Read Only Domain Controller Group Policy errors


i have deployed our first read domain controller in our domain , getting following repeating event log error.  domain controller having issue , if related read role.

log name:      system
source:        microsoft-windows-grouppolicy
date:          13/06/2011 20:44:58
event id:      1058
task category: none
level:         error
keywords:     
user:          system
computer:     
description:
processing of group policy failed. windows attempted read file \\<domain>\sysvol\<domain>\policies\{b126f80b-cb27-4105-8b9f-7743b870f546}\gpt.ini domain controller , not successful. group policy settings may not applied until event resolved. issue may transient , caused 1 or more of following:
a) name resolution/network connectivity current domain controller.
b) file replication service latency (a file created on domain controller has not replicated current domain controller).
c) distributed file system (dfs) client has been disabled.
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-grouppolicy" guid="{aea1b4fa-97d1-45f2-a64c-4d69fffd92c9}" />
    <eventid>1058</eventid>
    <version>0</version>
    <level>2</level>
    <task>0</task>
    <opcode>1</opcode>
    <keywords>0x8000000000000000</keywords>
    <timecreated systemtime="2011-06-14t00:44:58.404306800z" />
    <eventrecordid>8263</eventrecordid>
    <correlation activityid="{8b532c99-33fd-4f2b-b4e2-160429a3d1ab}" />
    <execution processid="944" threadid="3036" />
    <channel>system</channel>
    <computer></computer>
    <security userid="s-1-5-18" />
  </system>
  <eventdata>
    <data name="supportinfo1">4</data>
    <data name="supportinfo2">816</data>
    <data name="processingmode">0</data>
    <data name="processingtimeinmilliseconds">968</data>
    <data name="errorcode">1265</data>
    <data name="errordescription">the system detected possible attempt compromise security. please ensure can contact server authenticated you. </data>
    <data name="dcname"></data>
    <data name="gpocnname">cn={b126f80b-cb27-4105-8b9f-7743b870f546},cn=policies,cn=system,dc=<domain>,dc=<domain></data>
    <data name="filepath">\\<domain>\sysvol\<domain>\policies\{b126f80b-cb27-4105-8b9f-7743b870f546}\gpt.ini</data>
  </eventdata>
</event>

hi,

thanks posting back. seems frs\dfsr broken prevented sysvol being replicated rodc.

more information

7.1.1.2.2.1.2.1.3 rodc ntfrs connection object - http://msdn.microsoft.com/en-us/library/dd340911(prot.10).aspx

rt (ntdsconn_opt_rodc_topology, 0x00000040): ntdsconn_opt_rodc_topology bit in options attribute indicates whether connection can used drs replication [ms-drdm]. when set, connection should ignored drs replication , used frs replication.

despite mention of frs in article, 0x40 value required both dfsr , frs. other connections ad replication still separately required , exist on rodc locally.

thanks!

ajayps



Windows Server  >  Group Policy



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

RDS 2012 r2 collections show black screen and then close