Solved

PDC not visible in Locations... when setting share permissions?

Posted on 2006-10-25
14
277 Views
Last Modified: 2013-12-23
When attempting to set user permissions to a directory on my webserver,
I can only add users from the local machine, the locations do not show my primary domain controller.

I have checked that my webserver is definatly joined to the domain, and then removed it and rejoined just to be sure.
WHY does my primary domain controller not show up so that I can add user permissions from users in the PDCs active directory?????

Help!
0
Comment
Question by:HarperBen
  • 6
  • 5
  • 3
14 Comments
 
LVL 30

Expert Comment

by:Gareth Gudger
ID: 17811940
When you are trying to add the users, click the "Locations" button. Does just the web server show up or do you see "Entire Directory" as an option to choose? Sounds like Location is just set to your computer.
0
 
LVL 4

Author Comment

by:HarperBen
ID: 17816018
I see only the local machine.
I was able to add the users to the share by managing the webserver remotly from the Managment Console on my AD machine.  But I would still like to know how to get it all to show up on the webserver, like it does on every other machine in our place.
0
 
LVL 30

Assisted Solution

by:Gareth Gudger
Gareth Gudger earned 200 total points
ID: 17816064
Hmm, I wonder what it could be. I dont think it is an AD read permission issue on the server. What DNS server is the webserver using?
0
 
LVL 7

Assisted Solution

by:CharliePete00
CharliePete00 earned 300 total points
ID: 17827115
Is the webserver logging into the domain?

Check to see if the Netlogon service is started.

Also, from the command line on the web server:

Echo %LogonServer%

If the name of the local computer is returned you are not authenticated to the domain.
0
 
LVL 4

Author Comment

by:HarperBen
ID: 17827803
diggisaur
webservers DNS is local ip of my PDC.

CharliePete00 ,
Yes I am definatly on the domain,
Echo %LogonServer% returns //SERVERNAME of my PDC.
Netlogon is started
0
 
LVL 30

Expert Comment

by:Gareth Gudger
ID: 17829088
Wait is this Windows 2003 Web Edition?
http://www.microsoft.com/windowsserver2003/evaluation/overview/web.mspx

I know Web Edition can be joined to a domain but can't be a domain controller. However, I wonder if this includes reading AD objects.
0
 
LVL 4

Author Comment

by:HarperBen
ID: 17830366
Yes, It's 2003 Web Edition.
I understand that it cant be a pdc, but I assuemed that didnt extend to being totaly usless as a domain member.
I am pretty sure its my settings, not micosofts mistake.
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 30

Expert Comment

by:Gareth Gudger
ID: 17831273
yea i think you are right. I need to look into it some more.
0
 
LVL 4

Author Comment

by:HarperBen
ID: 17831589
I THINK ITS A DNS ISSUE
I have also noticed that there are serveral entries in the event log that might not be helping my issue.

On the Web Server

Event Type:      Error
Event Source:      Userenv
Event Category:      None
Event ID:      1053
User:            NT AUTHORITY\SYSTEM
Computer:      WEBSERV
Description:
Windows cannot determine the user or computer name. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

Event Type:      Error
Event Source:      W32Time
Event Category:      None
Event ID:      29
User:            N/A
Computer:      WEBSERV
Description:
The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible.  No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.

Event Type:      Warning
Event Source:      DnsApi
Event Category:      None
Event ID:      11165
User:            N/A
Computer:      WEBSERV
Description:
The system failed to register host (A) resource records (RRs) for network adapter
with settings:

   Adapter Name : {B0110787-D110-4A42-9B28-ABFA88D23CC5}
   Host Name : webserv
   Primary Domain Suffix : austman.local
   DNS server list :
           192.168.1.6
   Sent update to server : <?>
   IP Address(es) :
     192.168.1.80

 The reason the system could not register these RRs was because the DNS server contacted refused the update request. The reasons for this might be (a) you are not allowed to update the specified DNS domain name, or (b) because the DNS server authoritative for this name does not support the DNS dynamic update protocol.

 To register the DNS host (A) resource records using the specific DNS domain name and IP addresses for this adapter, contact your DNS server or network systems administrator.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2a 23 00 00               *#..    


Event Type:      Error
Event Source:      NETLOGON
Event Category:      None
Event ID:      5719
User:            N/A
Computer:      WEBSERV
Description:
This computer was not able to set up a secure session with a domain controller in domain AUSTMAN due to the following:
There are currently no logon servers available to service the logon request.  
This may lead to authentication problems. Make sure that this computer is connected to the network. If the problem persists, please contact your domain administrator.  

ADDITIONAL INFO
If this computer is a domain controller for the specified domain, it sets up the secure session to the primary domain controller emulator in the specified domain. Otherwise, this computer sets up the secure session to any domain controller in the specified domain.

AND ON THE DOMAIN CONTROLLER

Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4004
User:            N/A
Computer:      PLUTO
Description:
The DNS server was unable to complete directory service enumeration of zone austman.com.au.  This DNS server is configured to use information obtained from Active Directory for this zone and is unable to load the zone without it.  Check that the Active Directory is functioning properly and repeat enumeration of the zone. The extended error debug information (which may be empty) is "". The event data contains the error.


Event Type:      Error
Event Source:      DNS
Event Category:      None
Event ID:      4015
User:            N/A
Computer:      PLUTO
Description:
The DNS server has encountered a critical error from the Active Directory. Check that the Active Directory is functioning properly. The extended error debug information (which may be empty) is "". The event data contains the error.

0
 
LVL 4

Author Comment

by:HarperBen
ID: 17831591
This is getting difficult and urgent, so up the points
0
 
LVL 7

Accepted Solution

by:
CharliePete00 earned 300 total points
ID: 17835086
We've gone from a minor annoying problem to a very serious one.  If we are not able to resolve this quickly I suggest you break off the DC error into a new question to get more people working on it.  Let's give this a try:

I'm focusing on the DC error because it is more serious.

From any workstation on the domain:

1.  Execute the following from the command-line to validate A (or Host) record for PDC Emulator in DNS:
       ping -a <Name of PDC Emulator>
1.  Execute the following from the command-line to verify SRV record for PDC Emulator in DNS:
       net time /set /domain:<Your Domain Name>

Is there more than 1 DC in your domain?  Have there been any replication errors recently?  Have any of your DCs failed or been removed from the domain in the recent past?

Let's start by validating the SYSVOL and NETLOGON shares.

From the troubled DC:

1.  Restart the file replication service (net start ntfrs) and examine the event log for errors and report back
2.  Execute the following from the command-line and report any errors
       dcdiag /netlogons



0
 
LVL 7

Expert Comment

by:CharliePete00
ID: 17835197
Just execute "dcdiag / c > outputfile.txt" instead of "dcdiag /netlogons" and post the results if there are any errors
0
 
LVL 4

Author Comment

by:HarperBen
ID: 17838257
Hi There,
I have solved the problem.
My forwardlookup zone was austman.com.au not austman.local.
This seemed to have been the source of more problems than I had even begin to ask you about.

Once a new forwad lookup was corectly configured, systems started getting the correct times,
group policy was now being applied to clients, win xp clients stopped getting kicked of the network at 6:00 pm every day, loggging on to the network is now much faster, ping -a now resolves host names, all locations show up in my web server and other domain member machines, the list of things that now work properly is endless!

I am going to split the points between CharliePete00 and diggisaur as you were both obviosly keen to stick it out and get me a result. Thanks again guys.
Ben Harper
0
 
LVL 30

Expert Comment

by:Gareth Gudger
ID: 17839766
Your welcome!
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

A brief overview to explain gateways, default gateways and static routes OR NO - you CANNOT have two default gateways on the same server, PC or other Windows-based network device. In simple terms a gateway is formed when a computer such as a serv…
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now