?
Solved

Windows 2003 PDC unable to open netlogon or Domain Controller Security Policy

Posted on 2005-03-19
8
Medium Priority
?
217 Views
Last Modified: 2010-05-18
I manage a server that has started giving the following problems.

First we noticed that the netlogon share was not able to be accessed. After that we also noticed that Domain Controller Serurity Policy was not availiable.

This all seems to be tied back to the fact that fact that the sysvol share has a different name than the system is looking for. I am unsure how this could be, but the following errors in event view is what lead me to this conclusion.

Event ID: 1058
Windows cannot access the file gpt.ini for GPO CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=intranet,DC=local. The file must be present at the location <\\intranet.local\sysvol\intranet.local\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9}\gpt.ini>. (The system cannot find the path specified. ). Group Policy processing aborted.

Event ID: 1030
Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this.

When I open the "c:\WINNT\SYSVOL\sysvol\intranet.local\Policies" directory the only folder is "{5CC22055-4D2D-4714-B449-0A174D4A6751}".

Does anyone know how I can fix this problem? I have tried Micrsoft KB article 830676 and 842804. These did not seem to help.

Thanks in advance.
0
Comment
Question by:mcminc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
8 Comments
 
LVL 85

Expert Comment

by:oBdA
ID: 13583939
If you have more than one DC, check the sysvol folders on all of them. If it's present on one of the others, you have a replication problem.
If you have only one DC, check if you have a valid backup of the sysvol folder, and restore the missing folder.
If you don't have a backup, you can try to recreate the folder manually. Here's a similar issue; this might work for you as well:

Group Policy Error Message When Appropriate Sysvol Contents Are Missing
http://support.microsoft.com/?kbid=253268
0
 

Author Comment

by:mcminc
ID: 13584477
I appricate the post, but they did not help me.

I have check the only other DC on the domain and it has the same directory structure.

I do not have a backup as I believe this has been a problem for over a month and our backup scheme does not go back that many days.

If anyone else has a suggestion please let me know.
0
Get real performance insights from real users

Key features:
- Total Pages Views and Load times
- Top Pages Viewed and Load Times
- Real Time Site Page Build Performance
- Users’ Browser and Platform Performance
- Geographic User Breakdown
- And more

 

Author Comment

by:mcminc
ID: 13584548
One other note.

When I restart the netlogon service I get the folloowing error.

Event Type:      Error
Event Source:      NETLOGON
Event Category:      None
Event ID:      5706
Date:            3/20/2005
Time:            12:07:11 AM
User:            N/A
Computer:      TERMSER
Description:
The Netlogon service could not create server share C:\WINNT\SYSVOL\sysvol\intranet.local\SCRIPTS.  The following error occurred:
The system cannot find the file specified.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 02 00 00 00               ....    

Does anyone know how to fix this? If so maybe that will create the share.
0
 

Author Comment

by:mcminc
ID: 13584560
BTW: I was going to say that I had already looked at http://support.microsoft.com/default.aspx?scid=kb;en-us;318936 and the Registry entries look good.
0
 
LVL 4

Expert Comment

by:ajsaasta
ID: 13585328
does the netlogon service start and stay up on boot? if not, see http://support.microsoft.com/?kbid=269375.

I had the similar problem on sysvol location, just fix the path to sysvol location and it should work. See articles

http://www.jsifaq.com/SUBI/tip4400/rh4460.htm

and

http://www.jsifaq.com/SUBD/tip1700/rh1794.htm

how to modify registry.
0
 
LVL 85

Accepted Solution

by:
oBdA earned 2000 total points
ID: 13585394
Have you tried to create the ...\Policies\{31B2F340-016D-11D2-945F-00C04FB984F9} folder manually?
As for the scripts folder--does it exist at all?
0
 

Author Comment

by:mcminc
ID: 13585983
oBdA,

Manually recreating the folders seems to have taken care of the problem. I had to also create the SCRIPTS folder and set the permissions, but it worked. Now all I have to do is recreate all the login scripts.

Thanks.
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question