Networking Forums

Networking Forums > Computer Networking > Windows Networking > Unable to resolve SPNEGO Event ID 40961 errors

Reply
Thread Tools Display Modes

Unable to resolve SPNEGO Event ID 40961 errors

 
 
Leythos
Guest
Posts: n/a

 
      11-25-2007, 04:54 PM
I have a few workstations, not all of them, that randomly start getting
security failures in their event logs, rebooting the main server and the
workstations often takes care of it, but not always. I've looked all
over the net, tried many things, but I can't seem to shake this.

Anyone have a solution path for getting rid of these errors?

Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 11/25/2007
Time: 11:49:23 AM
User: N/A
Computer: WS56
Description:
The Security System could not establish a secured connection with the
server
ldap/servername.domainname.local/(E-Mail Removed).
No authentication protocol was available


--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
(E-Mail Removed) (remove 999 for proper email address)
 
Reply With Quote
 
 
 
 
Joe D
Guest
Posts: n/a

 
      11-25-2007, 05:27 PM
is there something "wrong"? or are you just thinking something is wrong
because you see these events?



"Leythos" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed). ..
>I have a few workstations, not all of them, that randomly start getting
> security failures in their event logs, rebooting the main server and the
> workstations often takes care of it, but not always. I've looked all
> over the net, tried many things, but I can't seem to shake this.
>
> Anyone have a solution path for getting rid of these errors?
>
> Event Type: Warning
> Event Source: LSASRV
> Event Category: SPNEGO (Negotiator)
> Event ID: 40961
> Date: 11/25/2007
> Time: 11:49:23 AM
> User: N/A
> Computer: WS56
> Description:
> The Security System could not establish a secured connection with the
> server
> ldap/servername.domainname.local/(E-Mail Removed).
> No authentication protocol was available
>
>
> --
>
> Leythos
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> (E-Mail Removed) (remove 999 for proper email address)


 
Reply With Quote
 
Leythos
Guest
Posts: n/a

 
      11-25-2007, 06:28 PM
In article <(E-Mail Removed)>, (E-Mail Removed) says...
> is there something "wrong"? or are you just thinking something is wrong
> because you see these events?


I'm assuming that since I get an Authentication Error in the security
event log, that there should be something wrong.

Any user that logs onto the problem machine will cause a Security Event
entry showing logon authentication failure, but they can login without
any problem.

I don't see this in any of the other domains we manage, just this one
and only on some workstations.

The SPNEGRO error is common for the ones that fail, if I disjoin from
the domain, delete the computer account, and rejoin it, it goes away 90%
of the time and doesn't return - but once in a while I have a computer
that doesn't seem to resolve that problem.


--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
(E-Mail Removed) (remove 999 for proper email address)
 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      11-25-2007, 08:52 PM
Hello Leythos,

Did you have a reverse lookup zone created in DNS console? If not create
it, should help you.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm

> In article <(E-Mail Removed)>, (E-Mail Removed) says...
>
>> is there something "wrong"? or are you just thinking something is
>> wrong because you see these events?
>>

> I'm assuming that since I get an Authentication Error in the security
> event log, that there should be something wrong.
>
> Any user that logs onto the problem machine will cause a Security
> Event entry showing logon authentication failure, but they can login
> without any problem.
>
> I don't see this in any of the other domains we manage, just this one
> and only on some workstations.
>
> The SPNEGRO error is common for the ones that fail, if I disjoin from
> the domain, delete the computer account, and rejoin it, it goes away
> 90% of the time and doesn't return - but once in a while I have a
> computer that doesn't seem to resolve that problem.
>



 
Reply With Quote
 
Leythos
Guest
Posts: n/a

 
      11-25-2007, 09:12 PM
In article <(E-Mail Removed) >, Meinolf
Weber <meiweb(nospam)@gmx.de> says...
> Hello Leythos,
>
> Did you have a reverse lookup zone created in DNS console? If not create
> it, should help you.


Yes, for all 6 subnets (we have a few branch offices that register their
DNS, but the ones (workstations) that cause the problem are the local
subnet ones.

What if I remove the records in the reverse LUZ?


--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
(E-Mail Removed) (remove 999 for proper email address)
 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      11-25-2007, 09:20 PM
Hello Leythos,

Think this will be ok. Do you have enabled NETBIOS over TCP/IP on the clients?
Also you can try to remove/reinstall MS client for networking on the workstations.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.dts-l.org/goodpost.htm

> In article <(E-Mail Removed) >,
> Meinolf Weber <meiweb(nospam)@gmx.de> says...
>
>> Hello Leythos,
>>
>> Did you have a reverse lookup zone created in DNS console? If not
>> create it, should help you.
>>

> Yes, for all 6 subnets (we have a few branch offices that register
> their DNS, but the ones (workstations) that cause the problem are the
> local subnet ones.
>
> What if I remove the records in the reverse LUZ?
>



 
Reply With Quote
 
Leythos
Guest
Posts: n/a

 
      11-25-2007, 11:09 PM
In article <(E-Mail Removed) >, Meinolf
Weber <meiweb(nospam)@gmx.de> says...
> Hello Leythos,
>
> Think this will be ok. Do you have enabled NETBIOS over TCP/IP on the clients?
> Also you can try to remove/reinstall MS client for networking on the workstations.


Thanks for the ideas - I'll check on this on Monday when I have more
time. Have a good evening.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
(E-Mail Removed) (remove 999 for proper email address)
 
Reply With Quote
 
Joe D
Guest
Posts: n/a

 
      11-25-2007, 11:45 PM
if it only happens on one machine, check the system time AND time zone on
that machine. could be a kerberos issue caused by a time difference between
the pc and the authenticating dc




"Leythos" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed). ..
> In article <(E-Mail Removed) >, Meinolf
> Weber <meiweb(nospam)@gmx.de> says...
>> Hello Leythos,
>>
>> Think this will be ok. Do you have enabled NETBIOS over TCP/IP on the
>> clients?
>> Also you can try to remove/reinstall MS client for networking on the
>> workstations.

>
> Thanks for the ideas - I'll check on this on Monday when I have more
> time. Have a good evening.
>
> --
>
> Leythos
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> (E-Mail Removed) (remove 999 for proper email address)


 
Reply With Quote
 
Leythos
Guest
Posts: n/a

 
      11-26-2007, 10:46 AM
In article <(E-Mail Removed)>, (E-Mail Removed) says...
> if it only happens on one machine, check the system time AND time zone on
> that machine. could be a kerberos issue caused by a time difference between
> the pc and the authenticating dc


It happens on one or two machines at a time, and once fixed, normally by
a disjoin from domain, delete computer account on server, rejoin to
domain, it doesn't come back, but it crops up from time to time.

I've checked the time zone, time, ensured that they are all set by DHCP,
ensured that the time service is reachable, etc....

The main server was an SBS 2003 server migrated (swing) to Win 2003 Std
R2, but everything seems to work without any errors other than that.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
(E-Mail Removed) (remove 999 for proper email address)
 
Reply With Quote
 
Roger Abell [MVP]
Guest
Posts: n/a

 
      11-26-2007, 02:32 PM
It is quite odd that they trigger the message, but then do manage
to get authenticated. If you are logging successful logins, what
is showing as the authentication provider? NTLM when this
happens (msgs but success anyway) whereas normally you see
that Kerberos is being used?

Later you say the main server was SBS03, never migrated.
So doesn't that mean still SBS03? If so, could it be some
odd SBS hardcoded limit (max clients) you are hitting?

Roger

"Leythos" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed). ..
> In article <(E-Mail Removed)>, (E-Mail Removed) says...
>> is there something "wrong"? or are you just thinking something is wrong
>> because you see these events?

>
> I'm assuming that since I get an Authentication Error in the security
> event log, that there should be something wrong.
>
> Any user that logs onto the problem machine will cause a Security Event
> entry showing logon authentication failure, but they can login without
> any problem.
>
> I don't see this in any of the other domains we manage, just this one
> and only on some workstations.
>
> The SPNEGRO error is common for the ones that fail, if I disjoin from
> the domain, delete the computer account, and rejoin it, it goes away 90%
> of the time and doesn't return - but once in a while I have a computer
> that doesn't seem to resolve that problem.
>
>
> --
>
> Leythos
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> (E-Mail Removed) (remove 999 for proper email address)



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
DNS error in eventlog SPNEGO 40961 LSASRV UselessUser Windows Networking 5 06-17-2008 08:11 PM
Event ID 40960 LSASRV SPNEGO SB Windows Networking 1 03-01-2007 08:31 AM
Event Warning 40961 LSASRV The Vogon Windows Networking 7 10-30-2005 11:13 AM
Event ID 40960 and 40961. Nori Windows Networking 4 04-02-2005 01:51 AM
LSASRV event 40961 =?Utf-8?B?bWFyaXNoZW4=?= Windows Networking 2 03-04-2005 07:29 PM



1 2 3 4 5 6 7 8 9 10 11