Problems with Virtual Server on a 2008 Domain Controller

I am setting up two new servers using Windows Server 2008.  After setting up thier roles, all is well and they replicated properly.  Then I reach the final step, installing Virtual Server 2005 R2 SP1 on the PDC.

After installing the Virtual Server app, the domain starts giving all types of errors.  This is without even setting up any VM instances and happens as soon as the installation completes.  At this point the DC's give errors when foring a replication throught the AD Sites and Services console.

When forcing replication to the secondary DC: "The target principle name is incorrect."
When forcing replication to the primary with Virtual server: "A security package specific error occured."

The Virtual Server itself provides two errors when the service starts.
1. The service principal names for Virtual Server could not be registered. Constrained delegation cannot be used until the SPNs have been registered manually. Error 0x80072098 - Insufficient access rights to perform the operation.
2. An error has occured during the creation of Service Connection points for Virtual Server in Active Directory. Either a domain controller is not available to complete the operation or there is a security problem accessing the domain. This operation will be retried the next time the service starts. Error 0x80070005 - Access is denied.

Strangely, if I load a Virtual server the instance runs properly and can access the DC.

Here is the real kicker.  If I simply uninstall Virtual Server 2005, all problems go away and replication works fine.
LVL 6
travis87Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

exx1976Commented:
Some brief googling shows lots of people have had issues with this as well.

Here's a link to a fix that worked for VS on a 2003 DC

http://www.winserverkb.com/Uwe/Forum.aspx/virtual-server/2171/Virtual-Server-on-domain-controller-and-problem-with-SPN

I don't know about the AD issues you're seeing.  Could be specific to 2008.


I would have to say, in short, running VS on a DC is not exactly a good idea, for lots of reasons...


HTH,
exx
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
travis87Author Commented:
Thanks for the link.  Adding the network account to the computer in AD allowed the VS to udate the Ldap and stop complaining.

The bigger issue is the problems with replication.  Why would AD just stop replicating after installing VS.

You are right about using a DC to run VS but it's a budget issue.
0
exx1976Commented:
When LDAP was updated on the computer account it very likely could have broken AD..  Honestly, I haven't worked with VS at all (I'm a VMware shop), so I'm not 100% sure what changes are made..

Can you post the before and after of the "LDAP updates"?

0
travis87Author Commented:
What finally fixed AD...

The atricle that was sent stated that I needed to allow a higher privelage the the NetworkService account on the DC.  That resolved the errors on the Virtual Server wbe interface but did not fix AD.   In fact the Virtual Server installation broke active directory (LDAP).  After uninstalling VS, Active Directory was again working.

Re-installing VS with the elevated NetworkService privelages made everything happy.  VS had no more SPN problems or errors and AD was able to replicate sites without error.

Thanks for the help!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.