- Server 2003 DC, boot up, slow to find domain
- Posted by Keith on January 17th, 2006
I have a domain controller, newly built, Windows 2003 SP1, that takes a
long time to find the domain after boot up. It's a domain controller,
but doesn't hold any FSMO roles (I have two DC's total.) Whenever I
reboot it, I get a number of errors in the Event Logs that indicate it
cannot locate the domain (the same domain that it is a DC in!), and I
can't log into the machine for about 5-10 minutes for the same reason
(cannot locate a domain controller.)
After it's up for a while, it seems to work fine. Here are some of the
errors:
__________________________________________________ ___________
Event Type: Error
Event Source: CertSvc
Event Category: None
Event ID: 44
Date: 1/17/2006
Time: 10:28:46 AM
User: N/A
Computer: DC03
Description:
The "Windows default" Policy Module "Initialize" method returned an
error. The specified domain either does not exist or could not be
contacted. The returned status code is 0x8007054b (1355). The Active
Directory containing the Certification Authority could not be
contacted.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
__________________________________________________ ____________
Event Type: Error
Event Source: Winlogon
Event Category: None
Event ID: 1219
Date: 1/17/2006
Time: 10:31:22 AM
User: N/A
Computer: DC03
Description:
Logon rejected for PRIDEDALLAS\Administrator. Unable to obtain Terminal
Server User Configuration. Error: The specified domain either does not
exist or could not be contacted.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 4b 05 00 00 K...
__________________________________________________ ___________________
Event Type: Warning
Event Source: NETLOGON
Event Category: None
Event ID: 5781
Date: 1/17/2006
Time: 10:34:11 AM
User: N/A
Computer: DC03
Description:
Dynamic registration or deletion of one or more DNS records associated
with DNS domain 'pridedallas.com.' failed. These records are used by
other computers to locate this server as a domain controller (if the
specified domain is an Active Directory domain) or as an LDAP server
(if the specified domain is an application partition).
Possible causes of failure include:
- TCP/IP properties of the network connections of this computer contain
wrong IP address(es) of the preferred and alternate DNS servers
- Specified preferred and alternate DNS servers are not running
- DNS server(s) primary for the records to be registered is not running
- Preferred or alternate DNS servers are configured with wrong root
hints
- Parent DNS zone contains incorrect delegation to the child zone
authoritative for the DNS records that failed registration
USER ACTION
Fix possible misconfiguration(s) specified above and initiate
registration or deletion of the DNS records by running 'nltest.exe
/dsregdns' from the command prompt or by restarting Net Logon service.
Nltest.exe is available in the Microsoft Windows Server Resource Kit
CD.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: b4 05 00 00 ´...
__________________________________________________ ____________________
Event Type: Error
Event Source: DhcpServer
Event Category: None
Event ID: 1059
Date: 1/17/2006
Time: 10:30:08 AM
User: N/A
Computer: DC03
Description:
The DHCP service failed to see a directory server for authorization.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 3a 20 00 00 :...
__________________________________________________ _____________
Event Type: Error
Event Source: Print
Event Category: None
Event ID: 33
Date: 1/17/2006
Time: 10:30:07 AM
User: SYSTEM
Computer: DC03
Description:
The PrintQueue Container could not be found because the DNS Domain name
could not be retrieved. Error: 54b
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
- Posted by Danny Sanders on January 17th, 2006
What IPaddress/Computer does this DC point to for DNS?
hth
DDS W 2k MVP MCSE
"Keith" <laurin1@osai.com> wrote in message
news:1137515879.091213.38100@g43g2000cwa.googlegro ups.com...
I have a domain controller, newly built, Windows 2003 SP1, that takes a
long time to find the domain after boot up. It's a domain controller,
but doesn't hold any FSMO roles (I have two DC's total.) Whenever I
reboot it, I get a number of errors in the Event Logs that indicate it
cannot locate the domain (the same domain that it is a DC in!), and I
can't log into the machine for about 5-10 minutes for the same reason
(cannot locate a domain controller.)
After it's up for a while, it seems to work fine. Here are some of the
errors:
__________________________________________________ ___________
Event Type: Error
Event Source: CertSvc
Event Category: None
Event ID: 44
Date: 1/17/2006
Time: 10:28:46 AM
User: N/A
Computer: DC03
Description:
The "Windows default" Policy Module "Initialize" method returned an
error. The specified domain either does not exist or could not be
contacted. The returned status code is 0x8007054b (1355). The Active
Directory containing the Certification Authority could not be
contacted.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
__________________________________________________ ____________
Event Type: Error
Event Source: Winlogon
Event Category: None
Event ID: 1219
Date: 1/17/2006
Time: 10:31:22 AM
User: N/A
Computer: DC03
Description:
Logon rejected for PRIDEDALLAS\Administrator. Unable to obtain Terminal
Server User Configuration. Error: The specified domain either does not
exist or could not be contacted.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 4b 05 00 00 K...
__________________________________________________ ___________________
Event Type: Warning
Event Source: NETLOGON
Event Category: None
Event ID: 5781
Date: 1/17/2006
Time: 10:34:11 AM
User: N/A
Computer: DC03
Description:
Dynamic registration or deletion of one or more DNS records associated
with DNS domain 'pridedallas.com.' failed. These records are used by
other computers to locate this server as a domain controller (if the
specified domain is an Active Directory domain) or as an LDAP server
(if the specified domain is an application partition).
Possible causes of failure include:
- TCP/IP properties of the network connections of this computer contain
wrong IP address(es) of the preferred and alternate DNS servers
- Specified preferred and alternate DNS servers are not running
- DNS server(s) primary for the records to be registered is not running
- Preferred or alternate DNS servers are configured with wrong root
hints
- Parent DNS zone contains incorrect delegation to the child zone
authoritative for the DNS records that failed registration
USER ACTION
Fix possible misconfiguration(s) specified above and initiate
registration or deletion of the DNS records by running 'nltest.exe
/dsregdns' from the command prompt or by restarting Net Logon service.
Nltest.exe is available in the Microsoft Windows Server Resource Kit
CD.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: b4 05 00 00 ´...
__________________________________________________ ____________________
Event Type: Error
Event Source: DhcpServer
Event Category: None
Event ID: 1059
Date: 1/17/2006
Time: 10:30:08 AM
User: N/A
Computer: DC03
Description:
The DHCP service failed to see a directory server for authorization.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 3a 20 00 00 :...
__________________________________________________ _____________
Event Type: Error
Event Source: Print
Event Category: None
Event ID: 33
Date: 1/17/2006
Time: 10:30:07 AM
User: SYSTEM
Computer: DC03
Description:
The PrintQueue Container could not be found because the DNS Domain name
could not be retrieved. Error: 54b
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
- Posted by Keith on January 17th, 2006
It's own IP (192.168.0.9)
- Posted by Danny Sanders on January 17th, 2006
You indicated that you have another DC in the domain. What IP
address/computer does it point to for DNS?
You should point it to the DNS server you set up for the domain. It would
appear that since you are adding this server to an existing domain, this is
*not* the DNS server set up for the AD domain.
hth
DDS W 2k MVP MCSE
"Keith" <laurin1@osai.com> wrote in message
news:1137517421.175539.163430@o13g2000cwo.googlegr oups.com...
- Posted by Keith on January 17th, 2006
It's not the PDC, no, but all the documentation i've read says point
that if the DC is also DNS, to point it to itself.
- Posted by Keith on January 17th, 2006
I mean, it's not the DC i used to set up the domain, no. Though it was
the first DC I upgraded to Server 2003. Also, don't think it's related,
but I have another strange problem with this server. I use this server
for some disk based backups, which have worked fine until a few days
ago. Now, anytime I copy large files to this machine over the network,
I get write delay errors. The files fail to transfer and the machine
i'm copying from tells me there is a problem with the network/hardware.
I've tested this from two machines and the results are the same (i've
tested regular file transfers as well.) The server iself reports no
errors, nothing in the event logs to indicate disk or network issues.
- Posted by Danny Sanders on January 17th, 2006
You indicated that you have another DC in the domain. What IP
address/computer does it point to for DNS?
DDS
"Keith" <laurin1@osai.com> wrote in message
news:1137528271.553296.42090@g44g2000cwa.googlegro ups.com...
- Posted by Keith on January 17th, 2006
It's own 192.168.0.2
- Posted by Danny Sanders on January 17th, 2006
What happens when you point the "new" server to this IP address for DNS?
DDS
"Keith" <laurin1@osai.com> wrote in message
news:1137539535.520601.182750@g49g2000cwa.googlegr oups.com...
- Posted by Keith on January 18th, 2006
That seems to work, except if the primary is offline, i now get DNS
problems.