Internal event: The LDAP server returned an error. Error value: 0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT)

Sean Kuchle 41 Reputation points
2020-10-14T19:37:20.077+00:00

Following the advice in the 2020 LDAP Channel binding and LDAP signing requirements I changed the LdapEnforceChannelBinding to 1 and set the logging level to 2. Now I'm getting information log entries in the Directory Services log like the below. It references my 2 domain controllers which scares me a little. I've run DCDIAG and it does not come up with any errors. I've also checked replication using AD Replication Status Tool 1.0 and it also comes up clean. I just want to make sure this is not a sign of a larger problem

Internal event: The LDAP server returned an error.

Additional Data
Error value:
0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'CN=DC1,CN=Servers,CN=1-Office,CN=Sites,CN=Configuration,DC=LocalDomain,DC=local'

AND

Internal event: The LDAP server returned an error.

Additional Data
Error value:
0000208D: NameErr: DSID-03100238, problem 2001 (NO_OBJECT), data 0, best match of:
'CN=DC2,CN=Servers,CN=2-Office,CN=Sites,CN=Configuration,DC=LocalDomain,DC=local'

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,237 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,652 questions
0 comments No comments
{count} votes

15 answers

Sort by: Most helpful
  1. Vicky Wang 2,731 Reputation points
    2020-10-19T08:58:45.86+00:00

    Hi,
     
    Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
     
    Best Regards,
    Vicky


  2. Vicky Wang 2,731 Reputation points
    2020-10-21T09:03:58.673+00:00

    Hi,
     
    Just want to confirm the current situations.
     
    Please feel free to let us know if you need further assistance.
     
    Best Regards,
    Vicky 

    0 comments No comments

  3. Sean Kuchle 41 Reputation points
    2020-10-21T13:00:03.863+00:00

    Hello @Vicky Wang this week has gotten a bit away from me but I'm hoping to keep this open till I run the trace

    0 comments No comments

  4. Vicky Wang 2,731 Reputation points
    2020-10-26T08:28:28+00:00

    Hi,
     
    Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.
     
    Best Regards,
    Vicky

    0 comments No comments

  5. Sean Kuchle 41 Reputation points
    2020-11-09T19:53:44.467+00:00

    I'm so sorry for the delayed response I was finally able to get a capture. It appears it the other Domain controller that is asking for this info which is really odd seeing as it should have it.
    --I only have 2 domain controllers in 2 different sites / networks connected via a Brach Office VPN.
    Checked the AD Replication Status tool and I get no errors.
    Any where else I could check to make sure everything is healthy?
    Thanks
    Sean


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.