Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / Windows 2000 / DNS / June 2007

Tip: Looking for answers? Try searching our database.

[WARNING] Failed to query SPN registration on DC

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
James - 24 May 2007 14:05 GMT
We're getting the following errors on our test domain when running
dcidag:
   [WARNING] Failed to query SPN registration on DC
'pdc1.test.local'.
   [WARNING] Failed to query SPN registration on DC
'pdc2.test.local'.

Any ideas on what's causing this warning?

DCDiag Results below:
......................................

   Computer Name: JIM
   DNS Host Name: Jim.test.local
   System info : Windows 2000 Professional (Build 2600)
   Processor : x86 Family 15 Model 4 Stepping 1, GenuineIntel
   List of installed hotfixes :
       KB834707
       KB867282
       KB873333
       KB873339
       KB883939
       KB885250
       KB885835
       KB885836
       KB885884
       KB885887
       KB886185
       KB887472
       KB887742
       KB887797
       KB888113
       KB888302
       KB888310
       KB890046
       KB890047
       KB890175
       KB890859
       KB890923
       KB891122
       KB891781
       KB893066
       KB893086
       KB893756
       KB893803
       KB893803v2
       KB894391
       KB896344
       KB896358
       KB896422
       KB896423
       KB896424
       KB896428
       KB896688
       KB896727
       KB898461
       KB899587
       KB899588
       KB899589
       KB899591
       KB900485
       KB900725
       KB900930
       KB901017
       KB901214
       KB902400
       KB903235
       KB904706
       KB904942
       KB905414
       KB905749
       KB905915
       KB908519
       KB908521
       KB908531
       KB909520
       KB910437
       KB911280
       KB911562
       KB911564
       KB911565
       KB911567
       KB911927
       KB912812
       KB912919
       KB912945
       KB913446
       KB913580
       KB914388
       KB914389
       KB914440
       KB915865
       KB916281
       KB916595
       KB917159
       KB917344
       KB917422
       KB917537
       KB917734_WMP10
       KB917953
       KB918118
       KB918439
       KB918899
       KB919007
       KB920213
       KB920214
       KB920342
       KB920670
       KB920683
       KB920685
       KB920872
       KB921398
       KB921883
       KB922582
       KB922616
       KB922819
       KB923191
       KB923414
       KB923689
       KB923694
       KB923980
       KB924191
       KB924270
       KB924496
       KB924667
       KB925398_WMP64
       KB925486
       KB925720
       KB925876
       KB925902
       KB926239
       KB926255
       KB926436
       KB927779
       KB927802
       KB927891
       KB928090-IE7
       KB928255
       KB928388
       KB928843
       KB929120
       KB929338
       KB929399
       KB929969
       KB930178
       KB930916
       KB931261
       KB931768-IE7
       KB931784
       KB931836
       KB932168
       Q147222

Netcard queries test . . . . . . . : Passed

Per interface results:

   Adapter : Local Area Connection

       Netcard queries test . . . : Passed

       Host Name. . . . . . . . . : Jim
       IP Address . . . . . . . . : 180.26.10.23
       Subnet Mask. . . . . . . . : 255.255.0.0
       Default Gateway. . . . . . : 180.26.10.250
       Primary WINS Server. . . . : 180.26.10.5
       Dns Servers. . . . . . . . : 180.26.10.5
                                    180.26.10.15

       AutoConfiguration results. . . . . . : Passed

       Default gateway test . . . : Passed

       NetBT name test. . . . . . : Passed

       WINS service test. . . . . : Passed

Global results:

Domain membership test . . . . . . : Passed

NetBT transports test. . . . . . . : Passed
   List of NetBt transports currently configured:
       NetBT_Tcpip_{71DDFD3E-BB9C-42E6-B950-8647B74C1D3D}
   1 NetBt transport currently configured.

Autonet address test . . . . . . . : Passed

IP loopback ping test. . . . . . . : Passed

Default gateway test . . . . . . . : Passed

NetBT name test. . . . . . . . . . : Passed

Winsock test . . . . . . . . . . . : Passed

DNS test . . . . . . . . . . . . . : Passed

Redir and Browser test . . . . . . : Passed
   List of NetBt transports currently bound to the Redir
       NetBT_Tcpip_{71DDFD3E-BB9C-42E6-B950-8647B74C1D3D}
   The redir is bound to 1 NetBt transport.

   List of NetBt transports currently bound to the browser
       NetBT_Tcpip_{71DDFD3E-BB9C-42E6-B950-8647B74C1D3D}
   The browser is bound to 1 NetBt transport.

DC discovery test. . . . . . . . . : Passed

DC list test . . . . . . . . . . . : Passed

Trust relationship test. . . . . . : Passed
   Secure channel for domain 'TESTDOMAIN' is to '\\pdc1.test.local'.

Kerberos test. . . . . . . . . . . : Passed

LDAP test. . . . . . . . . . . . . : Passed
   [WARNING] Failed to query SPN registration on DC
'pdc1.test.local'.
   [WARNING] Failed to query SPN registration on DC
'pdc2.test.local'.

Bindings test. . . . . . . . . . . : Passed

WAN configuration test . . . . . . : Skipped
   No active remote access connections.

Modem diagnostics test . . . . . . : Passed

IP Security test . . . . . . . . . : Passed
   Service status  is: Started
   Service startup is: Automatic
   IPSec service is available, but no policy is assigned or active
   Note: run "ipseccmd /?" for more detailed information

The command completed successfully
Ace Fekay [MVP] - 26 May 2007 15:02 GMT
> We're getting the following errors on our test domain when running
> dcidag:
[quoted text clipped - 4 lines]
>
> Any ideas on what's causing this warning?

<snipped>

Normally creating a reverse zone with the a PTR to all the DCs will do the
trick, because it is querying for the PTR. However you're using public IPs.
The ISP has ownership of those records and may be difficult for you to do
that. I would suggest to either try creating your own reverse for the
180.26.0.0 subnet (based on your subnet mask) or actually changing
everything over to a private subnet.

Signature

Regards,
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT, MVP
Microsoft MVP - Directory Services
Microsoft Certified Trainer

Infinite Diversities in Infinite Combinations

Having difficulty reading or finding responses to your post?
Instead of the website you're using, try using OEx (Outlook Express
or any other newsreader), and configure a news account, pointing to
news.microsoft.com. Anonymous access. It's free - no username or password
required nor do you need a Newsgroup Usenet account with your ISP. It
connects directly to the Microsoft Public Newsgroups. OEx allows you
o easily find, track threads, cross-post, sort by date, poster's name,
watched threads or subject. It's easy:

How to Configure OEx for Internet News
http://support.microsoft.com/?id=171164

"Quitting smoking is easy. I've done it a thousand times." - Mark Twain

James - 11 Jun 2007 17:03 GMT
I changed everything over to a private subnet (192.168.0.0/16) and
created reverse PTR records for the DCs and I'm still getting the same
error messages.
Ace Fekay [MVP] - 12 Jun 2007 03:47 GMT
> I changed everything over to a private subnet (192.168.0.0/16) and
> created reverse PTR records for the DCs and I'm still getting the same
> error messages.

So I am assuming you are saying that the following two records have PTRs
created for them:
'pdc1.test.local'
'pdc2.test.local'

Also, I am confused. You ran a dcdiag that you provided in your original
post for a computer called jim.test.local. Is this computer a DC?

On the computer called Jim, you have two DNS addresses listed in it's IP
properties., I assume you've changed it to the current private IP. Also, no
need to enter it twice. For DNS, once is all you need.

Please post the following information:

1. If Jim is not a DC, please run a dcdiag /v /fix on both DCs and post the
results.
2. Please run a netdiag /v /fix on both DCs and post the results as well.
3. Please provide an unedited ipconfig /all from jim, pdc1 and pdc2.
4. Please post any event log errors from the DCs (provide the EventID# and
Source)

Thanks,

Ace
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2010 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.