Help needed with disjoint namespace on Server 2000

imported_Phil

Diamond Member
Feb 10, 2001
9,837
0
0
I'm looking at the Event Logs for a company that we support, and the single DC on the <domainname>.co.uk forest is reporting the following error:

Event Type: Error
Event Source: NTDS Replication
Event Category: Replication
Event ID: 1411
Date: 10/11/2005
Time: 12:06:51
User: Everyone
Computer: <server>
Description:
The Directory Service failed to construct a mutual authentication Service Principal Name (SPN) for server <domain>. The call is denied. The error was:
A Service Principal Name (SPN) could not be constructed because the provided hostname is not in the necessary format.

The record data is the status code.
Data:
0000: 6a 21 00 00 j!..

(I've removed the Server and Domain names obviously)

Looking at: http://support.microsoft.com/default.aspx?scid=kb;en-us;257623 it would appear that it's using a disjoint namespace, and to correct a certain registry key to include the Domain and NVDomain keys (which are currently both blank). All other machines on the network are using <name>.<domain>.co.uk.

Is it safe to alter these values using the MS-provided VB script? Should we export the Parameters branch first in case something goes tits-up?

Lastly, what implications will we have if we leave this alone? It's currently one DC and three member servers, ~40-50 workstations at any given time. The member servers again all have the FQDN in their Network Identification tabs. One is Windows 2000 TS, one is NT 4 Server and the last is a Redhat box. They're all Service Pack'ed up.

Any help would be appreciated! :)
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
Based on your description the symptoms described in that article sounds right. Though this is the type of issue I would probably open a case w/ PSS first just to discuss beforehand. This is not an issue I have run into anywhere.

And yes I would definetly export the registry settings as well as make sure I have an up-to-date full backup ready in the event of issues.

-Erik
 

imported_Phil

Diamond Member
Feb 10, 2001
9,837
0
0
Originally posted by: spyordie007
Based on your description the symptoms described in that article sounds right. Though this is the type of issue I would probably open a case w/ PSS first just to discuss beforehand. This is not an issue I have run into anywhere.

And yes I would definetly export the registry settings as well as make sure I have an up-to-date full backup ready in the event of issues.

-Erik

Thanks for the reply :)
Will PSS (I assume Product Support Services?) charge for this?
 

spyordie007

Diamond Member
May 28, 2001
6,229
0
0
Most likely. If you dont have a support agreement (SA/Technet, etc.) and you're looking to cut costs you could do email support (which I think is around $100 for this type of thing).
 

imported_Phil

Diamond Member
Feb 10, 2001
9,837
0
0
Nuts.
I think the research more + try it over Christmas route is best then ;)
It's certainly strange though; no other symptons apart from those messages in the Event Viewer. Even if there aren't any problems, I try to make sure that the logs are clean; it's just good practise as a server/network admin.