Logon Failure Certificate Server

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Something happened to our network over the weekend, and I believe it may be
related to our Cert Server running out of disk space due to about 8 GB log
files (for about one month). Now I have probelms GALORE!

The Exchange 2003 server's SA service will not start up, throwing off an
Event 1005 and 1004, implying the password is wrong. I reluctantly removed
the Exchange Server from the domain and tried to rejoin, which says it worked
and I can log onto the domain now, but SA still does not work, which means
Info Server doesn't either.

I noticed some weird message about the time service not being able to setup
a secure pipe to each DC from the main 2003 DC, so I tried to login to our
Cert Server and get the message about that domain account being invalid. The
big problem here is that I cannot remove the cert server from the domain to
add it back since you can't remove a cert server from a domain.

In addition, I have noticed that the DCs are not replicating as they should
even thought they appear to be setup correctly in the Sites config program.
I am getting a message to the effect that there is not enough information to
create the complete ring for replication for certain servers. Whe I try to
force replication using repadmin, it appears to work from one DC to another,
but not the other way around. It syas that there is not enough information
to remove an object, that I cannot even find!

I need help real bad and real fast. The mail server has already been down
one day so I can't afford for it to be down any longer. I have been here all
night trying to go through all of Technet and MSDN looking for a solution!
Please help, or tell me how to call someone for assistance... this is a big
mess!

Thanks
 
I monkeyed around with stuff for hours last night and by the time I left, I
was able to start the services on the Exchange Server. Do not ask me which
item fixed that issue since I have no idea!

I still have issues with synchronizing the DCs and would love some advice on
that. None of my DC do a two way synch and several have gone past the
tombstone time limit according to some of the tests I ran last night.

I have ten locations of which eight have their own DC, each with its own
subnet and Site set up. We usually add all users at the corporate and I am
guessing that the usernames are getting synchronized down to the branch
servers, but would have to verify that. We add computers at the local branch
office and most, it not all, of those fail to ever show up on our corporate
server. I don't doubt that I did something wrong somewhere, but where and
what?

We do have a firewall between the branches and here but there is a big hole
opened for ANY traffic coming from those subnets, at least in theory!

Let me know what I should be look for if you have any idea.

Thanks
 
I have all of the services running as mentioned, however, none of the new
users added after this event can log on to their email account. They
continually get a prompt for entering user, passw ,domain, even though they
are already logged into the domain.

Please help if you can.
 
Back
Top