Posts

Showing posts from June, 2014

Sleep no more?

hi guys, i had running win2008 x86 since few months ago. some time ago instaled x64, , fine, except can't seem enable sleep state more. running powercfg.exe /a got this: the following sleep states are not available on this system:   standby (s1)       the system firmware does not support this standby state.       an internal system component has disabled this standby state.   standby (s2)       the system firmware does not support this standby state.       an internal system component has disabled this standby state.   standby (s3)       an internal system component has disabled this standby state.   hibernate       an internal system component has disabled hibernation.   hybrid sleep   so, no information. for several different reasons i'd have sleep available. and hibernation usefull ups. do guys know can start looking? can hyper-v responsible this behaviour? can x64 responsible this behaviour? is there way fix / wor

Windows Server Essentials 2012 - Locked out

so have built server our small business. installed copy of windows server essentials 2012 , started connect different computers in office. running smooth, , found myself locked out ! doing software installation required me run windows in safe mode edit file. went msconfig , set computer restart in safe mode. once computer booted , safe mode login screen , proceeded key in password. have tried multiple times login , keeps saying username or password incorrect. dose have idea how have happen ? need server host quickbooks file. there 4 other workstations connecting it. don'tthink need connect computers sever far profile management or fancy. please advise.   Windows Server  >  Security

Unable to create folder on mapping drive(error access denied)

i having problem when create folder on mapping drive.(error access denied) please refer below. i have 1 unit server running on windows 2003 , 1 unit windows xp. now problem when remotely map server d: driver partition was successful(after key in local admin user name , password).but unable create any folder @ d: drive partition. (error not have permission access denied)    if using remote desktop server using same user name , password create folder @ d: drive successful without , error.  below few step had bee try(but still having problem) map same server c: driver partition (after key in local admin user name , password) create folder @ mapping drive was successful. format d: driver partition.  delete partition , recreate partition  add security permission to everyone full control at d: driver partition. fyi. user local administrator user name , password perform mapping drive , remote desktop. please on this.....many thank..... hi, you mentioned add

How can you disabled the Server 2008 "Application hung" screen?

we have old legacy app used on terminal services, , hosted on server 2003.  now we've migrated server 2008 r2 , because it's old app, has no progress bar or similar when it's doing things , on server 2003 sit there until it's finished.  with server 2008 however, after few seconds displays white, translucent "application hung" screen , prompting terminate or wait, causing problems because users think it's crashed whereas thought slow.  can disable white hang screen , go how pre-2008? hi, how windows detect application hang: when application (or more accurately, thread) creates window on desktop, enters implicit contract desktop window manager (dwm) process window messages in timely fashion. dwm posts messages (keyboard/mouse input , messages other windows, itself) thread-specific message queue. thread retrieves , dispatches messages via message queue. if thread not service queue calling getmessage(), messages not processed, , window hangs: can

How do I make a different server the PDC/AD DS/ FSMO role holder?

this small network has windows server 2003 machine primary domain controller/active directory/ infrastructure operations master role holder, , windows server 2008 r2 machine acting file server (and application server, though not configured application server). want remove server 2003 machine network , use server 2008 r2 machine server. understand how far running adprep.exe, after need assistance. there written materials on how this, , if can point me them? thank you hi  you can find detail article migrate fsmo roles 2003 2008 https://support.microsoft.com/en-us/kb/324801 by way dont suggest file server role , aplication server on pdc(i think have o dc after migration) maybe install filer server , application role server. greetings Windows Server  >  Windows Server General Fo

How to Authenticate Lotus LDAP Directory in asp.net web Application

Image
dear all, have requirement authenticate web application using ldap authentication against lotus notes(not active directory). besides list of user ldap. i able list of users ldap using following class ldapconnection searchrequest  searchresponse  searchresultentrycollection  don't know how authenticate user ldap password. able validate user id. whether password can taken? how find encryption have used. kindly guide me on same. many suggest following code, not validating users' password rather user alone. password given in code used binding ldap directory.  public bool isauthenticated(string domain, string username, string pwd)     {       string domainandusername = domain + @"\" + username;       directoryentry entry = new directoryentry(_path, domainandusername, pwd);       try       {         //bind native adsobject force authentication.         object obj = entry.nativeobject;         directorysea

load a page from an internal netwok pc

hello please can instruct how can load page failed nps hra , location have type in remediation url hi,   thanks post.   it nps related problem; may consider posting new thread in our network infrastructure servers forum.   for convenience, have list link followed.   network infrastructure servers forum http://social.technet.microsoft.com/forums/en-us/winservernis/threads   hope helps. Windows Server  >  Group Policy

RDweb gives HTTP 404

hi guys! something strange happening right now, our rdweb can't accessed 1 server. i'll explain our setup first, guys can follow. we have 3 rds servers (tsa, tsb , tsc example) , 1 remoteapp server (tsapp example). tsa , tsc can access rdweb website of tsapp, tsb can't , gets "http 404 not found" error. did every stap same on other 2 rds server, tsb can't access it. , yes, using https connect rdweb. someone got idea? 1 giving me headaches >.< thanks! in meantine found out problem. our trainee made in windows firewall rule block access our rdweb, thought virus due fact certificate security warning.  thanks help! Windows Server  >  Remote Desktop Services (Terminal Services)

Emails not going to junkmail folder

hi, we have exhange 2007 sp3, mailbox role 1 server , cas&ht role in server, no edge. i run shell command-> set-organizationconfig -scljunkthreshold 5 content filter configured scl 9 delete, 8 reject , 6 qrtn. i using symantec mail security premium antispam installed , configured in ht server. emails receiving in users mailbox tagged spam , checked message source shown below, scl 7 ********************************************** from: dilbert <dilbert@email.dilbert.com> reply-to: dilbert <dilbert@email.dilbert.com> subject: spam dilbert.com - daily strip email message-id: <bcad12dd86b0c74960f4c1fa49388ea3@localhost.localdomain> x-priority: 3 x-mailer: phpmailer 5.1 (phpmailer.worxware.com) mime-version: 1.0 content-type: multipart/mixed; boundary="=_boundary_fifzcgwbi816xvcylr6x" x-tm-as-product-ver: csc-0-6.5.1024-18226 x-tm-as-result: yes-32.44-4.50-31-1 return-path: dilbert@email.dilbert.com x-brightmail-tracker:

DISM error attempting to run online upgrade from Windows Server 2008 R2 Enterprise to DataCenter

Image
i running following command on windows server 2008r2 c:\windows\system32>dism /online /set-edition:serverdatacenter /productkey:xxxxx-xxxxx-xxxxx-xxxxx-xxxxx i following error: deployment image servicing , management tool version: 6.1.7600.16385 image version: 6.1.7600.16385 error: 1605 the specified product key not valid target edition. run command again product key specific target edition. the dism log file can found @ c:\windows\logs\dism\dism.log the telling lines in dism.log are 2012-06-25 13:44:58, error                 dism   dism transmog provider: pid=2824 product key keyed [], user requested transmog [serverdatacenter] - ctransmogmanager::validatetransmogrify i called microsoft licensing , told me verified product key, , there nothing else can unless want pay server support. hi, i noticed error message not complete: 2012-06-25 13:44:58, error dism dism transmog provider: pid=2824 product key keyed [], user requested transmog [serverdatacente

Creating Tables...

i know simple, have never figured out... want create table custom column names. example: i want make list of users 3 columns: username         password                      addtoadmin fflintstone       somepassword              false brubble              someotherpass            true shouldn't able create custom table / list / array or hash of kind create this? i have 2 objectives. script needs self-contained. don't want script dependent on external file , want list of users easy @ in code itself. plan loop through list creating users  based on the fields each user (there more 3 columns / fields when done). by creating customobject $mycolumn = @{ name = 'user1'; password='password1'} new-object psobject -property $mycolumn | select name,password | ft -autosize name  password ----  -------- user1 password1 ------------------------------------------------------- to understand better...from username, password , addtoadmin values

DFS namespace and replication group

hi, i new dfs , setting dfs namespace , replication group on windows 2012 r2. i having question: if have namespace 'public' point c:\shareddata\ shared folder , has many sub folders . can create replication group replicate 1 or 2 sub folders other replication memebers? or have replicate whole 'shareddata' shared folder? thanks, chris dfs-replication independant dfs-namespace.  can choose replicate folder want. suppose have c:\shareddata , following subfolders: c:\shareddata\finance c:\shareddata\marketing c:\shareddata\rd c:\shareddata\production you decide synchronize c:\shareddata\finance , c:\shareddata\rd server has dfs-r feature installed. this posting provided without warranty of kind Windows Server  >  File Services and Storage

Windows 2012 RDS farm licensing

hi, we have built windows 2012 rds "farm" , have purchased 100 rds cals mpsa. would instruction need make 120 days warning goes away?  how apply license each rds host?  need on connection broker?  have file server holds roaming profile of user.  should not need apply cals it, right?  hi, on broker: 1. server manager -- rds -- overview, please install rd licensing via the rd licensing icon if haven't already. 2. server manager -- rds -- overview -- deployment overview -- tasks -- edit deployment properties -- rd licensing tab, make sure licensing mode set match type of rds cals own, , fqdn of rd licensing server shown in list (it should if installed in step #1) 3. in rd licensing manager (licmgr.exe), please activate server , install purchased rds cals.  a shortcut rd licensing manager may found on tools -- terminal services menu in server manager. 4. server manager -- rds -- collections, please make sure have created session collection(s) , rdsh serve

moving old server and contents to new box (hardware)

hello, all. i have not fast dell poweredge server bought thinking isnt. main domain controller , has profiles , user settings. horribly slow , giving me bad reputation system admin. so went out , bought core i7 system built scratch. setup windows server 2008r2 on , wanting make take other servers place. now in addition have box has tmg on it. tmg box part of domain. simple question: whats best method migrating old server new core i7 box.. i @ 1 point , still considering hyper-v. making core i-7 box dc , setting hyper-v tmg box. not sure on procedure. please ... if can out. thanks hi, i suggest deploy new server secondary dc , once deploy it, size fsmo roles primery dc new 1 while make primery dc. as file shares, may need re create them on new server manually. as core i7 processor, intel core series made desktops not servers. if want go server, intel has xeon range specially built that. there difference in both processor series. xeon design more powerful , robust

Site-Linked & User-Based GPO

hi all: i have hope quick question... i have gpo configures ie proxy settings, , i'm looking link each active directory site rather specific ous. given user-based policy, , site-linked policy applies machines within physical site, need use loopback/merge policy well? or can link user-based gpo site , expect apply correctly? thanks!   you don't need apply loopback processing have gpo applied correctly. " never panic before reboot ! " Windows Server  >  Group Policy

Hyper-V Lagecy Adapter error

hello, i add hyper-v rule (single nic) in win2008 r2, , created new vm. now when add lagecy adapter vm not getting start , through error "failed start virtual machine" if remove lagecy adapter work perfect. hi, what's os of vm? tell if there errors in event log of host server. besides, microsoft recommands avoid use legacy network adapter windows 2003 x64 or windows xp professional x64. driver missing legacy network card. regards, best regards don't forget mark answer if helps Windows Server  >  Hyper-V

Event Id 1006 Error 49

i see not 1 having issue.  added 2008r2 dc 2003 domain.  looks good. nslookup passes.  replicate seems work no problems.  following. "the processing of group policy failed. windows not authenticate active directory service on domain controller. (ldap bind function call failed). in details tab error code , description." log name: system source: group policy event id: 1006 level: error user: system opcode: (1) details:   - eventdata       supportinfo1 1     supportinfo2 5012     processingmode 0     processingtimeinmilliseconds 1170     errorcode 49 i saw 1 post fixed there host file.  thing in host file fi127.0.0.1.  can @ resolve issue   norman mattox hi,   we don’t need transfer roles new server now. when want remove 2003 dc, please remember transfer roles.   best regards, yan li forum support pl

The server do not boot without having the Win 2k8 DVD

hi group, first of i’ve apologize bad english. i’m writing germany. not have win srv 2k8 forums here…   ;-). maybe product new? after raid failure had change 1 hdd oft raid. raid rebuilt successfully, data fine. but way boot server is, have win 2k8 dvd in dvd-rom. now, familiar message appears: “press key boot cd …” if not win 2k8 starting well, can use server. if win 2k8 dvd absent, message: “insert proper boot device…” for me it’s sounds mbr missing or corrupt. (maybe mbr on changed hdd). in former times booted dvd “repair installation part” fix problem “fixmbr”. there option “repair installation”, if click on that, current win 2k8 partition known able select, tool tells: “you can use tool vista os …”. to leave dvd @ dvd rom server booting means me workaround. what have server boot without having dvd? how can fix mbr issue (is mbr issue?)? i’m not happy idea use “external mbr” tools. the configuration of machine is fujitsu siemens   primergy econel 200 s2, 8 gb ram,

Do we have support for Print Server failover cluster in Windows Server 2012

Image
hi, do have support print server failover cluster in windows server 2012, if yes service need use configuration. i'm aware of configuring print server failover cluster in windows server 2008 r2, i'm unable find print server cluster service in roles. do same kind of behaviour same in windows server 2008 r2 request 1 please provide me valuable information. thanks santosh base knowledge can . high availability printing overview install , configure high availability printing i n fact print server high availabilty story in 2012 changed , there no longer supported print spooler resource  print server cluster vm supported approach.  the print vendors no longer have write cluster aware software. here guide publish details.  understand , troubleshoot high availability printing in windows server "8" beta and see therad : server 2012 - redundant print server whenever see helpful reply, click on vote helpful & click on mark answer if

Install all patches via WSUS in one session

hello, i have 2 questions deploying patches via wsus. 1. there way have patches deployed during 1 session? as example, let's have au setup automatically download , install @ 11pm every night.  patches detected, downloaded , installed , good.  let's there other patches not detected until the new patches installed, not installed until next day @ 11pm.  there way have patches deployed in same window?  don't care if there multiple reboots, want patches deployed on same day. 2. there way schedule reboots (if required) specific time?  patches deployed @ 11pm want reboots (if needed) happen @ 2am. thanks angelo angelo 1. there way have patches deployed during 1 session? natural behavior of windows update, , has been since inception 14 years ago. there exceptions, of course, , associated exclusive updates available installation. these include operating system service packs, .net service packs, , occasional infrastructure update -- occur infrequently enough

how to see if a merge is pending?

hi, simple question: have vm not has snapshots defined anyore still working off differncing disk. my question how can see if hyper-v has merge pending? it's not indicated in status column of vm. other way see that? even if shut down vm merge not occur. can manually force so? thanks manually merge snapshots: http://itproctology.blogspot.com/2008/06/how-to-manually-merge-hyper-v-snapshots.html by way, way merge snapshot, power off vm, and it can sometime take 3 minutes before merge process starts. make sure have enough free storage process merge. kristian (virtualization , coffee: http://kristiannese.blogspot.com ) Windows Server  >  Hyper-V

BadLogonCount and LastBadPasswordAttempt

hi all, i can't seem find information on msdn these properties.  i trying find out mean , updates them etc. assume lastbadpasswordattempt user enters his/her username/password incorrectly.  but the badlogoncount property, causes counter increment one? updated when user fails incorrect user/pass 3 times or whatever ad set to?  here confusion: using get-aduser on selected user, return these 4 properties , data: badlogoncount          : 0 badpasswordtime       : 130231682532108088 badpwdcount             : 0 lastbadpasswordattempt : 9/09/2013 12:44:13 pm as can see, there bad password attempt on 9th of september, badlogoncount , badpwdcount both 0. can me understand these properties little or lot better? thank you!   im not sure documented exactly. below article explains bad-pwd-count attribute similar 1 talking about. also can set option no of bad password attempts id locked out in password policy. think option titled "account lockout thereshold&q

OneNote default notebook root to sharepoint site

is possible define default notebook root sharepoint site ? using administrative templates onenote , editing gpo, add setting documents path. we configure new notebooks added users stored default on sharepoint site , not on local system. hi shmuel, >>is possible define default notebook root sharepoint site ? based on description, in order better help, can ask suggestions in following community or sharepoint forums. ask onenote 2013 community http://support2.microsoft.com/ask-community/office/onenote/ sharepoint forums https://social.technet.microsoft.com/forums/office/en-us/home?category=sharepoint technet subscriber support if are  technet subscription  user , have feedback on our support quality, please send feedback  here . best regards, frank shen Windows Server  > 

NAP IPSEC:How Can I make Non-Windows Computers Access Internet?

Image
i want design nap ipsec manage windows computers in office lan. put tmg2010  in ipsec secure ou,the tmg2010  provide web proxy service access internet。but non-windows computers can't join domain,and not support nap。 how can make non-windows computers access internet? hi owlinrye, thanks posting here. so tmg set internet gateway in environment ? know can implement such restriction setting tmg rules or policy on (could restrict non-domain joined hosts). access design guide forefront tmg http://technet.microsoft.com/en-us/library/dd897017.aspx anyway, not expert of tmg , please post tmg forum in order professional responses : http://social.technet.microsoft.com/forums/en-us/forefrontedgegeneral/threads thanks. tiger li tiger li technet community support Windows Server  > 

Syncing files over VPN

i have windows 2003 standard file server. have site-to-site vpn setup between 4 offices using cisco routers. each user has home directory mapped server. i'm looking best way sync files documents folder home directory. way can keep backup in case of hard drive failure. hi, all home directory folders on windows 2003 standard file server, what's location of documents folders saved on? if in home directory, question sync subfolder in home directory hard disk backup. if true, may use folder redirection redirect users' my documents folders root folder, able replicated server using dfsr (or frs if not windows 2003 r2). shaon shan |technet subscriber support in forum |if have feedback on our support, please contact tngfb@microsoft.com Windows Server  >  File Services and Storage

Preffered and alternate DNS details

dear team,i have many dc/adc in domain , of course dns servers also.but noticed of dc  dns does't have correct preferred/alternate dns. there way through power shell or netsh in can know server in dns installed in domain along assigned preferred , alternate dns details.so can have bird's view. senior system engineer. hello kusuma, i found script on gallery fits needs: https://gallery.technet.microsoft.com/gather-dns-settings-from-fec23eaa best regards, sergio figueiredo microsoft certified solutions associate Windows Server  >  Directory Services

Powershell to Noob Translation?

hi all! i'm new powershell, , i've been tasked updating whole organizational unit new logins reflect new domain name. previous person did left script says: import-csv c:\uploadtest.csv | %{set-aduser $_.samaccountname -userprincipalname $_.userprincipal} while i've been able follow instructions prepare .csv, couldn't figure out script doing, wanted ask help! ps. i've reseached powershell class i'm going boss approve.  thanks much! hi tachc, import-csv c:\uploadtest.csv, commandlet importing uploadtest.csv file. "|" - call pipe. means pass information other commandlet "%" - stands foreach. alias. import-csv c:\uploadtest.csv | %{set-aduser $_.samaccountname -userprincipalname $_.userprincipal} so, here importing .csv file looping through amaccountname, userprincipal column or data passing through pipe. calling set-aduser comdlet modify iformation in ad. hope helps you. thanks, sabah shariq

I have installed Active Directory without DNS How can I integrate DNS with Active Directory ?

i have installed active directory without dns how can integrate dns active directory thaks george hello, if attempt to install dns role setup new ad-integrated zone on dc, please follow instruction provided sachin. if unclear, feel free follow us. otherwise, mean have dc dns server, convert existing primary dns zone ad-integrated zone? for windows server 2003 or windows server 2000, refer to: how convert dns primary server active directory integrated http://support.microsoft.com/kb/816101 windows server 2008 or windows server 2008 r2, can configure primary dns zone use ad ds. refer to: understanding active directory domain services integration http://technet.microsoft.com/en-us/library/cc726034.aspx thanks zhang Windows Server  >  Server Manager

favorites roaming

guys, i want users have favorites whatever browser use available @ every desktop log in. possible if enable roaming profiles or can folder redirection? regards, > want users have favorites whatever browser use > available @ every desktop log in. possible if i > enable roaming profiles or can folder redirection?   folder redirection works smooth internet explorer. firefox uses a database :)   check out xmarks...   martin mal ein gutes buch über gpos lesen? no not evil, if know doing: or bad gpos? , if bothers me - coke bottle design refreshment :)) Windows Server  >  Group Policy

The SIS status of this volume cannot be retrieved??

hello, we've been using windows storage server 2008 several months success. we've been using sis functions on our primary raid volume (12.7 tb in raid 6). this morning, noticed "enable sis on volume" option in "advanced" tab of volumes properties was grayed out. underneath, said "the sis status of volume cannot retrieved." in command prompt, running "sisadmin /v e:" returned: volume 'e:' not sis volume. also, trying initialize/install sis on volume in command prompt "sisadmin /i e:" returned: failed initialize sis on volume 'e:' (0x80041003)&#0; but, working great months! have happened? any thoughts? hi, check if groveler service user, "local system" has full controll on drive. open permission of e: , in case add local system , give full controll. try disable av, if doesn't help.   caddo       Window

Start Server 2008 recovery console from CD/DVD

dear all, does knows of way start recovery console cd/dvd? recovery console has not been installed on server. thanks in advanced... hello, please stick 1 thread: http://social.technet.microsoft.com/forums/en-us/winservergen/thread/ee7711b5-374a-4e33-97dc-3f25e7cee041 this posting provided "as is" no warranties or guarantees , , confers no rights.       microsoft student partner 2010 / 2011 microsoft certified professional microsoft certified systems administrator: security microsoft certified systems engineer: security microsoft certified technology specialist: windows server 2008 active directory, configuration microsoft certified technology specialist: windows server 2008 network infrastructure, configuration microsoft certified technology specialist: windows server 2008 applications infrastructure, configuration microsoft certified technology specialist: windows 7, configuring microsoft certified technology speciali

Remote Resource in RD Client for iPhone/iPad/Mac list the RemoteApps but unable to connect

when try connect through remote resource in rd client iphone/ipad/mac to connect remoteapp in windows server 2012 r2, establishing connection , see published apps in list. when click on app, gives me following error "the info_rail flag must set in flags field of info packet session on remote server can host remote applications (code remoteappsnotenabled(4339)) " can connect remoteapp windows remoteapp desktop connection , able open apps published in terminal server. , able connect web browser through rd web access. please suggest thanks hi, comment. sorry late response. please check selecting “bypass rd gateway server local address” in rd gateway manager , check result. please check this article . in addition, can check this article . hope helps! thanks. dharmesh solanki Windows Server  > 

GPOs for RD Users

we have windows 2008 r2 rdweb server, 2 window 2008 r2 rd servers remote apps. users go rdweb server run published apps. we have 1 app have run rdp app. starts rd session, users log rd server , run app i know how can set domain gpo(s) make sure when rdp app starts users can not doing following: 1. see control panel 2. see or run internet explorer 3. can select log off when completed also, don't want effect domain admins. thank you when say:  we have 1 app have run rdp app. i assuming not using rd app, rather full desktop session 1 program? the quick , dirty way need include "alternate shell" property in rdp config file.  way user full session, explorer not load, specified app. however, if want preserve basic explorer functionality have implement gpo rd session host farm.  acheve above mentioned settings, use following gpo options. 1 - user configuration \ policies \ administrative templates \ control panel \ prohibit access control pa

Error 4000 - DNS Access Denied

Image
dears, please urgent issue have 2 domain controller 1. a.contoso.com(primary domain) 2. b.contoso.com (chiled domain) when need open b.contoso.com show me error message access denied event id : 4000, please me because down in company dears, please urgent issue have 2 domain controller 1. a.contoso.com(primary domain) 2. b.contoso.com (chiled domain) when need open b.contoso.com show me error message access denied event id : 4000, please me because down in company greetings! go one:  dns zones not load, event 4000, 4007 mahdi tehrani   |     |   www.mahditehrani.ir please click on propose answer or mark post , helpful other people. posting provided as-is no warranties, , confers no rights. how query members of 'local administrators' group in computers? Windows Server  > 

ReFS, Data Integrity, and Hyper-V Server 2012

one of things interests me micorosft server 2012 new refs file format.  from things i've read believe new utility (integrity.exe) needed perform of refs functions such hard drive scrubbing? i install hyper-v server 2012 release candidate, can't find integrity.exe anywhere on system.  was integrity.exe left out of hyper-v server 2012 rc because not quite ready use?  or utility not included in hyper-v server 2012, can found in full microsoft server 2012?  (i hope that's not case!) i don't have windows 8 configured @ moment, 1 webpage found implied integrity.exe found in c:\windows\system32 directory on windows 8 system?  if that's true seems odd why not included on hyper-v server 2012. could integrity.exe copied windows 8 (or windows server 2012) , used on hyper-v server 2012?  i assume have same kernel.  or cause other problems? from webpage apparently integrity.exe not have built in file?  and haven't run across microsoft webpage describing how

Lsass insufficient system resources

most of users log on domain without problem, of them can’t. receive lsass “insufficient system resources” error message. problem not client specific; affected users cannot log on of clients. the environment: windows 2003 domain controller, xp sp3 clients. i turned on kerberos debug logging setting kerbdebuglevel , logtofile registry values. please me understand log got: 1224.1356> kerb-spn: found in spn cache 000cbd10 1224.1356> kerb-trace: delegationtgt endtime:   1-17-2010 18:34:38 1224.1356> kerb-trace: serviceticket endtime:   1-17-2010 18:34:38 1224.1356> kerb-spn: found in spn cache 000cbd10 1224.3396> kerb-(null): kerbinsertbinding binding cache disabled 1224.3396> kerb-trace: calling kdc 172.16.19.1 realm mydomain 1224.3396> ksupp-trace: calling kdc: 172.16.19.1   testuser 1224.3396> kerb-trace: mydomain 1224.3396> kerb-trace: flags:   raw 1224.3396> kerb-(null): kerbinsertbinding binding cache disabled 1224.3396> kerb-