Hi,
Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
Best Regards,
Vicky
Internal event: The LDAP server returned an error. Error value: 0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT)
Following the advice in the 2020 LDAP Channel binding and LDAP signing requirements I changed the LdapEnforceChannelBinding to 1 and set the logging level to 2. Now I'm getting information log entries in the Directory Services log like the below. It references my 2 domain controllers which scares me a little. I've run DCDIAG and it does not come up with any errors. I've also checked replication using AD Replication Status Tool 1.0 and it also comes up clean. I just want to make sure this is not a sign of a larger problem
Internal event: The LDAP server returned an error.
Additional Data
Error value:
0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'CN=DC1,CN=Servers,CN=1-Office,CN=Sites,CN=Configuration,DC=LocalDomain,DC=local'
AND
Internal event: The LDAP server returned an error.
Additional Data
Error value:
0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'CN=DC2,CN=Servers,CN=2-Office,CN=Sites,CN=Configuration,DC=LocalDomain,DC=local'
15 answers
Sort by: Most helpful
-
Vicky Wang 2,731 Reputation points
2020-10-19T08:58:45.86+00:00 -
Vicky Wang 2,731 Reputation points
2020-10-21T09:03:58.673+00:00 Hi,
Just want to confirm the current situations.
Please feel free to let us know if you need further assistance.
Best Regards,
Vicky -
Sean Kuchle 41 Reputation points
2020-10-21T13:00:03.863+00:00 Hello @Vicky Wang this week has gotten a bit away from me but I'm hoping to keep this open till I run the trace
-
Vicky Wang 2,731 Reputation points
2020-10-26T08:28:28+00:00 Hi,
Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
Best Regards,
Vicky -
Sean Kuchle 41 Reputation points
2020-11-09T19:53:44.467+00:00 I'm so sorry for the delayed response I was finally able to get a capture. It appears it the other Domain controller that is asking for this info which is really odd seeing as it should have it.
--I only have 2 domain controllers in 2 different sites / networks connected via a Brach Office VPN.
Checked the AD Replication Status tool and I get no errors.
Any where else I could check to make sure everything is healthy?
Thanks
Sean