The information in this article applies to:
SYMPTOMS
The NetLogon service fails to start on a backup domain controller (BDC)
with NetLogon error 3210 or 5721, whereas, in the system event logs of the
primary domain controller (PDC,) the NetLogon service logs errors 5722 or
At the same time, the Service Control Manager logs error 7023 on the
BDC because the NetLogon service could not be started.
CAUSE
For the purpose of this article assume the following configuration:
When a BDC is part of a domain, a computer account is created (the computer account can be seen with Server Manager.) A default password is given to the computer account and the BDC stores the password in LSA secret storage $machine.acc. The password is then changed every seven days. Each BDC maintains such an LSA secret, which is used by the NetLogon service in order to establish a secure channel. If the computer account's password and the LSA secret are not synchronized, the NetLogon service fails to start on the BDC with the following error message:
If the computer account has been deleted, one of the following error messages are logged by the BDC NetLogon service:
-or-
Similarly, the NetLogon service on the PDC logs the following error message when the password is not synchronized:
In all cases, the event data contains the error. For example, the error 0xC0000022 means the computer account's password is invalid, while the error 0xC000018B means the computer account has been deleted, and so on. For more information on secure channels, please see the following article(s) in the Microsoft Knowledge Base: Q131366Event Error 5712 with Status Access Q142869Event ID 3210 and 5722 Appear When Synchronizing Entire Domain Q149664Verifying Domain Netlogon Q158148Domain Secure Channel Utility -- NLTEST.EXE Q160324Event ID 5721 After Deleting Computer RESOLUTION
WARNING: The solution included in this article has not been extensively
tested in large installations. Microsoft cannot guarantee that
modifications of domains as recommended herein will accomplish the
objective described in this article under all circumstances and in all
configurations.
The command above may be run on the PDC, BDC, or any member of the domain, provided that you are logged on as a user who is a member of the Domain Admins group. The output looks similar to the following:
The command above resets BDC secure channels only if required. If the password for the BDC secure channel was good, then you receive a message silimar to the following:
Additional query words: 4.00 prodnt ntfaqdom
Keywords : kbnetwork nthowto ntnetserv NTSrv ntutil |
Last Reviewed: February 17, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |