Event 1008 followed by 1009 in Windows 2000 Server DC

My Primary Domain Controller in AD running windows 2000 server has been loggin events 1008 and 1009 recently.
the event shows up every 2-3 hours, sometimes consecutively.
This is the only DC in the network.

Event 1008: The enterprise root certificate store could not be updated. Incorrect function
Event 1009: The NT Smartcard authentication certificate store could not be updated Incorrect function".
sunhakAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

valiconCommented:
Any changes to this DC?  Did you add a DNS server to it?  Update any GPO's?

 From a newsgroup post: "In my case the problem started to appear after I had installed Wingate 5.01 client software onto the file server, and had added a second DNS address, where the Wingate server DNS is setup at the gateway. Removing the Wingate client software, removing the second DNS server address (the same as the gateway) and then rebooting resulted in a perfectly functioning DNS domain server. I had installed the Wingate client software so that I could run Windows Update. I had done this because although the file server could access the internet when directly connected (I could ping www addresses from a command prompt), it could not display any pages".

 I was getting this event and event id 1008 (same source) plus an error about "Cannot contact Domain" etc. I simply re-applied the GPO manually which seemed to resolve the above errors.
SECEDIT /REFRESHPOLICY MACHINE_POLICY /ENFORCE
SECEDIT /REFRESHPOLICY USER_POLICY /ENFORCE
After applying the above you should get a response in the Event Viewer stating : "SceCli - Security policy in the Group policy objects are applied successfully". Now reboot your machine and the errors should be resolved.  

is this an SBS DC?

 From a newsgroup post: "The 1008 errors are not the problem, they are the messenger. However, these errors are indicative that there are clock cycles being stolen by these items. There is a specific Perflib error that follows on the installation of SBS 2000. You resolve it quite simply with a command explained in the SBS readme doc which from the top of my head is:

c:\winnt.sbs\system32>lodctr c:\exchsrvr\bin\eseperf.ini

That means you must execute that command from that directory in order for this to solve the problem regarding this specific issue on this counter, assuming the other paths are correct.  BTW, this comes from the SBS readme doc."

Error code 0x80070051 = - no additional info
Error code 0x80070057 = E_INVALIDARG = "One or more arguments are not valid error." - no additional info  

0
sunhakAuthor Commented:
there were no changes in the DC.
I did tweak some GPOs, but reverting back and rebooting has not solved the problem.
I tried SECEDIT and in the event log, it shows SceCli successful, followed by event 1008 and 1009
This is not a SBS
0
valiconCommented:
What level service pack?
0
Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

sunhakAuthor Commented:
SP4
0
valiconCommented:
I have not been able to find anything on those event ID's.  I would try re-applying SP4.  Many times this will resolve issues like these.  Good Luck!  If I find anything I will let you know.
0
sunhakAuthor Commented:
I tried sfc and didn't work so I ran a Repair on windows 2000 last night and it solved the problem.
0
moduloCommented:
Closed, 500 points refunded.

modulo
Community Support Moderator
Experts Exchange
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows 2000

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.