Server 2003 issues after SP1 with a 2000 DC
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

Server 2003 issues after SP1 with a 2000 DC

 
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.general
Author Message
Guest






PostPosted: Wed Apr 19, 2006 5:17 pm    Post subject: Server 2003 issues after SP1 with a 2000 DC Reply with quote

Hi List,

This is the answer to a problem not a question.

It took me a day to work this out after some intense googling and
searching of Microsoft KB. So I decided for the benefit of everyone I
would share my knowledge.

The scenario is:

Windows 2000 SBS domain controller
Windows 2003 Member Server

Apply SP1 to 2003 server, networking dies, unable to connect to domain,
Event ID 10016 DCOM / COM+ objects failing to start.

In simple terms, SP1 changes the way some of the security is handled
around loading these COM objects. This is "Impersonate a client".

If you 2003 server is already on, or you join a 2000 domain it will
recieve a 2000 domain group policy. The "Impersonate a client" rights
set in this policy are not sufficient to allow the 2003 server COM
objects to start.

To fix the problem, you will need to uninstall SP1 or remove the 2003
member server from the domain and reboot.

Your networking etc should be returned to normal.

Edit the default domain policy on the DC (access to this through
Administrative Tools / Active Directory users and computers).

Drill down to:

Computer configuration / Windows Settings / Local Policies / User
Rights Assignments / Impersonate a client after authentication

Add the following : Service IIS_WPG ASPNET Administrators and
Administrator

When done you can close the policy editor.

On your 2003 member server you can now rejoin the domain, or reapply
SP1. It will take a couple of reboots before you have the policy and
it is installed.

Apparently MS are aware of this little feature be don't publicly share
it.

As I say, it took me a day of scouring the net to work this out, if I
used some of your ideas or posts thank you!

I hope this is helpful to you.

Chris
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.general All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory