Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > 2003 DC in 2008 R2 forest receives NTDS SDPROP event ID 2008

Reply
Thread Tools Display Modes

2003 DC in 2008 R2 forest receives NTDS SDPROP event ID 2008

 
 
c_hr1s
Guest
Posts: n/a

 
      11-10-2009
I have started receiving the following error since I upgraded my forest to
2008 R2 in preparation for a full domain upgrade. I receive this every half
hour on a user object (which occurs twice) and on the DC the error occurs.
All the googlign points to an Exchange 2003 SP1 issue but I have 2007 SP2
installed so am baffled as to how to fix this. I have no other replication
issues and this is only eventing on one DC.

Internal error: The security descriptor propagation task encountered an
error while processing the following object. The propagation of security
descriptors may not be possible until the problem is corrected.

Object:
CN=user and DC,OU=,OU=,DC=domain,DC=co,DC=nz

Additional Data
Error value:
-1026 JET_errRecordTooBig, Record larger than maximum size
Internal ID:
20903d5
 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      11-10-2009
Hello c_hr1s,

Did you raise the forest functional level to windows server 2008 R2?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I have started receiving the following error since I upgraded my
> forest to 2008 R2 in preparation for a full domain upgrade. I receive
> this every half hour on a user object (which occurs twice) and on the
> DC the error occurs. All the googlign points to an Exchange 2003 SP1
> issue but I have 2007 SP2 installed so am baffled as to how to fix
> this. I have no other replication issues and this is only eventing on
> one DC.
>
> Internal error: The security descriptor propagation task encountered
> an error while processing the following object. The propagation of
> security descriptors may not be possible until the problem is
> corrected.
>
> Object:
> CN=user and DC,OU=,OU=,DC=domain,DC=co,DC=nz
> Additional Data
> Error value:
> -1026 JET_errRecordTooBig, Record larger than maximum size
> Internal ID:
> 20903d



 
Reply With Quote
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      11-10-2009

From what I have found this deals with large numbers of ACL's applied or
inherited on this object.

Look at using the diagnostic tool ACLDiag.exe. The link to the tool usage
is below, the tool iteslf should be with the support tools on the
installation dvd.

http://technet.microsoft.com/en-us/l...88(WS.10).aspx

Run this tool against the offending user and see if there are an inordinate
amount of ALC's applied aginst this user.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"c_hr1s" <> wrote in message
news:3D0D374F-A0A8-4884-8CCA-...
>I have started receiving the following error since I upgraded my forest to
> 2008 R2 in preparation for a full domain upgrade. I receive this every
> half
> hour on a user object (which occurs twice) and on the DC the error occurs.
> All the googlign points to an Exchange 2003 SP1 issue but I have 2007 SP2
> installed so am baffled as to how to fix this. I have no other replication
> issues and this is only eventing on one DC.
>
> Internal error: The security descriptor propagation task encountered an
> error while processing the following object. The propagation of security
> descriptors may not be possible until the problem is corrected.
>
> Object:
> CN=user and DC,OU=,OU=,DC=domain,DC=co,DC=nz
>
> Additional Data
> Error value:
> -1026 JET_errRecordTooBig, Record larger than maximum size
> Internal ID:
> 20903d5



 
Reply With Quote
 
Florian Frommherz [MVP]
Guest
Posts: n/a

 
      11-10-2009
Howdie!

c_hr1s schrieb:
> Additional Data
> Error value:
> -1026 JET_errRecordTooBig, Record larger than maximum size
> Internal ID:
> 20903d5


The internal ID points to the SDProp process that checks ACLs and
permissions to user objects in Active Directory. Paul's suggestion is a
good advice so I'd check with the security descriptor on the object and
see whether there are too many (probably too deeply nested?) access
control entries.

Cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
ANY advice you get on the Newsgroups should be tested thoroughly in your
lab.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to Move WSUS Database From Windows Server 2003 to 2008 Charles Update Services 5 12-07-2011 08:42 PM
Re: Server 2008 R2 cannot join 2003 AD Meinolf Weber [MVP-DS] Windows Server 0 10-31-2009 08:49 AM
Security Failures after Password Change Zachary Server Security 14 10-30-2009 07:02 PM
Re: Server 2008 R2 cannot join 2003 AD Meinolf Weber [MVP-DS] Windows Server 0 10-30-2009 06:37 AM
Migrating old 2003 server with Exchange to new 2003 64-bit serverwith Exchange 2008 Willo van der Merwe Server Migration 3 10-24-2009 06:26 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59