Both domain controllers are running windows 2003 SP1 server and replicate fine, all these problems are with XP client machines running SP2
DC1 holds all FSMO roles and DC1 and 2 are both GC's
The Problem:
Dis-join and join XP client to the domain, first logon is fine, run rsop.msc and all GP settings are applied, events in eventvwr are all good.
Then i restart and on pretty much all XP machines i get Event ID 1054
Event ID: 1054
Source: Userenv
Type: Error
Description:
Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted). Group Policy processing aborted.
So to try resolve this i have done the dollowing
I ran DCDIAG on DC1 and everything passed apart from the Sytem log,, see below error:
Starting test: systemlog
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:48:20
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:48:21
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:48:22
(Event String could not be retrieved)
I ran DCDIAG on DC2 and everything apart from the Sytem log,, see below error:
Starting test: systemlog
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:13:23
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:13:24
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:13:25
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:42:34
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:42:35
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:42:36
(Event String could not be retrieved)
Ran NETDIAG on both domain controllers, all result passed.
Checked SMB Signing, "Digitally sign communications (always) Policy Setting:" was set to disabled as a MAC OSX wouldn't see server otherwise.
I have now set this back to not defined. so all my SMB signing is set back to defaults, see below.
Workstation/Client Microsoft network client:
Digitally sign communications (always) Policy
Setting: not defined
Microsoft network client: Digitally sign
communications (if server agrees) Policy Setting:
not defined Effective Setting: enabled (because of
local policy)
Server
Microsoft network server: Digitally sign
communications (always) Policy Setting: enabled
Microsoft network server: Digitally sign
communications (if client agrees) Policy Setting:
enabled
DNS config is as follows:
DC1
IP Address. . . . . . . . . . . 10.10.10.1
Subnet Mask . . . . . . . . . . 255.255.255.0
Default Gateway . . . . . . . . 10.10.10.34
DNS Servers . . . . . . . . . . 10.10.10.2
10.10.10.1
DC2
IP Address. . . . . . . . . . . 10.10.10.2
Subnet Mask . . . . . . . . . . 255.255.255.0
Default Gateway . . . . . . . . 10.10.10.34
DNS Servers . . . . . . . . . . 10.10.10.1
10.10.10.2
All XP clients have 10.10.10.2 as preffered DNS and 10.10.10.1 as secondary. I have tried switching this but this didn't help.
I have also configured a GPO with 'Always wait for Network at computer startup and logon' and linked this to an OU containing my test workstations and this ddn't help.
I have upgraded NIC drivers.
Replaced Network cable - rebooted the Cisco 2950 switch. Havn't tried a new NIC yet.
I am about to check permissions on the SYSVOL to see if permissions on 'Authenticated users' is correct, i will update the post with the results.
Any feedback on this will be welcomed as it's doing my ead in now.
DC1 holds all FSMO roles and DC1 and 2 are both GC's
The Problem:
Dis-join and join XP client to the domain, first logon is fine, run rsop.msc and all GP settings are applied, events in eventvwr are all good.
Then i restart and on pretty much all XP machines i get Event ID 1054
Event ID: 1054
Source: Userenv
Type: Error
Description:
Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted). Group Policy processing aborted.
So to try resolve this i have done the dollowing
I ran DCDIAG on DC1 and everything passed apart from the Sytem log,, see below error:
Starting test: systemlog
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:48:20
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:48:21
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:48:22
(Event String could not be retrieved)
I ran DCDIAG on DC2 and everything apart from the Sytem log,, see below error:
Starting test: systemlog
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:13:23
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:13:24
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:13:25
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:42:34
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:42:35
(Event String could not be retrieved)
An Error Event occured. EventID: 0x00000457
Time Generated: 04/05/2006 09:42:36
(Event String could not be retrieved)
Ran NETDIAG on both domain controllers, all result passed.
Checked SMB Signing, "Digitally sign communications (always) Policy Setting:" was set to disabled as a MAC OSX wouldn't see server otherwise.
I have now set this back to not defined. so all my SMB signing is set back to defaults, see below.
Workstation/Client Microsoft network client:
Digitally sign communications (always) Policy
Setting: not defined
Microsoft network client: Digitally sign
communications (if server agrees) Policy Setting:
not defined Effective Setting: enabled (because of
local policy)
Server
Microsoft network server: Digitally sign
communications (always) Policy Setting: enabled
Microsoft network server: Digitally sign
communications (if client agrees) Policy Setting:
enabled
DNS config is as follows:
DC1
IP Address. . . . . . . . . . . 10.10.10.1
Subnet Mask . . . . . . . . . . 255.255.255.0
Default Gateway . . . . . . . . 10.10.10.34
DNS Servers . . . . . . . . . . 10.10.10.2
10.10.10.1
DC2
IP Address. . . . . . . . . . . 10.10.10.2
Subnet Mask . . . . . . . . . . 255.255.255.0
Default Gateway . . . . . . . . 10.10.10.34
DNS Servers . . . . . . . . . . 10.10.10.1
10.10.10.2
All XP clients have 10.10.10.2 as preffered DNS and 10.10.10.1 as secondary. I have tried switching this but this didn't help.
I have also configured a GPO with 'Always wait for Network at computer startup and logon' and linked this to an OU containing my test workstations and this ddn't help.
I have upgraded NIC drivers.
Replaced Network cable - rebooted the Cisco 2950 switch. Havn't tried a new NIC yet.
I am about to check permissions on the SYSVOL to see if permissions on 'Authenticated users' is correct, i will update the post with the results.
Any feedback on this will be welcomed as it's doing my ead in now.