 0x80000677
Time Generated: 09/26/2003 09:57:07
Event String: The attempt to communicate with global catalog
An Error Event occured. EventID: 0xC0000466
Time Generated: 09/26/2003 09:57:07
Event String: Unable to establish connection with global
......................... CHC01 failed test kccevent
Starting test: systemlog
......................... CHC01 passed test systemlog

Running enterprise tests on : CHC.Local
Starting test: Intersite
......................... CHC.Local passed test Intersite
Starting test: FsmoCheck
......................... CHC.Local passed test FsmoCheck
<END dcdiag>
 
C

Crazy

In
Andrew Fields said:
(I posted this to multiple NGs since I had errors in: ADS, DNS,
Exchange2000)

I have an SBS2000 Server (SP4) running ADS, with Exchange 2000 (SP3).
When I try to launch the Microsoft System Attendant, I get the errors
in the Application Log (attached below).

I have looked at DNS as well as ADS; DNS has an issue in that if I
stop/restart netlogon, the <GUID>._msdcs.chc.local entry is an alias
to "chc01." instead of "chc01.chc.local". I have tried numerous
changes to the TCP/IP configuration and *none* have caused it to
behave as I would expect.

I'm hoping someone will see something I have missed. I attached as
much data as possible so you wouldn't have to waste time asking me to
post more, however, if I didn't post what you need, let me know and I
will post it.

Thanks in advance.

Andrew D. Fields
(e-mail address removed)

<BEGIN APP LOG>
Source: MSExchangeDSAccess
Category: LDAP
EventID: 2110
Description:
Process INETINFO.EXE (PID=1236). Could not bind to DS server CHC01,
error 52 at port 389.

For more information, click
http://www.microsoft.com/contentredirect.asp.

Source: MSExchangeDSAccess
Category: Topology
EventID: 2102
Description:
Process INETINFO.EXE (PID=1236). All Domain Controller Servers in use
are not responding:
CHC01


Source: MSExchangeDSAccess
Category: Topology
EventID: 2080
Description:
Process INETINFO.EXE (PID=1236). DSAccess has discovered the following
servers with the following characteristics:
(Server name | Roles | Reachability | Synchronized | GC capable | PDC
| SACL right | Critical Data | Netlogon)
In-site:
CHC01 CDG 7 0 1 1 0 1 0
Out-of-site:
<END APP LOG>



**In Addition, when DNS launches, I get the following:
<BEGIN DNS LOG>
Source: DNS
Category: None
EventID: 414
Description:
The DNS server machine currently has no DNS domain name. Its DNS
name is a single label hostname with no domain (example: "host"
rather than "host.microsoft.com").

You might have forgotten to configure a primary DNS domain for the
server computer. For more information, see either "DNS server log
reference" or "To configure the primary DNS suffix for a client
computer" in the online Help.

While the DNS server has only a single label name, all zones created
will have default records (SOA and NS) created using only this single
label name for the server's hostname. This can lead to incorrect and
failed referrals when clients and other DNS servers use these records
to locate this server by name.

To correct this problem:
1) open ControlPanel
2) open System applet
3) select NetworkIdentification tab
4) click the "Properties" button and enter a domain name or
workgroup name; this name will be used as your DNS domain name
5) reboot to initialize with new domain name

After reboot, the DNS server will attempt to fix up default records,
substituting new DNS name of this server, for old single label name.
However, you should review to make sure zone's SOA and NS records now
properly use correct domain name of this server.
<END DNS LOG>

In addition, I have the following entries in the ADS Log:
<BEGIN ADS Log>
Source: NTDS Replication
Category: Replication
Event ID: 1411
Description:
The Directory Service failed to construct a mutual authentication
Service Principal Name (SPN) for server CHC01. The call is denied.
The error was: A Service Principal Name (SPN) could not be
constructed because the provided hostname is not in the necessary
format.

The record data is the status code.


Source: NTDS General
Category: Global Catalog
Event ID: 1655
Description:
The attempt to communicate with global catalog \\CHC01 failed with the
following status:

A Service Principal Name (SPN) could not be constructed because the
provided hostname is not in the necessary format.

The operation in progress might be unable to continue. The directory
service will use the locator to try find an available global catalog
server for the next operation that requires one.

The record data is the status code.


Source: NTDS General
Category: Global Catalog
Event ID: 1126
Description:
Unable to establish connection with global catalog.

<END ADS Log>

Following is an unedited ipconfig / all
<BEGIN ipconfig /all>
D:\SW\Apps\Utils>ipconfig /all

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : CHC01
Primary DNS Suffix . . . . . . . : CHC.Local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : CHC.Local

Ethernet adapter LAN - INT - Linksys:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Linksys LNE100TX(v5) Fast
Ethernet A
dapter
Physical Address. . . . . . . . . : 00-04-5A-82-AF-7E
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2

Ethernet adapter WAN - EXT - Onboard:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/100 VM Network
Connecti
on
Physical Address. . . . . . . . . : 00-03-47-CC-A7-B5
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 66.182.23.146
Subnet Mask . . . . . . . . . . . : 255.255.255.248
Default Gateway . . . . . . . . . : 66.182.23.145
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2
<END ipconfig /all>

Following is netdiag output:
<BEGIN netdiag>
D:\SW\Apps\Utils>netdiag

..........................................

Computer Name: CHC01
DNS Host Name: CHC01
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 1 Stepping 2, GenuineIntel
List of installed hotfixes :
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : LAN - INT - Linksys

Netcard queries test . . . : Passed

Host Name. . . . . . . . . :
IP Address . . . . . . . . : 10.0.0.2
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . :
Primary WINS Server. . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.2


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Passed

Adapter : WAN - EXT - Onboard

Netcard queries test . . . : Passed

Host Name. . . . . . . . . :
IP Address . . . . . . . . : 66.182.23.146
Subnet Mask. . . . . . . . : 255.255.255.248
Default Gateway. . . . . . : 66.182.23.145
Primary WINS Server. . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.2


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
'Messenge
r Service', <20> 'WINS' names is missing.
No remote names have been found.

WINS service test. . . . . : Passed


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for
the name
'CHC01.CHC.Local.'. [RCODE_SERVER_FAILURE]
The name 'CHC01.CHC.Local.' may not be registered in DNS.
[WARNING] The DNS entries for this DC are not registered correctly
on DNS se
rver '10.0.0.2'. Please wait for 30 minutes for DNS server
replication. [FATAL] No DNS servers have the DNS records for this
DC registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Failed
[WARNING] The default SPN registration for 'HOST/CHC01' is missing
on DC 'CH
C01'.
[FATAL] The default SPNs are not properly registered on any DCs.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.


The command completed successfully
<END netdiag>

Following is my dcdiag output
<BEGIN dcdiag>
D:\SW\Apps\Utils>dcdiag

DC Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial non skippeable tests

Testing server: Default-First-Site-Name\CHC01
Starting test: Connectivity
*** Warning: could not confirm the identity of this server
in the directory versus the names returned by DNS
servers. If there are problems accessing this directory
server then you may need to check that this server is
correctly registered with DNS
......................... CHC01 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\CHC01
Starting test: Replications
......................... CHC01 passed test Replications
Starting test: NCSecDesc
......................... CHC01 passed test NCSecDesc
Starting test: NetLogons
......................... CHC01 passed test NetLogons
Starting test: Advertising
......................... CHC01 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... CHC01 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... CHC01 passed test RidManager
Starting test: MachineAccount
......................... CHC01 passed test MachineAccount
Starting test: Services
......................... CHC01 passed test Services
Starting test: ObjectsReplicated
......................... CHC01 passed test ObjectsReplicated
Starting test: frssysvol
......................... CHC01 passed test frssysvol
Starting test: kccevent
An Error Event occured. EventID: 0xC0000583
Time Generated: 09/26/2003 09:57:07
Event String: The Directory Service failed to construct a
An Warning Event occured. EventID: 0x80000677
Time Generated: 09/26/2003 09:57:07
Event String: The attempt to communicate with global
catalog An Error Event occured. EventID: 0xC0000466
Time Generated: 09/26/2003 09:57:07
Event String: Unable to establish connection with global
......................... CHC01 failed test kccevent
Starting test: systemlog
......................... CHC01 passed test systemlog

Running enterprise tests on : CHC.Local
Starting test: Intersite
......................... CHC.Local passed test Intersite
Starting test: FsmoCheck
......................... CHC.Local passed test FsmoCheck
<END dcdiag>

Your ipconfig /all looks OK do you have a forward lookup zone for CHC.local
and is "Allow dynamic updates" set to "Yes" on the zone?

In ADUC is CHC.local the domain name that appears there?
 
M

Matjaz Ladava [MVP]

On external LAN clear your DNS entries as there is no point of pointing them
to your internal DNS server. In your NIC binding order check, that your
internal NIC is listed first.

--
Regards

Matjaz Ladava, MCSE (NT4 & 2000), Windows MVP
(e-mail address removed)
http://ladava.com

Andrew Fields said:
(I posted this to multiple NGs since I had errors in: ADS, DNS,
Exchange2000)

I have an SBS2000 Server (SP4) running ADS, with Exchange 2000 (SP3).
When I try to launch the Microsoft System Attendant, I get the errors in the
Application Log (attached below).

I have looked at DNS as well as ADS; DNS has an issue in that if I
stop/restart netlogon, the <GUID>._msdcs.chc.local entry is an alias to
"chc01." instead of "chc01.chc.local". I have tried numerous changes to the
TCP/IP configuration and *none* have caused it to behave as I would expect.

I'm hoping someone will see something I have missed. I attached as much
data as possible so you wouldn't have to waste time asking me to post more,
however, if I didn't post what you need, let me know and I will post it.

Thanks in advance.

Andrew D. Fields
(e-mail address removed)

<BEGIN APP LOG>
Source: MSExchangeDSAccess
Category: LDAP
EventID: 2110
Description:
Process INETINFO.EXE (PID=1236). Could not bind to DS server CHC01, error 52
at port 389.

For more information, click http://www.microsoft.com/contentredirect.asp.

Source: MSExchangeDSAccess
Category: Topology
EventID: 2102
Description:
Process INETINFO.EXE (PID=1236). All Domain Controller Servers in use are
not responding:
CHC01


Source: MSExchangeDSAccess
Category: Topology
EventID: 2080
Description:
Process INETINFO.EXE (PID=1236). DSAccess has discovered the following
servers with the following characteristics:
(Server name | Roles | Reachability | Synchronized | GC capable | PDC | SACL
right | Critical Data | Netlogon)
In-site:
CHC01 CDG 7 0 1 1 0 1 0
Out-of-site:
<END APP LOG>



**In Addition, when DNS launches, I get the following:
<BEGIN DNS LOG>
Source: DNS
Category: None
EventID: 414
Description:
The DNS server machine currently has no DNS domain name. Its DNS name is a
single label hostname with no domain (example: "host" rather than
"host.microsoft.com").

You might have forgotten to configure a primary DNS domain for the server
computer. For more information, see either "DNS server log reference" or "To
configure the primary DNS suffix for a client computer" in the online Help.

While the DNS server has only a single label name, all zones created will
have default records (SOA and NS) created using only this single label name
for the server's hostname. This can lead to incorrect and failed referrals
when clients and other DNS servers use these records to locate this server
by name.

To correct this problem:
1) open ControlPanel
2) open System applet
3) select NetworkIdentification tab
4) click the "Properties" button and enter a domain name or workgroup name;
this name will be used as your DNS domain name
5) reboot to initialize with new domain name

After reboot, the DNS server will attempt to fix up default records,
substituting new DNS name of this server, for old single label name.
However, you should review to make sure zone's SOA and NS records now
properly use correct domain name of this server.
<END DNS LOG>

In addition, I have the following entries in the ADS Log:
<BEGIN ADS Log>
Source: NTDS Replication
Category: Replication
Event ID: 1411
Description:
The Directory Service failed to construct a mutual authentication Service
Principal Name (SPN) for server CHC01. The call is denied. The error was:
A Service Principal Name (SPN) could not be constructed because the provided
hostname is not in the necessary format.

The record data is the status code.


Source: NTDS General
Category: Global Catalog
Event ID: 1655
Description:
The attempt to communicate with global catalog \\CHC01 failed with the
following status:

A Service Principal Name (SPN) could not be constructed because the provided
hostname is not in the necessary format.

The operation in progress might be unable to continue. The directory
service will use the locator to try find an available global catalog server
for the next operation that requires one.

The record data is the status code.


Source: NTDS General
Category: Global Catalog
Event ID: 1126
Description:
Unable to establish connection with global catalog.

<END ADS Log>

Following is an unedited ipconfig / all
<BEGIN ipconfig /all>
D:\SW\Apps\Utils>ipconfig /all

Windows 2000 IP Configuration

Host Name . . . . . . . . . . . . : CHC01
Primary DNS Suffix . . . . . . . : CHC.Local
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : CHC.Local

Ethernet adapter LAN - INT - Linksys:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Linksys LNE100TX(v5) Fast
Ethernet A
dapter
Physical Address. . . . . . . . . : 00-04-5A-82-AF-7E
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 10.0.0.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . :
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2

Ethernet adapter WAN - EXT - Onboard:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel(R) PRO/100 VM Network
Connecti
on
Physical Address. . . . . . . . . : 00-03-47-CC-A7-B5
DHCP Enabled. . . . . . . . . . . : No
IP Address. . . . . . . . . . . . : 66.182.23.146
Subnet Mask . . . . . . . . . . . : 255.255.255.248
Default Gateway . . . . . . . . . : 66.182.23.145
DNS Servers . . . . . . . . . . . : 10.0.0.2
Primary WINS Server . . . . . . . : 10.0.0.2
<END ipconfig /all>

Following is netdiag output:
<BEGIN netdiag>
D:\SW\Apps\Utils>netdiag

..........................................

Computer Name: CHC01
DNS Host Name: CHC01
System info : Windows 2000 Server (Build 2195)
Processor : x86 Family 15 Model 1 Stepping 2, GenuineIntel
List of installed hotfixes :
Q147222


Netcard queries test . . . . . . . : Passed



Per interface results:

Adapter : LAN - INT - Linksys

Netcard queries test . . . : Passed

Host Name. . . . . . . . . :
IP Address . . . . . . . . : 10.0.0.2
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . :
Primary WINS Server. . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.2


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Skipped
[WARNING] No gateways defined for this adapter.

NetBT name test. . . . . . : Passed

WINS service test. . . . . : Passed

Adapter : WAN - EXT - Onboard

Netcard queries test . . . : Passed

Host Name. . . . . . . . . :
IP Address . . . . . . . . : 66.182.23.146
Subnet Mask. . . . . . . . : 255.255.255.248
Default Gateway. . . . . . : 66.182.23.145
Primary WINS Server. . . . : 10.0.0.2
Dns Servers. . . . . . . . : 10.0.0.2


AutoConfiguration results. . . . . . : Passed

Default gateway test . . . : Passed

NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03>
'Messenge
r Service', <20> 'WINS' names is missing.
No remote names have been found.

WINS service test. . . . . : Passed


Global results:


Domain membership test . . . . . . : Passed


NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
1 NetBt transport currently configured.


Autonet address test . . . . . . . : Passed


IP loopback ping test. . . . . . . : Passed


Default gateway test . . . . . . . : Passed


NetBT name test. . . . . . . . . . : Passed


Winsock test . . . . . . . . . . . : Passed


DNS test . . . . . . . . . . . . . : Failed
[WARNING] Cannot find a primary authoritative DNS server for the
name
'CHC01.CHC.Local.'. [RCODE_SERVER_FAILURE]
The name 'CHC01.CHC.Local.' may not be registered in DNS.
[WARNING] The DNS entries for this DC are not registered correctly on DNS
se
rver '10.0.0.2'. Please wait for 30 minutes for DNS server replication.
[FATAL] No DNS servers have the DNS records for this DC registered.


Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
The redir is bound to 1 NetBt transport.

List of NetBt transports currently bound to the browser
NetBT_Tcpip_{D8627DC1-4AD3-41ED-86BF-C28350893871}
The browser is bound to 1 NetBt transport.


DC discovery test. . . . . . . . . : Passed


DC list test . . . . . . . . . . . : Passed


Trust relationship test. . . . . . : Skipped


Kerberos test. . . . . . . . . . . : Passed


LDAP test. . . . . . . . . . . . . : Failed
[WARNING] The default SPN registration for 'HOST/CHC01' is missing on DC
'CH
C01'.
[FATAL] The default SPNs are not properly registered on any DCs.


Bindings test. . . . . . . . . . . : Passed


WAN configuration test . . . . . . : Skipped
No active remote access connections.


Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
IPSec policy service is active, but no policy is assigned.


The command completed successfully
<END netdiag>

Following is my dcdiag output
<BEGIN dcdiag>
D:\SW\Apps\Utils>dcdiag

DC Diagnosis

Performing initial setup:
Done gathering initial info.

Doing initial non skippeable tests

Testing server: Default-First-Site-Name\CHC01
Starting test: Connectivity
*** Warning: could not confirm the identity of this server in
the directory versus the names returned by DNS servers.
If there are problems accessing this directory server then
you may need to check that this server is correctly registered
with DNS
......................... CHC01 passed test Connectivity

Doing primary tests

Testing server: Default-First-Site-Name\CHC01
Starting test: Replications
......................... CHC01 passed test Replications
Starting test: NCSecDesc
......................... CHC01 passed test NCSecDesc
Starting test: NetLogons
......................... CHC01 passed test NetLogons
Starting test: Advertising
......................... CHC01 passed test Advertising
Starting test: KnowsOfRoleHolders
......................... CHC01 passed test KnowsOfRoleHolders
Starting test: RidManager
......................... CHC01 passed test RidManager
Starting test: MachineAccount
......................... CHC01 passed test MachineAccount
Starting test: Services
......................... CHC01 passed test Services
Starting test: ObjectsReplicated
......................... CHC01 passed test ObjectsReplicated
Starting test: frssysvol
......................... CHC01 passed test frssysvol
Starting test: kccevent
An Error Event occured. EventID: 0xC0000583
Time Generated: 09/26/2003 09:57:07
Event String: The Directory Service failed to construct a
An Warning Event occured. EventID: 0x80000677
Time Generated: 09/26/2003 09:57:07
Event String: The attempt to communicate with global catalog
An Error Event occured. EventID: 0xC0000466
Time Generated: 09/26/2003 09:57:07
Event String: Unable to establish connection with global
......................... CHC01 failed test kccevent
Starting test: systemlog
......................... CHC01 passed test systemlog

Running enterprise tests on : CHC.Local
Starting test: Intersite
......................... CHC.Local passed test Intersite
Starting test: FsmoCheck
......................... CHC.Local passed test FsmoCheck
<END dcdiag>
 
A

Andrew Fields

Kevin:
Yes, "Allow dynamic updates" is set to "Yes"
Yes, in ADUC "CHC.local" is the domain that appears there.

Andrew.
 
A

Andrew Fields

Matjaz:

I removed the DNS entry on the Externan NIC (not sure what that will
change since if it is missing it will default to the internal NIC
anyway...but I removed it).

I had already checked, and the binding order of the NICs is in the order
listed by ipconfig /all; Internal first, External second.

Any other thoughts?

Andrew.
 
M

Matjaz Ladava [MVP]

Hmm. The error is caused by something blocking port 389 on your server which
is used for clients to connect to Active Directory. Can you verify, that
there is no other application using port 389 ? Use tcpmon from
www.sysinternals.com to see which process is using this port.

--
Regards

Matjaz Ladava, MCSE (NT4 & 2000), Windows MVP
(e-mail address removed)
http://ladava.com
 
A

Andrew Fields

Matjaz:

The process running on port 389 is: LSASS.exe
My understanding is that that is what is *supposed* to run on port 389.

Thoughts?

Andrew.
 
K

Kevin Goodknecht

In
Andrew Fields said:
Kevin:
Yes, "Allow dynamic updates" is set to "Yes"
Yes, in ADUC "CHC.local" is the domain that appears there.

Andrew.

Are the Blank host records in the gc folder under the _msdcs folder of your
CHC.local Forward Lookup zone?
You do have a CHC.local forward lookup zone?
This is on a DC correct?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top