Internal event: The LDAP server returned an error. Error value: 0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT)

Sean Kuchle 41 Reputation points
2020-10-14T19:37:20.077+00:00

Following the advice in the 2020 LDAP Channel binding and LDAP signing requirements I changed the LdapEnforceChannelBinding to 1 and set the logging level to 2. Now I'm getting information log entries in the Directory Services log like the below. It references my 2 domain controllers which scares me a little. I've run DCDIAG and it does not come up with any errors. I've also checked replication using AD Replication Status Tool 1.0 and it also comes up clean. I just want to make sure this is not a sign of a larger problem

Internal event: The LDAP server returned an error.

Additional Data
Error value:
0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'CN=DC1,CN=Servers,CN=1-Office,CN=Sites,CN=Configuration,DC=LocalDomain,DC=local'

AND

Internal event: The LDAP server returned an error.

Additional Data
Error value:
0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'CN=DC2,CN=Servers,CN=2-Office,CN=Sites,CN=Configuration,DC=LocalDomain,DC=local'

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,287 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,996 questions
0 comments No comments
{count} votes

15 answers

Sort by: Most helpful
  1. Dave Patrick 426.2K Reputation points MVP
    2020-10-14T19:46:40.79+00:00
    0 comments No comments

  2. Sean Kuchle 41 Reputation points
    2020-10-14T20:03:28.31+00:00

    Thank you for your reply @Dave Patrick . I did see the article but it seemed a bit dated as I'm sure more and more people will be enabling logging I thought there had to be a bit more info out there.

    0 comments No comments

  3. Dave Patrick 426.2K Reputation points MVP
    2020-10-14T20:12:54.017+00:00

    You may need to do a network capture. It looks like the request is targeting some object that doesn't exist. Likely is not fatal as you said the dcdiag, repadmin comes back clean.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  4. Sean Kuchle 41 Reputation points
    2020-10-15T18:57:23.587+00:00

    Thank you for your time. It is going to be difficult for be to setup a capture on that server. But I'm glad it seems like it shouldn't be an issue. The error below is also coming up often in the Directory Services log, does it mean anything in conjunction with the original error? (random number of duplicates)

    Duplicate event log entries were suppressed.

    See the previous event log entry for details. An entry is considered a duplicate if the event code and all of its insertion parameters are identical. The time period for this run of duplicates is from the time of the previous event to the time of this event.

    Event Code:
    400005ff
    Number of duplicate entries:
    1

    0 comments No comments

  5. Dave Patrick 426.2K Reputation points MVP
    2020-10-15T18:59:12.523+00:00

    Please post the source and event ID

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments