Link to home
Start Free TrialLog in
Avatar of gazasc78
gazasc78Flag for United Kingdom of Great Britain and Northern Ireland

asked on

Windows cannot open template file

I am trying to apply auditing to the default domain controllers GPO on my Windows 2000 server machine.
When I expand Computer Configuration, Windows Settings, Security Templates I get an error saying:
"Windows cannot open template file"

I then go on to expand Security Settings, Local Policy, Audit Policy and if I make a change to a setting, for example 'Audit Account Logon Events' I get the following error message twice after clicking ok:

Failed to Save Fail to Save
l\SysVol\mydomain.local\Policies\{6E4B5C53-F6FC-4D1B-BFA3-39F91C58290B}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf

It then appears that the changes have been made, but if I exit the Group Policy Editor, and go in again to edit the policy, when I expand Computer Configuration, Windows Settings, Security Settings only the 'Public Key Policies' and 'IP Security Policies on Active Directory' folders are present.  i.e. 'Account Policies' and 'Local Policies' etc are all missing.
ASKER CERTIFIED SOLUTION
Avatar of aissim
aissim
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of gazasc78

ASKER

I ran the RecreateDefPol utility however however symptoms are still the same as before.
I have also noticed that the shortcut to 'Domain Controller Security Policy' under administrative tools is invalid and does not work.  Not sure if this is relevant?

A point I forgot to mention previously is that I have a second domain controller configured on the network which also has the same symptoms.

If I were to demote one domain controller at a time and then use DCPROMO to reinstall AD do you think this would correct my problem?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I've checked the Gptmpl.inf under the following path ....{6AC1786C-016F-11D2-945F-00C04fB984F9}\Computer\Microsoft\Windows NT\SecEdit as recommended in MS KB Article 936483 and SeNetworkLogonRight = *S-1-5-11,*S-1-5-32-544,*S-1-1-0 which seem correct.
 
However the error message I'm receiving is indicating the following path C:\WINNT\sysvol\sysvol\mydomain.local\Policies\{6E4B5C53-F6FC-4D1B-BFA3-39F91C58290B}\Machine\Microsoft\Windows NT\SecEdit

Is this the correct path?  I checked the Gpttmpl.inf file there and it only has the following entries:

[Unicode]
Unicode=yes
[Version]
signature="$CHICAGO$"
Revision=1

I've checked what services are running and I do not see an entry for DCOM, however the COM+ Event System is running.

SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The only errors I have in my Application Log are:

Source: SclgNtfy
Default group policy object cannot be created. Error 80070020 to save GPO Domain EFS Recovery Policy.

Source: SceSrv
Policy change from LSA/SAM can't be saved in the policy storage. Error 5 to save policy change for account S-1-5-21-1645522239-362288127-839522115-1680 in the default GPOs. For more debugging information, please look security\logs\scepol.log under Windows root.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks guys for all your help on this.
Thanks guys for all your help