Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Domain controller computer account expired?

Reply
Thread Tools Display Modes

Domain controller computer account expired?

 
 
Claude Lachapelle
Guest
Posts: n/a

 
      07-03-2009

Hi!

We have some domain controllers for which we have this event logged every
minutes (and more):

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 532
Date: 6/10/2009
Time: 1:11:15 AM
User: NT AUTHORITY\SYSTEM
Computer: DC01
Description:
Logon Failure:
Reason: The specified user account has expired
User Name:
Domain:
Logon Type: 3
Logon Process: Authz
Authentication Package: Kerberos
Workstation Name: DC01
Caller User Name: DC01$
Caller Domain: DOMAIN
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 848
Transited Services: -
Source Network Address: -
Source Port: -

However we could logon to this server without any problem and users do not
have any problem at all.

I did the following, but with no success, we are still getting the error
message:

How To Use Netdom.exe to Reset Machine Account Passwords of a Windows 2000
Domain Controller
http://support.microsoft.com/kb/260575

What's wrong with those domain controllers???

Thanks.

Claude Lachapelle
Systems Administrator, MCSE
 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      07-03-2009

Hello Claude,

Please post an unedited dcdiag /v, netdiag /v from that DC, also a repadmin
/showrepl.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi!
>
> We have some domain controllers for which we have this event logged
> every minutes (and more):
>
> Event Type: Failure Audit Event Source: Security Event Category:
> Logon/Logoff Event ID: 532 Date: 6/10/2009 Time: 1:11:15 AM User: NT
> AUTHORITY\SYSTEM Computer: DC01 Description: Logon Failure: Reason:
> The specified user account has expired User Name: Domain: Logon Type:
> 3 Logon Process: Authz Authentication Package: Kerberos Workstation
> Name: DC01 Caller User Name: DC01$ Caller Domain: DOMAIN Caller Logon
> ID: (0x0,0x3E7) Caller Process ID: 848 Transited Services: - Source
> Network Address: - Source Port: -
>
> However we could logon to this server without any problem and users do
> not have any problem at all.
>
> I did the following, but with no success, we are still getting the
> error message:
>
> How To Use Netdom.exe to Reset Machine Account Passwords of a Windows
> 2000
> Domain Controller
> http://support.microsoft.com/kb/260575
> What's wrong with those domain controllers???
>
> Thanks.
>
> Claude Lachapelle Systems Administrator, MCSE
>



 
Reply With Quote
 
Claude Lachapelle
Guest
Posts: n/a

 
      07-03-2009

dcdiag, netdiag and repadmin reported no error.

What I found is related to the logon type, which is 3, which is indicating a
network logon event failure...

But with no user and no domain name, what does that mean, which user account
has expired ???

Anything else I could run or monitor to find out the source of the error?

Thanks.

"Meinolf Weber [MVP-DS]" wrote:

> Hello Claude,
>
> Please post an unedited dcdiag /v, netdiag /v from that DC, also a repadmin
> /showrepl.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>
> > Hi!
> >
> > We have some domain controllers for which we have this event logged
> > every minutes (and more):
> >
> > Event Type: Failure Audit Event Source: Security Event Category:
> > Logon/Logoff Event ID: 532 Date: 6/10/2009 Time: 1:11:15 AM User: NT
> > AUTHORITY\SYSTEM Computer: DC01 Description: Logon Failure: Reason:
> > The specified user account has expired User Name: Domain: Logon Type:
> > 3 Logon Process: Authz Authentication Package: Kerberos Workstation
> > Name: DC01 Caller User Name: DC01$ Caller Domain: DOMAIN Caller Logon
> > ID: (0x0,0x3E7) Caller Process ID: 848 Transited Services: - Source
> > Network Address: - Source Port: -
> >
> > However we could logon to this server without any problem and users do
> > not have any problem at all.
> >
> > I did the following, but with no success, we are still getting the
> > error message:
> >
> > How To Use Netdom.exe to Reset Machine Account Passwords of a Windows
> > 2000
> > Domain Controller
> > http://support.microsoft.com/kb/260575
> > What's wrong with those domain controllers???
> >
> > Thanks.
> >
> > Claude Lachapelle Systems Administrator, MCSE
> >

>
>
>

 
Reply With Quote
 
Claude Lachapelle
Guest
Posts: n/a

 
      07-03-2009

I finally found it, this is related to services which are unable to start
using LOCAL SYSTEM.

But I'm still searching for what they are unable to start with this account,
since a lot of others services are using the same account with no problem...

And about "The specified user account has expired", this is almost
impossible with the LOCAL SYSTEM account???

Thanks.

"Claude Lachapelle" wrote:

> dcdiag, netdiag and repadmin reported no error.
>
> What I found is related to the logon type, which is 3, which is indicating a
> network logon event failure...
>
> But with no user and no domain name, what does that mean, which user account
> has expired ???
>
> Anything else I could run or monitor to find out the source of the error?
>
> Thanks.
>
> "Meinolf Weber [MVP-DS]" wrote:
>
> > Hello Claude,
> >
> > Please post an unedited dcdiag /v, netdiag /v from that DC, also a repadmin
> > /showrepl.
> >
> > Best regards
> >
> > Meinolf Weber
> > Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> > no rights.
> > ** Please do NOT email, only reply to Newsgroups
> > ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
> >
> >
> > > Hi!
> > >
> > > We have some domain controllers for which we have this event logged
> > > every minutes (and more):
> > >
> > > Event Type: Failure Audit Event Source: Security Event Category:
> > > Logon/Logoff Event ID: 532 Date: 6/10/2009 Time: 1:11:15 AM User: NT
> > > AUTHORITY\SYSTEM Computer: DC01 Description: Logon Failure: Reason:
> > > The specified user account has expired User Name: Domain: Logon Type:
> > > 3 Logon Process: Authz Authentication Package: Kerberos Workstation
> > > Name: DC01 Caller User Name: DC01$ Caller Domain: DOMAIN Caller Logon
> > > ID: (0x0,0x3E7) Caller Process ID: 848 Transited Services: - Source
> > > Network Address: - Source Port: -
> > >
> > > However we could logon to this server without any problem and users do
> > > not have any problem at all.
> > >
> > > I did the following, but with no success, we are still getting the
> > > error message:
> > >
> > > How To Use Netdom.exe to Reset Machine Account Passwords of a Windows
> > > 2000
> > > Domain Controller
> > > http://support.microsoft.com/kb/260575
> > > What's wrong with those domain controllers???
> > >
> > > Thanks.
> > >
> > > Claude Lachapelle Systems Administrator, MCSE
> > >

> >
> >
> >

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot logon to Domain Controller with any Domain Admins account Steve Windows Small Business Server 2 11-20-2006 09:27 PM
Account to shutdown a Domain Controller - non-domain admin Sabo, Eric Windows Server 2 08-10-2005 12:55 PM
Deletion of Domain Controller Computer Account Steve B Active Directory 1 07-07-2005 02:31 PM
Computer Account for a Domain Controller` Phil Active Directory 2 05-24-2004 06:28 PM
dcpromo - unable to convert computer account to domain controller sam Active Directory 0 11-26-2003 04:58 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59