Networking Forums

Networking Forums > Computer Networking > Windows Networking > Event ID 1411

Reply
Thread Tools Display Modes

Event ID 1411

 
 
Jon Rowlan
Guest
Posts: n/a

 
      12-01-2006, 07:43 AM
Recently I removed a DC from the domain.

There were lingering objects that I just could not remove.

I have now managed to remove the DC using /forceremoval on the dcpromo
command.

However, whilst there is no evidence of the DC in the AD as far as I can
tell, I am still getting an error in the event logs of the other DC's.

Event ID 1411, Category "DS RPC Client"

Active Directory failed to construct a mutual authentication service
principal name (SPN) for the following domain controller.

Domain controller:
a8771fa8-c060-4e91-9f5b-8600065ba918._msdcs.sads.com

The call was denied. Communication with this domain controller might be
affected.

Additional Data
Error value:
8589 The DS cannot derive a service principal name (SPN) with which to
mutually authenticate the target server because the corresponding server
object in the local DS database has no serverReference attribute.

Everything seems healthy apart from this error ... but I want to get the
domain all completely clean.

There is no info on the MS K/B regarding this and I guess I need to just
into ADSIEDIT or something to remove this.

Can any please advise ?

Many thanks,

jON


 
Reply With Quote
 
 
 
 
Jon Rowlan
Guest
Posts: n/a

 
      12-01-2006, 02:28 PM
I already used that Gareth after I had done the dcpromo /forceremoval

After completing all of these steps successfully, this error occurs.

And I can find no info on it anywhere ...

I need to know how to remove this entity from the AD I suspect.

jON


"GarethBaxendale" <(E-Mail Removed)> wrote in
message news:535B0C52-DB57-4317-9600-(E-Mail Removed)...
> This articl may point you in the right direction...
> http://support.microsoft.com/default.aspx/kb/216498
>
> Hope that helps
> Thanks
> Gaz
>
> "Jon Rowlan" wrote:
>
>> Recently I removed a DC from the domain.
>>
>> There were lingering objects that I just could not remove.
>>
>> I have now managed to remove the DC using /forceremoval on the dcpromo
>> command.
>>
>> However, whilst there is no evidence of the DC in the AD as far as I can
>> tell, I am still getting an error in the event logs of the other DC's.
>>
>> Event ID 1411, Category "DS RPC Client"
>>
>> Active Directory failed to construct a mutual authentication service
>> principal name (SPN) for the following domain controller.
>>
>> Domain controller:
>> a8771fa8-c060-4e91-9f5b-8600065ba918._msdcs.sads.com
>>
>> The call was denied. Communication with this domain controller might be
>> affected.
>>
>> Additional Data
>> Error value:
>> 8589 The DS cannot derive a service principal name (SPN) with which to
>> mutually authenticate the target server because the corresponding server
>> object in the local DS database has no serverReference attribute.
>>
>> Everything seems healthy apart from this error ... but I want to get the
>> domain all completely clean.
>>
>> There is no info on the MS K/B regarding this and I guess I need to just
>> into ADSIEDIT or something to remove this.
>>
>> Can any please advise ?
>>
>> Many thanks,
>>
>> jON
>>
>>
>>



 
Reply With Quote
 
Ace Fekay [MVP]
Guest
Posts: n/a

 
      12-04-2006, 01:15 AM
In news:u2%(E-Mail Removed),
Jon Rowlan <(E-Mail Removed)> stated, which I commented on below:
> I already used that Gareth after I had done the dcpromo /forceremoval
>
> After completing all of these steps successfully, this error occurs.
>
> And I can find no info on it anywhere ...
>
> I need to know how to remove this entity from the AD I suspect.
>
> jON


If you followed the article Garath provided and did not see any objects
associated with the failed DC, then I would look in ADUC under DCs to make
sure it is removed, as well as in Sites and Services/Sites/SiteName/Servers.
Manually delete any old references.

--
Ace
Innovative IT Concepts, Inc (IITCI)
Willow Grove, PA

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Having difficulty reading or finding responses to your post?
Instead of the website you're using, I suggest to use OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. This is a direct link to the Microsoft Public
Newsgroups. It is FREE and requires NO ISP's Usenet account. OEx allows you
to easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject.
It's easy:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

Infinite Diversities in Infinite Combinations
Assimilation Imminent. Resistance is Futile
"Very funny Scotty. Now, beam down my clothes."

The only constant in life is change...


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
MRxSmb event ID 8003 found in event log Pakeon Windows Networking 1 02-15-2008 10:24 AM
LSASRV Event 40960 and Failure Audit Event 673 since Feb 2007 Drew Govnyak Windows Networking 1 07-25-2007 05:34 AM
Need help resolving Event ID 1054 errors appearing in event log every 5 mins! thelotus99@gmail.com Windows Networking 2 07-16-2007 02:30 PM
Event ID: 8003 filling up the System Event log... Claude Lachapelle Windows Networking 6 10-11-2006 08:21 PM
Event ID1058 & Event ID1030 errors in the application log!!! Herm Windows Networking 2 01-07-2005 07:35 AM



1 2 3 4 5 6 7 8 9 10 11