Имеется один домен, один лес, один сайт.
3 контроллера домена, один Citrix Metaframe Presentation Server. на DC серверах недавно стала появляться ошибка:
Источник: AutoEnrollment
Код (ID) 13
Автоматическая подача заявки на сертификат Локальная система: не удалось подать заявку на один сертификат Контроллер домена (0x80070005). Отказано в доступе.
DC сервера:
POSTGATE (все роли, PDC)
DISTANT
DONOR
компьютер лицензирования CTXSW (Citrix сервер).
NETDIAG с него:
F:\Program Files\Support Tools>netdiag
.......................................
Computer Name: CTXSW
DNS Host Name: ctxsw.ДОМЕН.ru
System info : Microsoft Windows Server 2003 (Build 3790)
Processor : x86 Family 15 Model 4 Stepping 1, GenuineIntel
List of installed hotfixes :
KB833407
KB890046
KB893756
KB896358
KB896422
KB896424
KB896428
KB898715
KB899587
KB899588
KB899589
KB899591
KB900725
KB901017
KB901214
KB902400
KB904706
KB905414
KB905915
KB908519
KB908531
KB910437
KB911280
KB911562
KB911567
KB911927
KB912919
KB913446
KB914388
KB914389
KB917344
KB917422
KB917537
KB917734
KB917953
KB918439
KB920213
KB920214
KB920670
KB920683
KB920685
KB921398
KB921883
KB922582
KB922616
KB922760
KB922819
KB923191
KB923414
KB923980
KB924191
KB924496
KB925486
Q147222
Netcard queries test . . . . . . . : Passed
GetStats failed for '¦Ё ьющ ярЁрыыхы№эvщ яюЁЄ'. [ERROR_NOT_SUPPORTED]
[WARNING] The net card '¦шэшяюЁЄ WAN (PPTP)' may not be working because it h
as not received any packets.
[WARNING] The net card '¦шэшяюЁЄ WAN (PPPoE)' may not be working because it
has not received any packets.
[WARNING] The net card '¦шэшяюЁЄ WAN (IP)' may not be working because it has
not received any packets.
[WARNING] The net card '¦шэшяюЁЄ WAN (TхЄхтющ ьюэшЄюЁ)' may not be working b
ecause it has not received any packets.
GetStats failed for '¦шэшяюЁЄ WAN (L2TP)'. [ERROR_NOT_SUPPORTED]
Per interface results:
Adapter : ¦юфъы¦ўхэшх яю ыюъры№эющ ёхЄш
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : ctxsw
IP Address . . . . . . . . : 192.168.2.7
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.2.4
Primary WINS Server. . . . : 192.168.2.2
Secondary WINS Server. . . : 192.168.2.9
Dns Servers. . . . . . . . : 192.168.2.2
192.168.2.12
IpConfig results . . . . . : Failed
Pinging the Secondary WINS server 192.168.2.9 - not reachable
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Failed
No gateway reachable for this adapter.
NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.
WINS service test. . . . . : Passed
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{2ADB11FB-478A-465A-BE3B-C7383E54CD87}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Failed
[FATAL] NO GATEWAYS ARE REACHABLE.
You have no connectivity to other network segments.
If you configured the IP protocol manually then
you need to add at least one valid gateway.
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{2ADB11FB-478A-465A-BE3B-C7383E54CD87}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{2ADB11FB-478A-465A-BE3B-C7383E54CD87}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Passed
Secure channel for domain 'ДОМЕН' is to '\\postgate.ДОМЕН.ru'.
Cannot test secure channel for domain 'ДОМЕН' to DC 'distant'. [ERROR_NO_L
OGON_SERVERS]
Cannot test secure channel for domain 'ДОМЕН' to DC 'donor'. [ERROR_NO_LOG
ON_SERVERS]
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully
**************************************
NETDIAG c POSTGATE
C:\Documents and Settings\novich>netdiag
.......................................
Computer Name: POSTGATE
DNS Host Name: postgate.ДОМЕН.ru
System info : Microsoft Windows Server 2003 R2 (Build 3790)
Processor : x86 Family 15 Model 4 Stepping 1, GenuineIntel
List of installed hotfixes :
KB924667-v2
KB925902
KB927891
KB929123
KB930178
KB931784
KB931836
KB932168
KB933566-IE7
KB935839
KB935840
KB935966
Q147222
Netcard queries test . . . . . . . : Passed
GetStats failed for '╧Ё ьющ ярЁрыыхы№э√щ яюЁЄ'. [ERROR_NOT_SUPPORTED]
[WARNING] The net card '╠шэшяюЁЄ WAN (PPTP)' may not be working because it h
as not received any packets.
[WARNING] The net card '╠шэшяюЁЄ WAN (PPPoE)' may not be working because it
has not received any packets.
[WARNING] The net card '╠шэшяюЁЄ WAN (IP)' may not be working because it has
not received any packets.
GetStats failed for '╠шэшяюЁЄ WAN (L2TP)'. [ERROR_NOT_SUPPORTED]
Per interface results:
Adapter : ╧юфъы■ўхэшх яю ыюъры№эющ ёхЄш 2
Netcard queries test . . . : Passed
Host Name. . . . . . . . . : postgate
IP Address . . . . . . . . : 192.168.2.2
Subnet Mask. . . . . . . . : 255.255.255.0
Default Gateway. . . . . . : 192.168.2.4
Primary WINS Server. . . . : 192.168.2.2
Dns Servers. . . . . . . . : 127.0.0.1
192.168.2.12
AutoConfiguration results. . . . . . : Passed
Default gateway test . . . : Failed
No gateway reachable for this adapter.
NetBT name test. . . . . . : Passed
[WARNING] At least one of the <00> 'WorkStation Service', <03> 'Messenge
r Service', <20> 'WINS' names is missing.
WINS service test. . . . . : Passed
Global results:
Domain membership test . . . . . . : Passed
NetBT transports test. . . . . . . : Passed
List of NetBt transports currently configured:
NetBT_Tcpip_{B6E2AEBF-0938-4721-B8B9-8B8E1A51B581}
1 NetBt transport currently configured.
Autonet address test . . . . . . . : Passed
IP loopback ping test. . . . . . . : Passed
Default gateway test . . . . . . . : Failed
[FATAL] NO GATEWAYS ARE REACHABLE.
You have no connectivity to other network segments.
If you configured the IP protocol manually then
you need to add at least one valid gateway.
NetBT name test. . . . . . . . . . : Passed
[WARNING] You don't have a single interface with the <00> 'WorkStation Servi
ce', <03> 'Messenger Service', <20> 'WINS' names defined.
Winsock test . . . . . . . . . . . : Passed
DNS test . . . . . . . . . . . . . : Passed
PASS - All the DNS entries for DC are registered on DNS server '127.0.0.1' a
nd other DCs also have some of the names registered.
PASS - All the DNS entries for DC are registered on DNS server '192.168.2.12
' and other DCs also have some of the names registered.
Redir and Browser test . . . . . . : Passed
List of NetBt transports currently bound to the Redir
NetBT_Tcpip_{B6E2AEBF-0938-4721-B8B9-8B8E1A51B581}
The redir is bound to 1 NetBt transport.
List of NetBt transports currently bound to the browser
NetBT_Tcpip_{B6E2AEBF-0938-4721-B8B9-8B8E1A51B581}
The browser is bound to 1 NetBt transport.
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Passed
Trust relationship test. . . . . . : Skipped
Kerberos test. . . . . . . . . . . : Passed
LDAP test. . . . . . . . . . . . . : Passed
Bindings test. . . . . . . . . . . : Passed
WAN configuration test . . . . . . : Skipped
No active remote access connections.
Modem diagnostics test . . . . . . : Passed
IP Security test . . . . . . . . . : Skipped
Note: run "netsh ipsec dynamic show /?" for more detailed information
The command completed successfully
***************************************
dcdiag с POSTGATE
C:\Documents and Settings\novich>dcdiag
Domain Controller Diagnosis
Performing initial setup:
Done gathering initial info.
Doing initial required tests
Testing server: Default-First-Site-Name\POSTGATE
Starting test: Connectivity
......................... POSTGATE passed test Connectivity
Doing primary tests
Testing server: Default-First-Site-Name\POSTGATE
Starting test: Replications
......................... POSTGATE passed test Replications
Starting test: NCSecDesc
......................... POSTGATE passed test NCSecDesc
Starting test: NetLogons
......................... POSTGATE passed test NetLogons
Starting test: Advertising
......................... POSTGATE passed test Advertising
Starting test: KnowsOfRoleHolders
......................... POSTGATE passed test KnowsOfRoleHolders
Starting test: RidManager
......................... POSTGATE passed test RidManager
Starting test: MachineAccount
......................... POSTGATE passed test MachineAccount
Starting test: Services
......................... POSTGATE passed test Services
Starting test: ObjectsReplicated
......................... POSTGATE passed test ObjectsReplicated
Starting test: frssysvol
......................... POSTGATE passed test frssysvol
Starting test: frsevent
......................... POSTGATE passed test frsevent
Starting test: kccevent
......................... POSTGATE passed test kccevent
Starting test: systemlog
......................... POSTGATE passed test systemlog
Starting test: VerifyReferences
......................... POSTGATE passed test VerifyReferences
Running partition tests on : ForestDnsZones
Starting test: CrossRefValidation
......................... ForestDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... ForestDnsZones passed test CheckSDRefDom
Running partition tests on : DomainDnsZones
Starting test: CrossRefValidation
......................... DomainDnsZones passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... DomainDnsZones passed test CheckSDRefDom
Running partition tests on : Schema
Starting test: CrossRefValidation
......................... Schema passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Schema passed test CheckSDRefDom
Running partition tests on : Configuration
Starting test: CrossRefValidation
......................... Configuration passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... Configuration passed test CheckSDRefDom
Running partition tests on : swgroup
Starting test: CrossRefValidation
......................... swgroup passed test CrossRefValidation
Starting test: CheckSDRefDom
......................... swgroup passed test CheckSDRefDom
Running enterprise tests on : swgroup.ru
Starting test: Intersite
......................... swgroup.ru passed test Intersite
Starting test: FsmoCheck
......................... swgroup.ru passed test FsmoCheck
****************************************************
С двух других DC (DONOR и DISTANT) картина одинаковая.
Предпринятые действия:
Рекомендации с
Eventlog (ERROR 13) помогите разобраться ....
на POSTGATE изменены пермишны на
%system drive%\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys
из ACL убраны "все". оставлены Administrator и System. (на DONOR и DISTANT то же самое)
_________________________________________________
рекомендации с
http://support.microsoft.com/kb/903220 группа DomainControllers добавлена в локальную группу CERTSVC_DCOM_ACCESS на CTXSW.
_________________________________________________
перезагружены DISTANT и POSTGATE.
_________________________________________________
на DISTANT и POSTGATE запущены службы учета лицезий. тип запуска Авто. Были в состоянии Отключено.
_________________________________________________
на CTXSW в консоли:
F:\Documents and Settings\novich>certutil -setreg setupstatus -setup_dcom_security_updated_flag
SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\SetupStatus:
Старое значение:
SetupStatus REG_DWORD = 2003 (8195)
SETUP_SERVER_FLAG -- 1
SETUP_CLIENT_FLAG -- 2
SETUP_DCOM_SECURITY_UPDATED_FLAG -- 2000 (8192)
Новое значение:
SetupStatus REG_DWORD = 3
SETUP_SERVER_FLAG -- 1
SETUP_CLIENT_FLAG -- 2
CertUtil: -setreg - команда успешно выполнена.
Чтобы изменения вступили в силу, может потребоваться перезапуск службы CertSvc.
F:\Documents and Settings\novich>net stop certsvc
Служба "Службы сертификации" останавливается.
Служба "Службы сертификации" успешно остановлена.
F:\Documents and Settings\novich>net start certsvc
Служба "Службы сертификации" успешно запущена.
________________________________________________
ПРОБЛЕМА НЕ РЕШЕНА. НА ВСЕХ DC ПРИ ЗАПУСКЕ certutil -pulse ПОЯВЛЯЕТСЯ ВЫШЕУПОМЯНУТАЯ ОШИБКА.