Y
Yvonne
Hi all,
I was wondering if any of you can help me with the following problem
which has been driving me nuts for the past few months and none of the
solutions found on the internet work (for more than two days anyway).
First off, standalone windows 2000 computer, SP4 with all updates, US
edition. I'm logged on not as administrator but as user with
administrative privileges.
I'm getting repeated instances of the following errors in my event
log:
Error
ESENT
Event ID 439
Services (248): Unable to write a shadowed header for file
C:\WINNT\Security\tmp.edb
Error
ESENT
Event ID 427
Services (248): The database engine could not access the file called
C:\WINNT\Security\tmp.edb
Warning
SCECLI
Event ID 1202
Security policies are propagated with warning (0x4b8): an extended
error has occurred.
In addition, I cannot access the local security database (access
denied).
Once the errors appear in the event log, I check the database for
integrity with the command:
esentutl /g %SystemRoot%\security\database\secedit.sdb
Output: the database is inconsistent.There may be uncommitted
logfiles. Operation terminated with error -1206
(JET_errDatabaseCorrupted, Non database file or corrupted db) after
1.391 seconds
I then remove all logs from c:\winnt\security as
well as c:\winnt\security\logs (after closing the handle on
scepol.log). I then recreate the local security database through the
MMC snap in procedure as outlined in KB 278316.
Lo and behold, integrity checks out OK with esentutl, I can access the
local security policy again and error are gone from the event log. For
about two days
The only policy I implement is to not have my password expire after 42
days (set to 0 days).
I also applied the following tweaks (probably irrelevant):
- disabled administrative shares
- disallowed my account full access to the regedit key in the registry
to prevent Windows from displaying the most recently viewed key
I checked security rights on C, WINNT as well as the Security folder
and they are identical to the ones on my machine at work. I never
messed with access rights apart from disabling administrative shares
through a registry key (problem also occurs with administrative shares
enabled). Admin account was not renamed either (besides, that'ss a
server policy).
After browsing the Internet for hours on end I don't know what to do
next.
Do you guys have any ideas what's going on?
TIA.
Yvonne
I was wondering if any of you can help me with the following problem
which has been driving me nuts for the past few months and none of the
solutions found on the internet work (for more than two days anyway).
First off, standalone windows 2000 computer, SP4 with all updates, US
edition. I'm logged on not as administrator but as user with
administrative privileges.
I'm getting repeated instances of the following errors in my event
log:
Error
ESENT
Event ID 439
Services (248): Unable to write a shadowed header for file
C:\WINNT\Security\tmp.edb
Error
ESENT
Event ID 427
Services (248): The database engine could not access the file called
C:\WINNT\Security\tmp.edb
Warning
SCECLI
Event ID 1202
Security policies are propagated with warning (0x4b8): an extended
error has occurred.
In addition, I cannot access the local security database (access
denied).
Once the errors appear in the event log, I check the database for
integrity with the command:
esentutl /g %SystemRoot%\security\database\secedit.sdb
Output: the database is inconsistent.There may be uncommitted
logfiles. Operation terminated with error -1206
(JET_errDatabaseCorrupted, Non database file or corrupted db) after
1.391 seconds
I then remove all logs from c:\winnt\security as
well as c:\winnt\security\logs (after closing the handle on
scepol.log). I then recreate the local security database through the
MMC snap in procedure as outlined in KB 278316.
Lo and behold, integrity checks out OK with esentutl, I can access the
local security policy again and error are gone from the event log. For
about two days
The only policy I implement is to not have my password expire after 42
days (set to 0 days).
I also applied the following tweaks (probably irrelevant):
- disabled administrative shares
- disallowed my account full access to the regedit key in the registry
to prevent Windows from displaying the most recently viewed key
I checked security rights on C, WINNT as well as the Security folder
and they are identical to the ones on my machine at work. I never
messed with access rights apart from disabling administrative shares
through a registry key (problem also occurs with administrative shares
enabled). Admin account was not renamed either (besides, that'ss a
server policy).
After browsing the Internet for hours on end I don't know what to do
next.
Do you guys have any ideas what's going on?
TIA.
Yvonne