User A's profile on PC01 was created "fresh" while on PC02 it was migrated when PC02 was joined to the domain. The fix was changing the DNS settings to point to a Win2k DNS which was tied into Active Directory. using cached information 11/03 03:39:59 [MISC] DsGetDcName function returns 0: Dom:MFK Acct:(null) Flags: DS WRITABLE RET_DNS 0

I started to get this event on an SBS 2003 server every hour or so after I changed the domain administrator's password. Check the following areas for possible self-send configuration errors: 1) Forwarders list. (DNS servers should not forward to themselves). 2) Master lists of secondary zones. 3) Notify lists. Do you have more than one DC? Have you checked for layer 1 issues between the two clients and the server(s)?

If the problem persists, please contact your domain administrator. I've tried unjoining the domain, clearing stored passwords and re-joining, which seems to work for a bit, but it doesn't hold. Regarding DNS; the DNS activity log on the DC has 20 entries from this month talking about packets to and from itself with various URLs. When registration was attempted I got the "Security System could not establish a secured connection with the server DNS/".

  • This resulted in no name lookup for the Active Directory Domain and hence could not contact any Domain Controllers.
  • I guess if that particular client goes off mark in one direction and the server in another that might cause problems, though why would it reconnect and all be well, hmm...
  • Right-click the Domain and select Properties. 3.

This is sometimes mistakenly misconfigured by network administrators, either by using other subblocks of the 192/8 network for private addresses, or by blocking the whole of 192/8 at the router. I should mention there was a problem with external NTP servers beeing unresponsive and the server clock going off mark pretty quickly. using cached information 11/03 04:43:26 [MISC] DsGetDcName function returns 0: Dom:MFK Acct:(null) Flags: 11/03 04:43:27 [MISC] DsrEnumerateDomainTrusts: Called, Flags = 0x3 11/03 04:43:27 [MISC] DsrEnumerateDomainTrusts: returns: 0 11/03 04:43:33 [MISC] DsGetDcName

DomainGuid:ae248820-dd3e-48f7-8b3f-fb3ab6c4e384 11/03 03:35:38 [MISC] DsGetDcName function called: Dom:MFK.ATLAS Acct:(null) Flags: IP KDC 11/03 03:35:38 [LOGON] NlSetForestTrustList: New trusted domain list: 11/03 03:35:38 [LOGON] 0: MFK mfk.atlas (NT 5) (Forest. This event only occured on XP clients. See ME824217 to troubleshoot this problem.

Event ID: 40691 Type: Warning Source: LSASRV Category: SPNEGO (Negotiator) Description: The Security System could not establish a secured connection with the server ldap/. With SP2, default is 1465.

Open a command prompt and type net time /setsntp: .

Clear cached credentials. 2003 - Control Panel, Stored User Names and Passwords, Remove them all. What is an authentication protocol? Reset Secure channel netdom resetpwd /server:another domain controller /userd:domain\administrator /passwordd:administrator password. Also purge kerberos tickets using "klist purge", reboot the DC and check.

DomainGuid:ae248820-dd3e-48f7-8b3f-fb3ab6c4e384 11/03 04:43:18 [LOGON] NlSetForestTrustList: New trusted domain list: 11/03 04:43:18 [LOGON] 0: MFK mfk.atlas (NT 5) (Forest Tree Root) (Primary Domain) (Native) 11/03 04:43:18 [LOGON] From a newsgroup post: "In my case, this error occurred because the credentials specified in my DHCP server on DC1 for dynamic DNS registration were misspelled". Microsoft article ME259922 describes a situation in which this event occurs.

Apparently the workstation could no longer locate SVR records for the kerberos authentication server. Windows XP SP2 was getting application Event IDs 4226, 40961, 40960 for one end user only.

I was getting this error along with EventID 40960 from source LsaSrv and EventID 1006 from source Userenv. But after this, internet is getting disconnected in these systems. In my case, the server referenced in the event description was an external DNS server from my ISP. using cached information 11/03 04:27:02 [MISC] DsGetDcName function returns 0: Dom:(null) Acct:(null) Flags: RET_DNS 11/03 04:27:16 [MISC] DsGetDcName function called: Dom:(null) Acct:(null) Flags: DS 11/03 04:27:16 [MISC] NetpDcGetName: mfk.atlas.

At the same time as the 1030 event was generated, a corresponding Event 40960 and 40961 from source LsaSrv was generated in the System Log. Netlogon debugging provided concrete info to work from. End User was able to logon to the domain but the domain account would then get locked out right away.