L
Lewis Crow
On a very irregular basis, our W2K PDC reports this error
in the event log:
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1000
Date: 11/10/2003
Time: 3:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
Windows cannot access the registry information at
\\mydomain\sysvol\mydomain\Policies\{31B2F340-016D-11D2-
945F-
00C04FB984F9}\Machine\registry.pol with (1351).
Sometimes it happens twice a day; sometimes once in two
weeks. I have read through everything on EventID.net and
the KB articles referenced countless times, and nothing
seems to fit our situation. It's happening on the PDC,
not a workstation. The server is not multihomed. And so
on. I've applied the solution in KB 290647 three or four
times, and the error still reoccurs.
1351 = Configuration information could not be read from
the domain controller, either because the machine is
unavailable, or access has been denied.
I've verified that the referenced file is present, has
the proper permissions, and so on.
The only other thing I can see going is that at the exact
same time as the error occurs in the application log,
these are recorded in the security log:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 11/10/2003
Time: 3:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
Successful Network Logon:
User Name: MYSERVER$
Domain: MYDOMAIN
Logon ID: (0x0,0x3068834)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 11/10/2003
Time: 3:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
User Logoff:
User Name: MYSERVER$
Domain: MYDOMAIN
Logon ID: (0x0,0x3068834)
Logon Type: 3
in the event log:
Event Type: Error
Event Source: Userenv
Event Category: None
Event ID: 1000
Date: 11/10/2003
Time: 3:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
Windows cannot access the registry information at
\\mydomain\sysvol\mydomain\Policies\{31B2F340-016D-11D2-
945F-
00C04FB984F9}\Machine\registry.pol with (1351).
Sometimes it happens twice a day; sometimes once in two
weeks. I have read through everything on EventID.net and
the KB articles referenced countless times, and nothing
seems to fit our situation. It's happening on the PDC,
not a workstation. The server is not multihomed. And so
on. I've applied the solution in KB 290647 three or four
times, and the error still reoccurs.
1351 = Configuration information could not be read from
the domain controller, either because the machine is
unavailable, or access has been denied.
I've verified that the referenced file is present, has
the proper permissions, and so on.
The only other thing I can see going is that at the exact
same time as the error occurs in the application log,
these are recorded in the security log:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 11/10/2003
Time: 3:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
Successful Network Logon:
User Name: MYSERVER$
Domain: MYDOMAIN
Logon ID: (0x0,0x3068834)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 538
Date: 11/10/2003
Time: 3:16:44 PM
User: NT AUTHORITY\SYSTEM
Computer: MYSERVER
Description:
User Logoff:
User Name: MYSERVER$
Domain: MYDOMAIN
Logon ID: (0x0,0x3068834)
Logon Type: 3